<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Some websites get ERR_TIMED_OUT</title><link>https://community.sophos.com/sophos-xg-firewall/f/discussions/139056/some-websites-get-err_timed_out</link><description>Hello 
 I have been looking for this problem for a while now. 
 Support was useless. 
 On 2 different sites, at random moments, some websites are returning ERR_TIMED_OUT . 
 Site https://www.bankinter.com/ or another one point on a server on Azure. 
</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: Some websites get ERR_TIMED_OUT</title><link>https://community.sophos.com/thread/526277?ContentTypeID=1</link><pubDate>Fri, 21 Jul 2023 13:14:11 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:5e3a65e6-c910-4a82-b80e-8bf948d0c816</guid><dc:creator>Dragos Avram1</dc:creator><description>&lt;p&gt;Check if the firewall rule has an application filter. probably&amp;nbsp;&lt;a id="yui-gen1190"&gt;&lt;/a&gt;Block filter avoidance apps.&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Some websites get ERR_TIMED_OUT</title><link>https://community.sophos.com/thread/522570?ContentTypeID=1</link><pubDate>Mon, 15 May 2023 18:54:26 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:ce3a1c8a-94d1-41e7-b133-21eab05d167d</guid><dc:creator>Walter Burke</dc:creator><description>&lt;p&gt;Was this issue ever resolved? If so, what was the solution?&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Some websites get ERR_TIMED_OUT</title><link>https://community.sophos.com/thread/517893?ContentTypeID=1</link><pubDate>Fri, 03 Mar 2023 10:48:11 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:c8385427-3cf9-4dfc-9f80-94e3cfdc503f</guid><dc:creator>Erick Jan</dc:creator><description>&lt;p&gt;Hi FJay,&lt;/p&gt;
&lt;p&gt;The screenshot you&amp;#39;ve attached are not visible.&lt;/p&gt;
&lt;p&gt;based on the&amp;nbsp;previous FW rule log. It isnt hitting any FW rule logs and is being denied.&lt;/p&gt;
&lt;p&gt;Also, kindly add more information concerning the issue,&lt;/p&gt;
&lt;p&gt;1. What sites are experiencing err_timed_out&lt;/p&gt;
&lt;p&gt;2.&amp;nbsp;Create a test policy to allow any without Web policy&lt;/p&gt;
&lt;p&gt;3. Screenshot of&amp;nbsp; FW logs and the FW rule you&amp;#39;ve created&lt;/p&gt;
&lt;p&gt;4. Screenshot of SSL/TLS&amp;nbsp;configuration and logs after accessing the site.&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;I would recommend creating a case so that it can be properly investigated,&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Some websites get ERR_TIMED_OUT</title><link>https://community.sophos.com/thread/517834?ContentTypeID=1</link><pubDate>Thu, 02 Mar 2023 14:43:23 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:0be1da2f-fd89-4127-9885-4ec530c85e31</guid><dc:creator>FJay</dc:creator><description>&lt;p&gt;Hi Erick Jan,&lt;/p&gt;
&lt;p&gt;Thank you again.&lt;/p&gt;
&lt;p&gt;I have created a rule at the top : no go.&lt;/p&gt;
&lt;p&gt;I added the TLS rule as shown : to no avail. Still ERR_TIMED_OUT.&lt;/p&gt;
&lt;p&gt;Here is what I have in logs :&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;img src="/resized-image/__size/1280x960/__key/communityserver-components-multipleuploadfilemanager/5655e03e_2D00_183d_2D00_4b09_2D00_a4e0_2D00_cc3159eb7ead-231925-complete/Screenshot-2023_2D00_03_2D00_01-at-13.07.53.png" alt=" " /&gt;&lt;img src="/resized-image/__size/1280x960/__key/communityserver-components-multipleuploadfilemanager/5655e03e_2D00_183d_2D00_4b09_2D00_a4e0_2D00_cc3159eb7ead-231925-complete/Screenshot-2023_2D00_03_2D00_01-at-13.05.22.png" alt=" " /&gt;&lt;/p&gt;
