Hello Everyone:
I've recently switched from DD-WRT to Sophos XG Home for all my routing duties (still using a DD-WRT device as my Wireless AP) and ran into a issue when I go to pay my utility bill.
[note: I am a Firefox guy, however I've seen similar errors in the "dreaded" Internet Explorer, and the "nosy" Google Chrome]
I've adjusted my web policy to allow all HTTP and HTTPS for "Anybody" (my main goal with Sophos XG Home was to setup Site-To-Site VPN's; not to Harden my Network). I've also put in an Exception for the URL affected and it still does not allow me to proceed. i've also turned off the Web Policy rule and all I would get after is "Page Cannot Be Displayed".
I can ping the affected URL from the Sophos XG Home and from my Windows PC. I've also tried this from another location where i've likewise installed Sophos XG Home and it works fine from there. before I go finger-pointing my ISP. I'd thought I would inquire about it here.
Any Suggestions would be welcome.
Hi thewi2kbug
Please try packet capture to analyze- https://community.sophos.com/kb/en-us/127647 and https://community.sophos.com/kb/en-us/123189
Regards,
Keyur
Community Support Engineer | Sophos Support
Sophos Support Videos | Knowledge Base | @SophosSupport | Sign up for SMS Alerts |
If a post solves your question use the 'This helped me' link
Ran into this same issue today, this is because Sophos XG incorrectly identifies the TLS Handshake traffic as TOR Proxy application traffic and if you have an Application Filter on that firewall rule it is Denied.
You can get it to work again by allowing TOR Proxy in the Application Filter, although that's not ideal for obvious reasons.
Hi Ryan Maclachlan
Allowing TOR is not an option to resolve the issue, we cannot compromise on that front.
I would request you to contact technical support to investigate the issue further or try the packet capture to analyze the traffic, please also share more information about your scenario.
Regards,
Keyur
Community Support Engineer | Sophos Support
Sophos Support Videos | Knowledge Base | @SophosSupport | Sign up for SMS Alerts |
If a post solves your question use the 'This helped me' link