This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SSP.exe creating lots of traffic

We have been investigating issues with our firewalls and one thing I noticed is i have been seeing hundred and hundred of hits from ssp.exe to our firewall

Client base is over 500!


These seem to be amazon IP Address, why is it talkign too these and what is ssp.exe?



This thread was automatically locked due to age.
Parents
  • Same issue here, the SPP Service is killing our Sophos UTM with more than 400000 blocked reqests on Port 80 instead of 8080.

    We need a Hotfix for this immediatly. Our entire network is collapsing because of this fail feature !!!

  • OK, SSP uses port 443. Can you allow 443 out to 4.sophosxl.net?

    Can you let me see some of your logs? Pm me.

  • Same issue as of 10.6 update. Sophos support stated we can clear the check box for "Detect malicious behavior" to stop this traffic. This does not seem to be correct as this setting is already disabled in one of our A/V policies yet we are seeing traffic coming from those endpoints.

    For now, we have elected to stop the new Sophos service on the endpoints until we have an way to disable this via Sophos policies.

  • Hi Craig, 4.sophosxl.net is allowed for http, https, and dns traffic in our UTM firewall. We also added it to the skip proxy auth. rule for this url.

    But there is still thousands of packets sent directly to our Sophos UTM. Thist traffic instantly stops when i disbale the SSP service on

    the monitored endpoint. i dont understand why the service keeps sending the packets directly to the UTM appliance insted of sending it to 4.sophosxl.net.

Reply
  • Hi Craig, 4.sophosxl.net is allowed for http, https, and dns traffic in our UTM firewall. We also added it to the skip proxy auth. rule for this url.

    But there is still thousands of packets sent directly to our Sophos UTM. Thist traffic instantly stops when i disbale the SSP service on

    the monitored endpoint. i dont understand why the service keeps sending the packets directly to the UTM appliance insted of sending it to 4.sophosxl.net.

Children