&lt;p&gt;Does it help ?&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Fab&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Some websites get ERR_TIMED_OUT</title><link>https://community.sophos.com/thread/517731?ContentTypeID=1</link><pubDate>Wed, 01 Mar 2023 11:39:06 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:2cf26467-e572-4271-b7a2-68ce1811ab71</guid><dc:creator>Erick Jan</dc:creator><description>&lt;p&gt;Hi Fjay,&lt;/p&gt;
&lt;p&gt;Upon checking your FW logs, It is being denied.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Can you create a test policy to allow the said site on the very top.&lt;/li&gt;
&lt;li&gt;Also, create an SSL/TLS Policy with the following if what you said that &amp;quot;&lt;span&gt;I went to TLS/SSL inspection but there is nothing there.&amp;quot;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img src="/resized-image/__size/1280x960/__key/communityserver-discussions-components-files/126/pastedimage1677668716379v1.png" alt=" " /&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;For Exception, you can try to follow the following link:&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&amp;nbsp;&lt;a href="https://community.sophos.com/sophos-xg-firewall/f/discussions/138422/server-did-not-respond-to-client-hello"&gt;Server did not respond to client hello&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Can you share your SSL/TLS log after accessing the site like below&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img src="/resized-image/__size/1280x960/__key/communityserver-discussions-components-files/126/pastedimage1677670689753v1.png" alt=" " /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Some websites get ERR_TIMED_OUT</title><link>https://community.sophos.com/thread/517715?ContentTypeID=1</link><pubDate>Wed, 01 Mar 2023 10:24:42 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:dddcfb2d-22aa-4f52-921e-45d882174804</guid><dc:creator>FJay</dc:creator><description>&lt;p&gt;Hi again,&lt;/p&gt;
&lt;p&gt;I went to the Exceptions... and apparently I tried that already (sorry it has been so long we have this issue...)&lt;/p&gt;
&lt;p&gt;&lt;img src="/resized-image/__size/1280x960/__key/communityserver-discussions-components-files/126/Screenshot-2023_2D00_03_2D00_01-at-11.22.48.png" alt=" " /&gt;&lt;/p&gt;
&lt;p&gt;Is this correct ?&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Some websites get ERR_TIMED_OUT</title><link>https://community.sophos.com/thread/517714?ContentTypeID=1</link><pubDate>Wed, 01 Mar 2023 10:21:41 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:ff015b4c-3bd4-4c3a-880a-960b24f226cc</guid><dc:creator>FJay</dc:creator><description>&lt;p&gt;Hi Erick Jan,&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;
&lt;p&gt;Thank you for looking.&lt;/p&gt;
&lt;p&gt;Funny to see how cases like that are closed by Sophos. But that&amp;#39;s the past.&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;
&lt;p&gt;Anyway, it seems a lot faster and to the point here. Let&amp;#39;s give it a try !&lt;/p&gt;
&lt;p&gt;This is what I get in the Firewall logs for one of the site I am trying to reach :&lt;/p&gt;
&lt;p&gt;&lt;img alt=" " height="425" src="/resized-image/__size/2012x850/__key/communityserver-discussions-components-files/126/Screenshot-2023_2D00_03_2D00_01-at-11.12.55.png" width="1006" /&gt;&lt;/p&gt;
&lt;p&gt;I will add the exceptions as you suggested.&lt;br /&gt;Would I have to continue adding any other site that doesn&amp;#39;t work when Sophos is in the chain ?&lt;br /&gt;&lt;br /&gt;For the TLS/SSL, could you guide me on where you want me to grab that ?&amp;nbsp;&lt;/p&gt;
&lt;p&gt;I went to TLS/SSL inspection but there is nothing there.&lt;/p&gt;
