Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

Use web proxy instead of DPI engine enabled mysteriously XGS116

We noticed that Microsoft Office was not updating, so we added the Microsoft Office exceptions as per Sophos Firewall: Configure web exceptions for Office 365.

Next, we encountered an issue where Google Chrome wouldn't install, so we added the exceptions outlined in Sophos Firewall: Unable to download Google Chrome.

However, users began reporting that websites were taking around 30 seconds to load. After extensive troubleshooting, we discovered that the "Use web proxy instead of DPI engine" option was enabled in the Default Network Policy firewall rule, causing routing issues.

We can confirm that we never enabled this setting, and it seems unlikely that it was enabled from day one, as we would have noticed this issue earlier.

We don't have any central policies applied. Has anyone else experienced this? Any insights on what might have caused this setting to be enabled would be appreciated.



Added TAGs
[edited by: Raphael Alganes at 11:15 PM (GMT -7) on 12 Aug 2024]
Parents
  • I've not seen that setting change automatically ever (we have a lot of systems under management, we are a MSP) --- my bet would be on a team member somewhere enabling it and not remembering, etc. to maybe troubleshoot something, or support, etc.

    CTO, Convergent Information Security Solutions, LLC

    https://www.convergesecurity.com

    Sophos Platinum Partner

    --------------------------------------

    Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries.  Use the advice given at your own risk.

Reply
  • I've not seen that setting change automatically ever (we have a lot of systems under management, we are a MSP) --- my bet would be on a team member somewhere enabling it and not remembering, etc. to maybe troubleshoot something, or support, etc.

    CTO, Convergent Information Security Solutions, LLC

    https://www.convergesecurity.com

    Sophos Platinum Partner

    --------------------------------------

    Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries.  Use the advice given at your own risk.

Children
No Data