Configure the Sophos USM gateway

This topic describes how to configure Sophos USM to use the Sophos UTM RADIUS OIN app. There are four parts to this configuration:

  1. Enable automatic user creation
  2. Configure a new authentication server
  3. Create a RADIUS back-end group
  4. Allow group access to resources

Before you begin

  • Ensure that you have the common UDP port and secret key values available.

Enable automatic user creation

  1. In the Sophos UTM Web Admin Console, go to Definitions & UsersAuthentication Services.
  2. Click Add to define a new RADIUS server.
  3. On the Global Settings tab, select Create users automatically.
  4. In the Automatic User Creation for Facilities section, select the appropriate facilities for your environment. Select Client Authentication and End-User Portal.

Configure a new authentication server

  1. In the Sophos UTM Web Admin Console, go to Definitions & UsersAuthentication Services.
  2. Select the Servers tab.
  3. Click New Authentication Server and enter the following information:
    • Backend: Select RADIUS.
    • Postion: Select Top.
    • Server: Enter a unique and descriptive name, like OktaMFA.
    • Type: Enter the Host.
    • IPv4 address: Enter the IP address of the Okta RADIUS Server Agent.
    • Interface: Select the appropriate interface for your environment.
    • Port: Enter the UDP port that you want to use.
    • Shared secret: Enter the secret key that you want to use.
    • Authentication timeout (sec): Enter the length of the timeout period in seconds.
  4. Click Save.

Create a RADIUS back-end group

  1. In the Sophos UTM Web Admin Console, go to Definitions & UsersUsers & Groups.
  2. Select the Groups tab.
  3. Click New Group.
  4. Enter the following information in the Add Group section:
    • Group name: Enter a unique and appropriate name, like Okta RADIUS Users.
    • Group type: Select Backend membership.
    • Backend: Select RADIUS.
  5. Click Save.

Allow group access to resources

  1. In the Sophos UTM Web Admin Console, go to Remote Access.
  2. Select the desired connection method from the menu.
  3. Click New HTML5 VPN Portal Connection... or use an existing connection.
  4. Add the group that you created in Create a RADIUS back-end group to the Users and Groups or Allowed Users (Userportal) list.