Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

SSL/TLS : ERR_CONNECTION_RESET Issue

Hi Support,

I hope someone can assist me. I've recently encountered an issue where some websites fail to load, displaying the error "ERR_CONNECTION_RESET."

Upon reviewing the log viewer, the issue is tagged under SSL/TLS Inspection with the following details:
ACTION: Error
Reason: Server did not respond to client hello

I have tried exempting these sites in the Firewall Rules and SSL/TLS settings, but the error "ERR_CONNECTION_RESET" persists. 

Firewall Rules:

SSL/TLS:

Below are the affected sites:

I'm using Sophos Home Firewall running SFOS 21.0.0 GA-Build169 

Looking forward to your guidance.



Added TAGs
[edited by: Erick Jan at 11:23 PM (GMT -8) on 30 Dec 2024]
Parents
  • Hi,

    which firewall rule is blocking the traffic? There is also  possibility that the tecmint site is using other URLs which you have blocked.

    Please post the bottom half of the firewall rule.

    A suggestion, you could simply your rules by using LAN as the source zone.

    Ian

    XG115W - v20.0.3 MR-3 - Home

    XG on VM 8 - v21 GA

    If a post solves your question please use the 'Verify Answer' button.

  • Hi  ,

    Thank you for your reply. The issue is related to my SSL/TLS policy ID 6 (MyExclusions). Please note that the firewall rules where these sites are whitelisted do not have web and app filtering enabled.

    The URLs belong to Information Technology and online shopping categories, which are not blocked by my web filtering. I’m using a single web filtering policy for all my LAN to WAN traffic, as detailed below:

    Web Policy (HomeWeb-Filter)

    List of web categories: Advertisements, Anonymizers, Auctions & Classified Ads, Command & Control, Criminal Activity, Gambling, Hacking,

    Marijuana, Nudity, Peer-to-peer & torrents, Personals & Dating, Phishing & Fraud, Pro-Suicide & Self-Harm, Sex Education, Sexually Explicit,

    Spam URLs, Spyware & Malware

    SSL/TLS Policy:

    Firewall Rules (MyExclusionList)

     

    I’ll keep your suggestion in mind. The reason I set up the LAN zoning was to easily identify each network within my home.

  • Hi,

    a zone and a network are different. You have identified each network in the network field.

    I have access the tecmint site without any issues and I have a way more complex firewall rule set.

    Further I would suggest you select the WEB proxy rather than the DPI. The SSL/TLS does not look at UDP packets where as the proxy does.

    Ian

    XG115W - v20.0.3 MR-3 - Home

    XG on VM 8 - v21 GA

    If a post solves your question please use the 'Verify Answer' button.

  • Hi    

    Yes, I mean using zones to separate my network into categories like HOME, PROXMOX, KIDS, etc., which utilize multiple networks to segregate them. However, I don’t think this setup is related to the current issue.

    By the way, can the WEB Proxy detect malware? I’m particularly concerned about files that might be downloaded by home users and the implementation of zero-day protection.

    As I’m new to Sophos, based on your experience, which is better in terms of security: DPI or Web Proxy? From my previous experience, I’ve used DPI with other firewall vendors.

  • Hi,

    I was suggesting using LAN zone because you have already identified your networks in the network field. I was suggesting the change to make rule modification and management easier. All your categories are LAN zone.

    The web proxy can detect malware though you will need to reduce the port range to http/s 

    Also to detect malware you will need to change applications to allow all and add LAN to WAN in IPS regardless of DPI or web proxy.

    Web proxy allows you to use google safe browsing etc which is not currently supported in DPI.

    Ian

    XG115W - v20.0.3 MR-3 - Home

    XG on VM 8 - v21 GA

    If a post solves your question please use the 'Verify Answer' button.

Reply
  • Hi,

    I was suggesting using LAN zone because you have already identified your networks in the network field. I was suggesting the change to make rule modification and management easier. All your categories are LAN zone.

    The web proxy can detect malware though you will need to reduce the port range to http/s 

    Also to detect malware you will need to change applications to allow all and add LAN to WAN in IPS regardless of DPI or web proxy.

    Web proxy allows you to use google safe browsing etc which is not currently supported in DPI.

    Ian

    XG115W - v20.0.3 MR-3 - Home

    XG on VM 8 - v21 GA

    If a post solves your question please use the 'Verify Answer' button.

Children