Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

new Sophos XGS - Webclients are unable to reach URLs but DNS works

Hi all,

we moved from LANcom to Sophos XGS SFOS 20.0.2. Fine so far.

We migrated last night. Now it comes more and more, that some webclients are unable reach some URLs.

Every clients are able to resolve every DNS name. But when putting that DNS name into browser half of the clients are getting a timeout. this happens not to alle URLs but some. We migrated DHCP range exactly as it was before, all clients have Sophos as DNS server. No proxy is in place.

Putting the LANcom router as gateway all is fine...

Any ideas?

Thanks for help Gernot



Added TAGs
[edited by: Raphael Alganes at 12:14 AM (GMT -7) on 23 Aug 2024]
Parents Reply
  • Hi   Please find the answer below:

    Google Chrome and Microsoft Edge have enabled and introduced the PQ Kyber key exchange algorithm (hybridized Kyber support) from version 124 onwards which increases the Client Hello packet size to be more than the MTU in SSL TLS handshake and a device further in the chain does not support IP fragmentation, leading to the flow to fail.

    If you would like to check around this in detail, you may capture the PCAP on the end machine and generate browsing of the website for which the issue is getting triggered from Chrome or Edge and in the client hello check the below details:

    So here solution is to disable Kyber support on the browser which you may try as per the previous steps or another way is to reduce the MTU on the WAN interface of the XGS which would negate the need for fragmentation. A good starting point is to set it to 1420 and so on until it fixes! 

    With a Sophos Firewall in place without a workaround, this will be fixed once the path MTU discovery support is implemented in the future SF OS release as in feature enhancement and as of now above workaround will help to manage the situation.

    For more info below KBA will help, KBA is pointing to Sophos Central Endpoint-protected macOS but in general, it applies to Windows OS and Firewall too. There is a section in the same KBA for "Sophos Firewall".

    Unable to browse the internet using Google Chrome or Microsoft Edge after version 124 update
    support.sophos.com/.../KBA-000009276

    Regards,

    Vishal Ranpariya
    Technical Account Manager | Sophos Technical Support

    Sophos Support Videos | Knowledge Base  |  @SophosSupport | Sign up for SMS Alerts |
    If a post solves your question use the 'Verify Answer' link.

Children