Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

FILT-APP Block Office365 SOPHOS XGS

Hello,

I have recently see my officesetup.exe installation blocked when I activated the app-filter based on this policy "Block generally unwanted apps" on my LAN TO WAN firewall rule.

This blocked was manifest juste after launch the officesetup.exe, the installation window be blocked on "Prepare your environnement". Sometimes blocked to the next step with the downloading window.

I not found any log during debug.

The cause categorie seems to be "File Transfert" categorie because when I allow this, the installation work instant.

My questions is:
- How I can debug this from logs ?

- Somebody already impacted by and soluce this ?

Thank you in advance for help.



Edited TAGs
[edited by: emmosophos at 5:02 PM (GMT -7) on 17 Jun 2024]
Parents Reply
  • Hello  ,

    Thanks for the additional details.

    If you find the "Multi Thread File Transfer" is the legitimate traffic that's being blocked under "File Transfer Category" and you still want to block the category File Transfer, here's what I may recommend:

    You may select the application individually,

    Then set to - Allow

    Then put this on top of the of your Application Filter list, then Configure a Select All for File Transfer then set it to deny

    Then set it below your Allow rule on the application filter, so the arrangement would look like this: 

    - You may also further add any applications you need to allow on top of your deny rules. 

    - For your testing, I may recommend you test it on a Firewall Rule on Top using specific settings, e.g. test it on 1 host only before completely applying the application filter to the whole network.

    - Further, denied applications on your rules can be seen under Log Viewer > Application Filter 

    Hope this helps. Have a nice day and thank you for choosing Sophos.

    Cheers,

    Raphael Alganes
    Community Support Engineer | Sophos Technical Support
    Sophos Support Videos Product Documentation  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.

Children