Sangfor Community»Categories Product Network Secure with next version(NGAF) SSO not working (user can access internet on new TAB ...

SSO not working (user can access internet on new TAB of browser without login)

views: 4681 | comments: 21 | added to Favorites 0
Lights on | 提示:支持键盘翻页<-左 右->
    组图打开中,请稍候......
Created: 22 May 2023 16:15

Summary:

I have integrated the Active directory users with my Sangfor NGAF, I have created the authentication test policy only on 3 IPs. and int new user authentication I have select "No authentication for new ...

Reply

sumran Posted 30 May 2023 12:22
please remove the SSO and make the policy for the blocking of internet then it works
Taha Posted 30 May 2023 12:15
please review your SSO policy .it looks the problem at your policy .
Bebe_Bote Posted 30 May 2023 00:28
Specify the users that needs authentication and once authenticated can connect to the internet.
jetjetd Posted 30 May 2023 00:20
Just input the IP address or hostname of your NGAF device.
Farina Ahmed Posted 29 May 2023 15:38
1) Review policy configuration to ensure SSO traffic is not inadvertently blocked.
2) Whitelist SSO traffic by creating exceptions or allowing necessary ports/protocols/URLs.
3) Check network connectivity between user devices and SSO server.
4) Verify proper Active Directory integration and SSO authentication settings.
5) Monitor NGAF logs for blocked SSO traffic or authentication failures.
6) Review SSO configuration and consult documentation or vendor for guidance.
7) Contact Sangfor technical support for further assistance if the issue persists.
Garfield Posted 29 May 2023 15:26

To prevent the internet access of the 3 test users who bypassed authentication, you can create access control rules on Sangfor NGAF to block their IP addresses from accessing specific websites or the internet entirely.
VanFlyheights Posted 29 May 2023 15:02
Your IdP SSO profile settings may be usable only if you use them to configure the SSO profile for your organization.
Natsu Dragneel Posted 29 May 2023 14:59
In the NGAF management interface, look for the Firewall Policy section or something similar. This is where you may configure internet access rules.
BitCloud Posted 29 May 2023 14:56
Access the Sangfor NGAF management interface: Open a web browser and enter the IP address or hostname of your NGAF device to access the management interface.
Adonis001 Posted 29 May 2023 14:52
Specify the AD authentication requirement: Configure the authentication method to utilize Active Directory inside the policy settings. This guarantees that before being allowed internet access, users must verify against AD.