Jump to content

lg-wave9

Members
  • Posts

    7
  • Joined

  • Last visited

Reputation

17 Good

About lg-wave9

Personal Information

  • Homepage
    http://www.wave9.co.uk

Recent Profile Visitors

The recent visitors block is disabled and is not being shown to other users.

  1. Hi there, Do you have a LAG on the LAN set? If so, and you remove one of the cables from that LAG, does that make any difference? (not sure if you'd need to restart a phone or two, but... just a thought).
  2. Have you got two WAN links which are active, by any chance? If so, try an SD WAN route for that VLAN to send all the traffic out of one link only (to rule out asynchronous routing)
  3. (I'm sure you've checked this, sorry to be obvious), but is the XG doing DHCP for this VLAN? Is there anything else that could be giving out DHCP leases for the same scope? If the XG is doing DHCP for the phones, do you see a non-working phone in the DHCP lease table? (Network->DHCP, IPv4 leases). If the MAC addresses are seen by the firewall, try an allow-all with the source MAC of a phone that's not working.
  4. If you have the list of exceptions in - Skipping HTTPS decryption, Malware & Policy checks - and they're showing up in the Log Viewer->Web Filter log as having those applied (EG "domain="outlook.office365.com", exception="av,https,policy,zero-day protection,validation"), then you should be good on that side of things. If you create an 'allow all' firewall rule on the XG for your test machine (LAN->SourceIPAddress, WAN->Any, no web policy attached = no filtering), that should give you an idea on whether there's a problem on the firewall or not. And, I'm sure you've already tried it, but there's an Outlook Connectivity Assistant tool here from Microsoft which may help identify any client-side / connetivity issues: http://tinyurl.com/mrxzwd6f
  5. Hi Jamman960, - Check the STAS client is started, either by the STAS client gui or the Windows Service 'Sophos Transparent Authentication Suite' - Check the monitored subnet in STAS is correct, and your IP address of expected user is within that subnet - Are eventIDs 4768 appearing in the DCs Event Viewer->Security log (you'll need to check all of your Domain Controllers) If you're getting a 4768 in the event log: - Check the logging events file in STAS to see if STAS is reading the events correctly. If the user's not appearing in STAS's 'Live Users' list when someone logs in to a PC, see if they appear in the log file STAS log file. If they're there, are they being skipped for any reason? - Check your DCs (if you have more than one) can talk to each other. You can use the Advanced tab in STAS, putting the IP address of the other DCs in the 'STAS Collector' field and clicking the Test button next to the IP address. - Ports 5566, 6677 and 50001 need to be open for STAS to work (and maybe 6060) and not held open by any other service, such as DNS Server (commonly holds open 50001).
  6. Hi there, This sounds like a Framed-IP address problem (the XG is expecting that info, but the AP isn't sending it). If using NPS (just to check), you need to add the XG as a remote RADIUS server and then pass RADIUS accounting to it: Then configure your XG:
  7. Hi there. If you SSH to your XG and go to the advanced shell (option 5, option 3), try taking a look at the log file in /log/access_server.log. If you then 'tailf /log/access_server.log' and see what you find when the session disconnects (you should be able to add '| grep yourusername' on to the end of your tailf command, if you're getting swampted by other users).
×
×
  • Create New...