Authentication: STAS, SSO & MFA Concepts

Sophos Firewall Sophos VM (GUI + CLI)

مقصدObjectiveObjective

اس لیب میں آپ سیکھیں گے کہ STAS Active Directory کے ساتھ کیسے کام کرتا ہے، transparent SSO اور captive portal میں فرق کیا ہے، اور یوزرز کے لیے MFA (one-time password) کیسے enable کرتے ہیں۔Is lab mein aap seekhenge ke STAS Active Directory ke saath kaise kaam karta hai, transparent SSO aur captive portal mein farq kya hai, aur users ke liye MFA (one-time password) kaise enable karte hain.In this lab you will learn how STAS works with Active Directory, how transparent SSO and the captive portal differ, and how to enable MFA (one-time password) for users.

آسان مثالSimple AnalogySimple Analogy

STAS اس ریسیپشنسٹ جیسا ہے جو ملازمین کو بیج لگاتے دیکھتا ہے اور گارڈ کو بتاتا ہے، 'علی ابھی اندر آیا ہے — اسے دوبارہ ID پوچھے بغیر جانے دو۔' Captive portal پرانا طریقہ ہے: ہر شخص گیٹ پر رک کر ID دکھاتا ہے۔ MFA دروازے پر دوسرا تالا ہے — چابی کے ساتھ وہ کوڈ جو ہر 30 سیکنڈ میں بدلتا ہے۔STAS us receptionist jaisa hai jo employees ko badge lagate dekhta hai aur guard ko batata hai, 'Ali abhi andar aaya hai — usay dobara ID pooche baghair jaane do.' Captive portal purana tareeqa hai: har shakhs gate par ruk kar ID dikhata hai. MFA darwaze par doosra taala hai — chaabi ke saath woh code jo har 30 second mein badalta hai.STAS is like a receptionist who watches employees badge in and tells the guard, 'Ali just came in — let him through without asking for ID again.' The captive portal is the old way: every person stops at the gate and shows ID. MFA is the second lock on the door — the key plus a code that changes every 30 seconds.

سیٹ اپLab SetupLab Setup

sophos-04 سے جاری رکھیں۔ STAS کے لیے آپ کو ڈومین سے جڑا Windows سرور چاہیے جس پر STAS ایجنٹ انسٹال ہو (یا اسے simulate کر سکتے ہیں)۔ MFA کے لیے صرف ایک ٹیسٹ local یوزر اور فون پر authenticator ایپ (کوئی بھی TOTP ایپ) چاہیے۔sophos-04 se continue karein. STAS ke liye aap ko domain se jura Windows server chahiye jis par STAS agent install ho (ya isay simulate kar sakte hain). MFA ke liye sirf ek test local user aur phone par authenticator app (koi bhi TOTP app) chahiye.Continue from sophos-04. For STAS you need (or can simulate) a Windows server joined to a domain with the STAS agent installed. MFA needs only a test local user and a phone authenticator app (any TOTP app).

اقداماتStepsSteps

Step 1

STAS سمجھیں۔ STAS ایک ایجنٹ ہے جو آپ Windows ڈومین کنٹرولرز پر انسٹال کرتے ہیں۔ جب یوزر Windows میں لاگ اِن کرتا ہے تو ایجنٹ فائر وال کو بتاتا ہے 'اس IP کا مالک یہ یوزر ہے' — فائر وال پر الگ سے لاگ اِن کی ضرورت نہیں۔STAS samjhein. STAS ek agent hai jo aap Windows domain controllers par install karte hain. Jab user Windows mein login karta hai to agent firewall ko batata hai 'is IP ka maalik ye user hai' — firewall par alag se login ki zaroorat nahi.Understand STAS. STAS is an agent you install on Windows domain controllers. When a user logs in to Windows, the agent tells the firewall 'this IP belongs to this user' — no extra login needed on the firewall.

