This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

DPI Engine Bypass

Hello,

If I have a firewall rule that has a web policy set to none, so why does the DPI engine still scan the traffic? I thought this was fixed. Still seeing the traffic in the SSL inspection logs. I would really like to reduce the CPU load for traffic I don't want scanned. Running 18.5.1 MR-1, but this has been an issue since the new DPI engine was introduced. I haven't noticed it in awhile since traffic has been low, but I'm now moving a lot of data around and the XG is scanning traffic it shouldn't.

Mike



This thread was automatically locked due to age.
Parents
  • I think you need to change your web policy to allow all.

    ian

    XG115W - v20 GA - Home

    XG on VM 8 - v20 GA

    If a post solves your question please use the 'Verify Answer' button.

  • I did that, but I also had to check the use proxy option. I don’t want the firewall to look at the traffic at all, not even the proxy.

    It’s crazy to think I can’t create a firewall rule that has no options, to bypass the DPI. You would think setting all options to none would be the answer. Not in Sophos world.

  • well you can turn off the SSL/TLS inspection but it does for all firewall rules.

    If you choose allow all in there web proxy with the services of any the proxy doesn't really inspect the traffic.

    The other option I use is don't log, none in web, none in application and none in IPS but you need to be very sure of your destination/destination.

    Ian

    XG115W - v20 GA - Home

    XG on VM 8 - v20 GA

    If a post solves your question please use the 'Verify Answer' button.

Reply
  • well you can turn off the SSL/TLS inspection but it does for all firewall rules.

    If you choose allow all in there web proxy with the services of any the proxy doesn't really inspect the traffic.

    The other option I use is don't log, none in web, none in application and none in IPS but you need to be very sure of your destination/destination.

    Ian

    XG115W - v20 GA - Home

    XG on VM 8 - v20 GA

    If a post solves your question please use the 'Verify Answer' button.

Children
  • Yeah I can’t turn off SSL inspection completely. 

    Yes, you’re right, an allow all rule doesn’t really inspect the traffic with the proxy, but it does have to look at it for the allow all rule to work. It’s unnecessarily using resources to do so. 

    Even using a rule that doesn’t log,  it still passes traffic to the DPI engine, you just don’t see it. I proved this in the V18 beta and thought they fixed it.