This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Firefox (especially Gmail) cannot complete some requests: no responses are returned (zero bytes), assume that because of Endpoint Agent

It is almost impossible to use Gmail (mail.google.com) in Firefox. There are no problems in Chrome on the same machine.

In the browser developer console / Network tab I see some requests are without responses (zero bytes responses). Some with SSL_ERROR_BAD_MAC_ALERT

GMail app constantly shows yellow warning: "Ups... the system encountered a problem. Retrying in ..." .  "Retry now" link doesn't help.

Similar errors discussed recently: https://community.sophos.com/sophos-central/f/discussions/133650/ssl_error_bad_mac_alert-pr_end_of_file_error



This thread was automatically locked due to age.
Parents
  • Sophos AV is interfering with all components of google apps (worlds largest email platform - gmail) with the 3rd most used browser (firefox, 2nd largest if you dis-include safari) and it's been a couple of weeks now with no fix. I've tried various browser tweaks, created ticket with my firewall vendor and the problem when away by entering the tamper protection password and disabling Sophos. So what's the solution? Right now it's disabling Sophos, but what good is Sophos if it's disabled right?

Reply
  • Sophos AV is interfering with all components of google apps (worlds largest email platform - gmail) with the 3rd most used browser (firefox, 2nd largest if you dis-include safari) and it's been a couple of weeks now with no fix. I've tried various browser tweaks, created ticket with my firewall vendor and the problem when away by entering the tamper protection password and disabling Sophos. So what's the solution? Right now it's disabling Sophos, but what good is Sophos if it's disabled right?

Children
  • Do you find disabling SSL/TLS decryption helps?  If so, that is probably the safest config change as it means you can leave Network Threat Protection enabled, web protection and web control enabled. Domains accessed will still be looked up using the SNI.  I suppose it all depends on if disable decryption helps?  As a check on the endpoint

    HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\Management\Policy\ThreatProtection\[latest revision]\web_protection

    https_decrypt_enabled = 1 or 0