🖱️ Authentication > Servers — تصور سمجھیںAuthentication > Servers — concept samjheinAuthentication > Servers — study the concept

Step 2

AD سرور ایڈ کریں۔ ڈومین کنٹرولر کا IP، ڈومین نیم اور ایک سروس اکاؤنٹ دے کر Active Directory سرور انٹری بنائیں۔ کنیکشن ٹیسٹ کریں۔AD server add karein. Domain controller ka IP, domain name aur ek service account de kar Active Directory server entry banayein. Connection test karein.Add the AD server. Create an Active Directory server entry with the domain controller's IP, domain name, and a service account. Test the connection.

🖱️ Authentication > Servers > Add (Active Directory)Authentication > Servers > Add (Active Directory)Authentication > Servers > Add (Active Directory)

Step 3

STAS enable کریں۔ STAS سروس on کریں اور اسے ایجنٹ کے IP کی طرف پوائنٹ کریں۔ اب فائر وال رولز صرف IPs کے بجائے یوزرز اور گروپس سے میچ ہو سکتے ہیں (مثلاً 'HR گروپ کو انٹرنیٹ allow')۔STAS enable karein. STAS service on karein aur use agent ke IP ki taraf point karein. Ab firewall rules sirf IPs ke bajaye users aur groups se match ho sakte hain (masalan 'HR group ko internet allow').Enable STAS. Turn on the STAS service and point it to the agent's IP. Now firewall rules can match users and groups (e.g. 'allow HR group to the internet') instead of just IPs.

🖱️ Authentication > Services — STAS enable کریںAuthentication > Services — STAS enable kareinAuthentication > Services — enable STAS

Step 4

SSO ویریفائی کریں۔ ڈومین سے جڑے PC سے ٹریفک جنریٹ کریں اور لاگ ویوئر چیک کریں — انٹریز میں صرف IP نہیں، یوزر نیم نظر آنا چاہیے۔ یہی transparent SSO ہے۔SSO verify karein. Domain se jure PC se traffic generate karein aur log viewer check karein — entries mein sirf IP nahi, username nazar aana chahiye. Yehi transparent SSO hai.Verify SSO works. Generate traffic from a domain-joined PC and check the log viewer — entries should show the username, not just the IP. This is transparent SSO in action.

🖱️ Log viewer > View log viewer — یوزر identity چیک کریںLog viewer > View log viewer — user identity check kareinLog viewer > View log viewer — check user identity

Step 5

captive portal سے موازنہ کریں۔ STAS کے بغیر یوزرز کو براؤزنگ سے پہلے ایک لاگ اِن ویب پیج (captive portal) نظر آتا ہے۔ STAS ڈومین یوزرز کے لیے یہ زحمت ختم کر دیتا ہے۔Captive portal se mawazna karein. STAS ke baghair users ko browsing se pehle ek login web page (captive portal) nazar aata hai. STAS domain users ke liye ye zahmat khatam kar deta hai.Compare with the captive portal. Without STAS, users see a login web page (captive portal) before browsing. STAS removes that friction for domain users.

🖱️ Authentication > Services — captive portal (تصور)Authentication > Services — captive portal (concept)Authentication > Services — captive portal (concept)

Step 6

MFA enable کریں۔ ٹیسٹ یوزر کے لیے one-time password (OTP) on کریں۔ Authenticator ایپ سے QR کوڈ اسکین کریں اور پاس ورڈ کے ساتھ 6-digit کوڈ دے کر لاگ اِن کریں۔MFA enable karein. Test user ke liye one-time password (OTP) on karein. Authenticator app se QR code scan karein aur password ke saath 6-digit code de kar login karein.Enable MFA. Turn on one-time password (OTP) for a test user. Scan the QR code with an authenticator app and log in with password plus the 6-digit code.

