This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XG CA and latest macOS break web sites

Hi foks,

I am running v19.5.1 on the XG and macOS13.3 on the mac book pro and mc air.

A couple of sites no longer work and the default is https even though I enter hrttp.If I use a hotspot the issue is not observed.

I have a mac mini in which the XG CA was not trusted and the sites all work correctly. after I trusted the XG CA on the mac mini the site broke and default to https.

I tried regenerating the CA that broke all the mail access as well as the http sites. I installed the CA on the MBP, the ipad and the iPhone. 

I have restored a backup from yesterday and mail is now working.

I will try again in the morning with just the XG CA regeneration.

Any thoughts on the subject?

Ian



This thread was automatically locked due to age.
  • I have performed a lot of testing this morning.

    1/. cleared history

    2/. cleared cache

    3/. used firewall rules with no policies, IP4 and IPv6

    4/. crested an exception

    5/. log viewer does not show any errors, but does show successful connections. (Application, web and SSL/TLS)

    6/. works fine while using hotspot or access on iPhone.

    Where to next?

    Ian

    XG115W - v20 GA - Home

    XG on VM 8 - v20 GA

    If a post solves your question please use the 'Verify Answer' button.

  • I have identified the cause, the Unifi AP is the common item. When treating via a hardwire connection everything works correctly.

    So moree investigation required at my end.

    Ian

    It was working via the cable, but not now.

    XG115W - v20 GA - Home

    XG on VM 8 - v20 GA

    If a post solves your question please use the 'Verify Answer' button.

  • Please explain the following.

    The last entry is with the web exception in place. The appears to be an intermittent bug in handling some websites. Sometimes it works and other times fail with an odd error message.

    'You are not authorized to view this page.

    Firewall Rule:NotAllowed'

    XG115W - v20 GA - Home

    XG on VM 8 - v20 GA

    If a post solves your question please use the 'Verify Answer' button.

  • Hello  ,

    Good day and thanks for reaching out to Sophos Community.

    I tried the mentioned website on the policy test and I did not experience the intermittent result by far - Im using Windows w/o DPI 

    May we ask if the last entry happens to websites in random or just this specific one on the example? And does this happen only on you MacOS devices? 

    Thanks

    Raphael Alganes
    Community Support Engineer | Sophos Technical Support
    Sophos Support Videos Product Documentation  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.

  • Hi Raphael,

    currently I have access via the mac mini safari and my iPad. The MBP fails so does muy iPhone. The W11 machine is having network issues.

    My main access is via the web proxy both IP4 and IPv6.

    I have two websites that are having issues coles.com.au and ht.com.au. All the sites I have tested I can access, this forum keeps dropping connections and needs to be reauthenticated many times a day. I can't test two other devices at the moment they are in use.

    Ian

    update - the mac air fails.

    All devices now failing.

    XG115W - v20 GA - Home

    XG on VM 8 - v20 GA

    If a post solves your question please use the 'Verify Answer' button.

  • I performed a configuration roll back to the day before the ISP/RSP made some network changes also to the configuration before I changed the IPv6 configuration and addresses thinking I made a mistake in the conversion.

    I have again created a web exception for coles.com.au which currently appears to have fixed the issue. There was a lot of disable/reenable configurations to get this far.

    The issue appears to be how xg handles IPv6 which in this case is very slowly causing the browsers to think the attempted connection has timed out and throw up errors.

    More testing because I am not satisfied with the solution and need to update the internal IPv6 addressing.

    Ian

    XG115W - v20 GA - Home

    XG on VM 8 - v20 GA

    If a post solves your question please use the 'Verify Answer' button.

  • Fixed. The rollback configuration and the recreate the IPv6 new address ranges appears to have fixed the issue along with another issue.

    The import of the new IPv6 configuration took over an hour to complete. The performance of the XG is improved and appears to be stable.

    Ian

    XG115W - v20 GA - Home

    XG on VM 8 - v20 GA

    If a post solves your question please use the 'Verify Answer' button.