WhatsApp Issue with Web Protection

hello everyone 

 

when ever i turn on web protection for a rule users who can use internet through this rule can use whatsapp application on there phones or web whatsapp

i tried to make a workaround for web whatsapp and created a top rule that allow access to web whatsapp and turned off web protection and that solved web whatsapp problem 

now my problem is with the application it self it wont work until i turn off the web protection 

although i made exception for it in the PROTECT>Web>Exceptions and checked the log viewer and it is all green and all http and https scan & Decrypt  are turned off 

is there any solution for this issue ?

thank you 

  • In reply to Michael Ploch1:

    ok, that did not last long...

    I had the same delay some hours ago. Messages just aren't sent without delay, if I switch to mobile data on smartphone, message is sent immediately. If I keep staying in my wifi, there is a delay about 2 minutes... more or less...

     

    As a last step I try to deactivate all firewall policies for that device and disable pharming protection.

    If problem although occurs, I would say it is not a Sophos issue, is it? Whats your opinon? What else could it be? Do you see any else options how I could debug my issue?

    Thanks a lot, Michael

  • In reply to Michael Ploch1:

    Hi,

    Try reviewing the DNS settings on the failing device.

    Ian

  • In reply to rfcat_vk:

    it is the firewall als dns and my providers dns servers.

    what else can I review here? normal webbrowsing and everything else works like a charm...

  • In reply to Michael Ploch1:

    Hey Michael, was going through my rules and forgot that i have specified my services for my general rule and within the services i created a whatsapp service of ports that whatsapp uses.

     

    so for my general rule i allow https, smtp..etc

  • Having the same issue here whatsapp application strangely stops working for some users and sometimes for all users, I am running 17.1 tried everything and quite frankly the logs don't help at all "God I wish they didn't change how logs were implemented in UTM), anyway it seems like disabling application filter rule helped; the rule was for blocking p2p and tunneling/vpn, gaming applications and youtube and had the whatsapp allowed on the top of the rules, I ended removing the vpn/tunneling rule and the application started to work. I couldn't find any indication in the logs that can help me figure out what vpn/tunnel application was mistakenly resembles whatsapp traffic. The only solution to add them gradually and see when the issue appears again.

  • In reply to Christopher Moss:

    Good point about the ports.  https://www.quora.com/What-is-the-port-number-for-whatsapp

     

    If that is not it, then:


    The problem could be something with web browsing (eg HTTP or HTTPS).  However it could also be DNS timeout or something on some custom ports it uses.  It can be hard to tell, especially since it is hard to packet capture on a mobile device.
     
    Are you doing HTTPS Decryption?  If you are, maybe the app does not like the CA.  You can try disabling it in the firewall rule or in an exception.
     
    If you temporarily put in a high level firewall rule for Source Any Destination Any Service Any with no malware protection or application or web policies (basically super wide open) does that resolve the issue?  If so, then start closing the rule to where is starts being slow.
  • In reply to Michael Ploch1:

    Well after testing it, it was the pharming protection

    I disable it and all went well, I have applied all my web and application rules again and all working fine till this moment...

  • In reply to Michael Ploch1:

    So, few days later, just to be sure thats a problem in my sophos I deactivated all firewall filters and pharming protection. Just had "scan http " option active. I never had the HTTPS scan option active. Do not need that at the moment. First have to get it working without that option to lower complexity.

    What shall I say, it just worked!

    As a next step I will reactivate setting by setting and see what happens. I will start with activating pharming protection and will see.

    I hop to drill down the problem within the next days. Depending on where it stucks, I will try to implement the ideas of the community I have heard so far..

    Thank you in advance, Michael

  • In reply to Michael Ploch1:

    Waiting to see your results.