Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

https decrypt and scan not working on v18 GA

Hi,

 

I have an XG 106.  Just upgraded to latest SFOS 18.0.0.0 GA-Build321.  I am not getting any traffic decrypted/scanned and pages are coming up with their original certs instead of my Sophos.  

 

Here is the rule log as well as screenshot of the rule.   It's my default rule.

 

2020-02-22 19:45:05Firewallmessageid="00001" log_type="Firewall" log_component="Firewall Rule" log_subtype="Allowed" status="Allow" con_duration="33" fw_rule_id="5" nat_rule_id="5" policy_type="1" user="" user_group="" web_policy_id="12" ips_policy_id="0" appfilter_policy_id="0" app_name="DNS" app_risk="1" app_technology="Network Protocol" app_category="Infrastructure" vlan_id="0" ether_type="Unknown (0x0000)" bridge_name="" bridge_display_name="" in_interface="Port1" in_display_interface="Port1" out_interface="Port2" out_display_interface="Port2" src_mac="xxx" dst_mac="xxx" src_ip="xxx" src_country="R1" dst_ip="xxx" dst_country="AUS" protocol="UDP" src_port="61647" dst_port="53" packets_sent="1" packets_received="1" bytes_sent="63" bytes_received="115" src_trans_ip="xxx" src_trans_port="0" dst_trans_ip="" dst_trans_port="0" src_zone_type="LAN" src_zone="LAN" dst_zone_type="WAN" dst_zone="WAN" con_direction="" con_event="Stop" con_id="xxx" virt_con_id="" hb_status="No Heartbeat" message="" appresolvedby="Signature" app_is_cloud="0"

 

 

 

Thanks



This thread was automatically locked due to age.
Parents Reply Children
  • Hi,

    That rule shows do not decrypt so it will not be scanned. You need to create your own rule of what you want scanned.

    ian

    XG115W - v20.0.2 MR-2 - Home

    XG on VM 8 - v20.0.2 MR-2

    If a post solves your question please use the 'Verify Answer' button.