&lt;p&gt;Thank you very mush for your help.&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;Fab&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Some websites get ERR_TIMED_OUT</title><link>https://community.sophos.com/thread/517710?ContentTypeID=1</link><pubDate>Wed, 01 Mar 2023 10:11:29 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:b503eb45-f135-45f9-b7e9-7f1983ec2e2d</guid><dc:creator>Erick Jan</dc:creator><description>&lt;p&gt;Hi FJay,&lt;/p&gt;
&lt;p&gt;Good day, Upon checking on the cases.&lt;/p&gt;
&lt;p&gt;Case &lt;strong&gt;05657043&lt;/strong&gt;&lt;br /&gt;The case was closed due to No Answer from the Customer side.&lt;/p&gt;
&lt;p&gt;Case &lt;strong&gt;05156521&lt;/strong&gt;&lt;br /&gt;The case was closed as the issue does not reside within Sophos Firewall&lt;/p&gt;
&lt;p&gt;Also, based on the screenshot of your SSL/TLS Logs on the previous post, It indicates that &amp;quot;&lt;strong&gt;Server did not respond to client Hello&lt;/strong&gt;&amp;quot;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Have you tried Excluding the domain by creating a new exception (web &amp;gt; Exceptions &amp;gt; Add) and checking all the skip actions&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;a href="https://docs.sophos.com/nsg/sophos-firewall/18.5/Help/en-us/webhelp/onlinehelp/AdministratorHelp/Web/Exceptions/index.html"&gt;https://docs.sophos.com/nsg/sophos-firewall/18.5/Help/en-us/webhelp/onlinehelp/AdministratorHelp/Web/Exceptions/index.html&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Can you share the TLS/SSL log when accessing the said sites?&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;I would recommend creating another case so that it can be properly investigated and kindly share the case#&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Some websites get ERR_TIMED_OUT</title><link>https://community.sophos.com/thread/517639?ContentTypeID=1</link><pubDate>Tue, 28 Feb 2023 15:05:49 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:6128ec9c-eea4-4a35-b9a1-cc0d7419ba9b</guid><dc:creator>Erick Jan</dc:creator><description>&lt;p&gt;Hi FJay,&lt;/p&gt;
&lt;p&gt;Thank you for the information. Will further check the issue.&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Some websites get ERR_TIMED_OUT</title><link>https://community.sophos.com/thread/517634?ContentTypeID=1</link><pubDate>Tue, 28 Feb 2023 14:47:27 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:333326b3-ac7d-4791-9cf8-f12535e8aa66</guid><dc:creator>FJay</dc:creator><description>&lt;p&gt;Cases&amp;nbsp;&lt;span&gt;05657043,&amp;nbsp;05156521and Discussion on this platform :&amp;nbsp;&lt;a href="/sophos-xg-firewall/f/discussions/135886/tcp-retransmission-rst-ack---some-websites-not-answering"&gt;https://community.sophos.com/sophos-xg-firewall/f/discussions/135886/tcp-retransmission-rst-ack---some-websites-not-answering&lt;/a&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Some websites get ERR_TIMED_OUT</title><link>https://community.sophos.com/thread/517630?ContentTypeID=1</link><pubDate>Tue, 28 Feb 2023 14:41:30 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:8a501724-c5f5-4c47-930d-556e593a0816</guid><dc:creator>FJay</dc:creator><description>&lt;p&gt;Tried all the options to no avail.&lt;/p&gt;
&lt;p&gt;I tried also no IPv6 address and any combination of internal DNS, ISP DNS and Google/Cloudflare DNS.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Some websites get ERR_TIMED_OUT</title><link>https://community.sophos.com/thread/517629?ContentTypeID=1</link><pubDate>Tue, 28 Feb 2023 14:40:30 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:ee89ba10-1d3c-4011-9b39-02396740d943</guid><dc:creator>PhilippRusch</dc:creator><description>&lt;p&gt;Could you try using IPv4 DNS resolution only? Disable IPv6?&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Some websites get ERR_TIMED_OUT</title><link>https://community.sophos.com/thread/517618?ContentTypeID=1</link><pubDate>Tue, 28 Feb 2023 14:09:17 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:0c2c080e-c625-47bc-a215-3eb571a14ba9</guid><dc:creator>Erick Jan</dc:creator><description>&lt;p&gt;Hi FJay,&lt;/p&gt;
