Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

cannot access a specific website; TLS Handshake

Hello Everyone:

 

I've recently switched from DD-WRT to Sophos XG Home for all my routing duties (still using a DD-WRT device as my Wireless AP) and ran into a issue when I go to pay my utility bill.

[note: I am a Firefox guy, however I've seen similar errors in the "dreaded" Internet Explorer, and the "nosy" Google Chrome]

I've adjusted my web policy to allow all HTTP and HTTPS for "Anybody" (my main goal with Sophos XG Home was to setup Site-To-Site VPN's; not to Harden my Network).  I've also put in an Exception for the URL affected and it still does not allow me to proceed.  i've also turned off the Web Policy rule and all I would get after is "Page Cannot Be Displayed".

I can ping the affected URL from the Sophos XG Home and from my Windows PC. I've also tried this from another location where i've likewise installed Sophos XG Home and it works fine from there.  before I go finger-pointing my ISP.  I'd thought I would inquire about it here.

Any Suggestions would be welcome.



This thread was automatically locked due to age.
Parents
  • Ran into this same issue today, this is because Sophos XG incorrectly identifies the TLS Handshake traffic as TOR Proxy application traffic and if you have an Application Filter on that firewall rule it is Denied.

    You can get it to work again by allowing TOR Proxy in the Application Filter, although that's not ideal for obvious reasons.

Reply
  • Ran into this same issue today, this is because Sophos XG incorrectly identifies the TLS Handshake traffic as TOR Proxy application traffic and if you have an Application Filter on that firewall rule it is Denied.

    You can get it to work again by allowing TOR Proxy in the Application Filter, although that's not ideal for obvious reasons.

Children