Sophos Firewall Match Known Users
Rule 2 will be applied to any events that do not match the rule 1 conditions and applies the firewall sophos general system tag.
Sophos firewall match known users. Remove the ips policy in the rule and check the throughput. Data is extracted from the. If you ve selected match known users the specified users traffic shaping policy is applied. In live users tab the xg is listing the users authenticated on the domain controller with client type as sso i ve added a firewall rule to authorize lan s pc to navigate.
Because microsoft uses non standard http https connections the sophos xg firewall s http scanning feature has the potential to prevent skype skype for business from working or may cause random call drops. Sophos xg230 sfos 16 05 3 mr 3 firewall authentication methods. For details see dscp value. Match known user may i know when i assign to each user with firewall rule after enable match known user and user local cannot access internet.
Select to add user identity as a matching criterion. Use web authentication for unknown users. Match known users and selected show captive portal to unknown users selected respective group under user group. Some user web policy was select none and allow all the time.
These are users who ve signed in to their endpoint devices but have not been authenticated. Check av pattern are up2date and configure av scan mode to single scan. Sophos central firewall management includes powerful cloud based group firewall management backup management one click firmware updates and rapid zero touch provisioning of new firewalls. This article explains how to allow this traffic through the xg without being scanned.
Two corresponding firewall rules for both rules i ve selected. Everything goes fine but if i check match known users. A regular expression in the source data field describes the format of the event data. Verify that no traffic shapping policy is defined in the rule.
What is the firmware version update to 16 05 mr 5. Hi check 1 1 in my troubleshooting guide and verify which fw rule id forwards the traffic and check the following configurations. Active directory local current activities. All users from ad have been populated in the firewall used the captive portal to get users from ad to firewall two groups of users and members are added to each group.
Select to authenticate unknown users who try to access the web. In the absence of a user policy the group policy is applied.