Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

ATP Exceptions is not working

Hello everyone,

I have a problem with two FW (one on Azure, one XG)

We have a lot of detections like this (ATP)

 

We saw that this URL centos.brontocdn.com is legit and it's an official Centos Repo.

I allowed it here :

But both FW are still throwing the ATP detections..
And we are spam by email Smiley

Maybe I'm doing it wrong ?

Thanks for the help
Regards


Alexandre



This thread was automatically locked due to age.
Parents Reply
  • Hello, 

    Thanks for sharing this, On your Web Filter logs you may try to adjust time filter to Last10mins up to 4hours or on the search button on upper right you can directly type in centos.brontocdn.com and make sure logging is on in the firewall rule

    I tested the link on my SF and it has been detected as Spyware and therefore blocked as per my Web Filter Rules: 

    It seems the said link is a CDN link for CentOS. Could you clarify if this is detection is same on your end? and If your Web Filter rules also blocks this specific category? Also can you confirm what SFOS version you are running?

    If you have tried testing this via Policy Tester which is under Log Viewer > Policy Test and produced the same result and believe that this is a legitimate website:

    You may create an exception for this: docs.sophos.com/.../index.html

    And also file this to SophosLabs for submission: support.sophos.com/.../filesubmission

    Hope this helps. Thanks for your time and patience and thank you for choosing Sophos

    Cheers,

    Raphael Alganes
    Community Support Engineer | Sophos Technical Support
    Sophos Support Videos Product Documentation  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.

Children