This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Website not accessible via Firewall XG

Hi all,

Need assistance as Sophos Support unable to assist further.

I facing an issue where one of the website not able to access through Sophos Firewall XG.

It is not blocked by Policy or whatever.

I tried Trace Route. The website stopped at Firewall IP.

Destination website:  daimler.com

Destination IP: 141.113.99.106

Attached is some of the test i did from Sophos Firewall - website status.

I tried to do whitelist the website as suggested by Sophos Support but same result too.

Please advice.

Thanks.



This thread was automatically locked due to age.
Parents
  • It is a parked domain which you might've blocked.

    Ian

    XG115W - v20 GA - Home

    XG on VM 8 - v20 GA

    If a post solves your question please use the 'Verify Answer' button.

  • Hi ian, Thanks for your reply.

    Unfortunately, it's not.  we don't have or set any parked domain.

    I found that it could be NAT issue. will check it out and troubleshoot after off work later.

    Any others possibility? Thanks man.

  • FormerMember
    0 FormerMember in reply to Charles Ng1

    Hi ,

    The URL is accessible only on HTTPS == https://www.daimler.com

    Did you find any denied logs in log viewer under web filter/IPS?

    I'd suggest allowing all sub-domains as well. They can be found from the browser's Developers tolls > Security option.

    You can check the packet flow by following the below steps.

    ==> Login to SSH > 4. Device Console

    console> tcpdump 'host 141.113.99.106

    or

    console> tcpdump 'host www.daimler.com

    ==> Try to browse the website with https://www.daimler.com URL and share the first 6-7 lines here or via PM.

    Could you please also take an observation with a plain LAN to WAN firewall rule with no web/app restrictions?

  • sorry my mistake, a typing error. I have full access to that site when using the correct spelling.

    Ian

    XG115W - v20 GA - Home

    XG on VM 8 - v20 GA

    If a post solves your question please use the 'Verify Answer' button.

Reply Children