Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Workstations on LAN fail to resolve play.google.com

Hello All, 

Using Sophos XG310 Firmware 18.5.4 MR-4 Build 418

I have an unusual issue, essentially all workstations on the LAN of the Sophos Firewall are unable to access play.google.com

Originally it appeared to be due to perhaps Web Filtering or Application control, created a temporary firewall rule to allow all traffic but the issue persisted

To scope the issue, I proceeded to check various computers to see if the issue was isolated to the affected computer, and as stated, all workstations were affected. HOWEVER, all of the servers on the LAN appear to be unaffected.

I begun utilizing the Policy Tester to compare and contrast why servers could access play.google.com and workstations couldn't, if there may be a rule or policy affecting one versus the other, but as depicted below, I was green lighted by the Policy Tester for both source IPs

I begun then begun to compare the IP configurations of the machines since we have various VLANs, but nothing explicit was comparable until I begun to run ping and tracert from the affected machines.

For some reason when I run tracert on the affected machines, it appears to fail to resolve and loopback play.google.com (127.0.0.1)

But for the Servers, they show what you would expect

Since all computers go through the same ISP based off the tracert, It looks like the workstations can't even hit the gateway/interface, so I'm wondering if this looks like a DNS isue or an issue with workstations reaching the listening port.



This thread was automatically locked due to age.
  • Hi,

    the issue will be with your DHCP server handing out the wrong or no gateway. Servers are usually fixed addressing the gateway is usually manually configured.

    Ian

    XG115W - v20.0.2 MR-2 - Home

    XG on VM 8 - v21 GA

    If a post solves your question please use the 'Verify Answer' button.

  • Hmmm...you may have a point, when I was examining the connection issue on a test computer and setup a manual IPv4 configuration on a test PC, it actually gave me an error regarding the gateway/subnet, then the machine lost internet connection. 

  • Hi Pablo Porta

    Please check the logs under Log Viewer, check Application filter and Web filter logs with policy applied on firewall rule to point into the right direction to fix the issue 

    Check drop packet capture 

    drop-packet-capture 'host play.google.com'

    "Sophos Partner: Networkkings Pvt Ltd".

    If a post solves your question please use the 'Verify Answer' button.