&lt;p&gt;Thank you for reaching out to Sophos Community.&lt;/p&gt;
&lt;p&gt;I apologies for the experienced. Would it be possible to share your case ID. Thank you&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Some websites get ERR_TIMED_OUT</title><link>https://community.sophos.com/thread/517612?ContentTypeID=1</link><pubDate>Tue, 28 Feb 2023 13:35:32 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:fdb71071-67b0-4a98-8b81-704847a323a3</guid><dc:creator>FJay</dc:creator><description>&lt;p&gt;Hi Philip,&lt;/p&gt;
&lt;p&gt;Thank you for the reply.&lt;/p&gt;
&lt;p&gt;Sorry if it is unspecific. I&amp;#39;ll try to make it clearer.&lt;/p&gt;
&lt;p&gt;2 Sites, both in HA.&lt;/p&gt;
&lt;p&gt;One Has XG2100 (19.0.1) and the other XG2300 (19.5MR1).&lt;/p&gt;
&lt;p&gt;1. There is no upstream proxy. I don&amp;#39;t get MASQ on the uplink port. MASQ is linked to the FW rule&lt;/p&gt;
&lt;p&gt;2. Here you go.&lt;br /&gt; &lt;img height="456" src="/resized-image/__size/1384x912/__key/communityserver-discussions-components-files/126/Screenshot-2023_2D00_02_2D00_28-at-14.02.46.png" width="692" alt=" " /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img height="462" src="/resized-image/__size/1218x924/__key/communityserver-discussions-components-files/126/Screenshot-2023_2D00_02_2D00_28-at-14.03.03.png" width="609" alt=" " /&gt;&lt;/p&gt;
&lt;p&gt;3. 19.0.1 on one site and 19.5MR1 on the other.&lt;/p&gt;
&lt;p&gt;4. I have checked the cabling on both sites, change from HA A/A to A/P, remove HA. Remove second appliance completely, remove the second internet line, change the internet line. I have replaced the XG2100 by a UDMPro to test and discard any other equipment -&amp;gt; This is working like a breeze.&lt;br /&gt;5. Yes indeed. On one site I have Telefonica and Orange. On the other I have Proximus and Colt.&lt;br /&gt;&lt;br /&gt;I am sorry if it was not clear enough and I am happy to add anything that might help.&lt;/p&gt;
&lt;p&gt;This is what I get...&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;&lt;img height="510" src="/resized-image/__size/1110x1020/__key/communityserver-discussions-components-files/126/pastedimage1677589716030v1.png" width="555" alt=" " /&gt;&lt;/p&gt;
&lt;p&gt;Thank you very much for your time.&lt;/p&gt;
&lt;p&gt;Fab&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Some websites get ERR_TIMED_OUT</title><link>https://community.sophos.com/thread/517605?ContentTypeID=1</link><pubDate>Tue, 28 Feb 2023 12:52:11 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:59d78a7d-5b03-4db5-bd83-33b1f48bfed6</guid><dc:creator>PhilippRusch</dc:creator><description>&lt;p&gt;Did you give more infos in your earlier/older post?&lt;/p&gt;
&lt;p&gt;I find your explanations very unclear and unspecific:&lt;/p&gt;
&lt;p&gt;1. You switched off filtering for testing, ok. But do you use the proxy, if yes, which mode? Did you implement a MASQ rule for the ISP uplink port?&lt;/p&gt;
&lt;p&gt;2. You &amp;quot;checked&amp;quot; the DNS? How? Show us the configuration. please. (paste screenshot)&lt;/p&gt;
&lt;p&gt;3. At least we know the release version your are on.&lt;/p&gt;
&lt;p&gt;4. Do you have a second firewall with HA in place? Is your cabling correct?&lt;/p&gt;
&lt;p&gt;5. What do you mean by &amp;quot;changed the internet connection&amp;quot;? Do you have different providers you can use alternatively?&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;We are volunteers trying to help, but we do not have a crystal ball.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>