🖱️ Authentication > One-time password — enable اور setup کریںAuthentication > One-time password — enable aur setup kareinAuthentication > One-time password — enable and set up

تصدیقVerifyVerify

لاگ ویوئر میں ڈومین ٹریفک کے لیے یوزر نیمز نظر آئیں، اور ٹیسٹ یوزر پاس ورڈ + OTP کوڈ سے لاگ اِن کرے۔ ایڈمن پورٹل پر OTP کے ساتھ لاگ اِن بھی کام کرے۔Log viewer mein domain traffic ke liye usernames nazar aayein, aur test user password + OTP code se login kare. Admin portal par OTP ke saath login bhi kaam kare.Log viewer shows usernames for domain traffic, and the test user logs in with password + OTP code. Admin portal login with OTP also works.

خرابی دور کرناTroubleshootingTroubleshooting

⚠️ لاگ ویوئر میں یوزر نیمز کے بجائے IPs نظر آ رہے ہیں۔Log viewer mein usernames ke bajaye IPs nazar aa rahe hain.Log viewer shows IPs instead of usernames.

✅ STAS کام نہیں کر رہا: چیک کریں کہ ایجنٹ ڈومین کنٹرولر پر چل رہا ہے، فائر وال اس تک پہنچ سکتا ہے (صحیح پورٹ)، اور PC ڈومین میں لاگ اِن ہے — لوکل اکاؤنٹ سے نہیں۔STAS kaam nahi kar raha: check karein ke agent domain controller par chal raha hai, firewall us tak pohnch sakta hai (sahi port), aur PC domain mein login hai — local account se nahi.STAS is not working: check the agent is running on the domain controller, the firewall can reach it (correct port), and the PC is logged in to the domain — not with a local account.

⚠️ OTP code صحیح لگنے کے باوجود reject ہو رہا ہے۔OTP code sahi lagne ke bawajood reject ho raha hai.The OTP code is rejected even though it looks correct.

✅ time-based کوڈز کے لیے گھڑیاں ملنی چاہئیں — فائر وال کا ٹائم چیک کریں (setup wizard، یا NTP سے sync کریں) اور فون کا ٹائم بھی۔ ایک منٹ کا فرق بھی فیل کر دیتا ہے۔Time-based codes ke liye ghariyan milni chahiyein — firewall ka time check karein (setup wizard, ya NTP se sync karein) aur phone ka time bhi. Ek minute ka farq bhi fail kar deta hai.Time-based codes need matching clocks — check the firewall's time (setup wizard, or synchronize with NTP) and the phone's time. Even a one-minute drift fails.

انٹرویو سوالاتInterview Q&AInterview Q&A

❓ STAS کیا ہے اور اس سے کیا حاصل ہوتا ہے؟STAS kya hai aur is se kya haasil hota hai?What is STAS and what does it achieve?

STAS (Sophos Transparent Authentication Suite) ایک ایجنٹ ہے جو Windows ڈومین کنٹرولرز پر انسٹال ہوتا ہے اور یوزر لاگ اِنز کی خبر فائر وال کو دیتا ہے، جس سے captive portal کے بغیر transparent single sign-on ملتا ہے۔STAS (Sophos Transparent Authentication Suite) ek agent hai jo Windows domain controllers par install hota hai aur user logins ki khabar firewall ko deta hai, jis se captive portal ke baghair transparent single sign-on milta hai.STAS (Sophos Transparent Authentication Suite) is an agent installed on Windows domain controllers that reports user logins to the firewall, enabling transparent single sign-on without a captive portal.

❓ فائر وال ایڈمن اور VPN رسائی کے لیے MFA کیوں استعمال کریں؟Firewall admin aur VPN access ke liye MFA kyun use karein?Why use MFA for firewall admin and VPN access?

MFA پاس ورڈ کے اوپر دوسرا فیکٹر (جیسے time-based one-time code) ایڈ کرتا ہے۔ اگر پاس ورڈ چوری بھی ہو جائے تو attacker کوڈ کے بغیر لاگ اِن نہیں کر سکتا۔MFA password ke upar doosra factor (jaise time-based one-time code) add karta hai. Agar password chori bhi ho jaye to attacker code ke baghair login nahi kar sakta.MFA adds a second factor (like a time-based one-time code) on top of the password. Even if the password is stolen, the attacker cannot log in without the code.