Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

HTTP Scanning (Malware) Blocks ALL HTTP Websites

Hello everyone,

I am a paid Sophos customer with a subscription, however it is taking me too long to get anywhere with their support and I have a deployment tomorrow for a client so I am hoping someone will be able to help me.

I have an XG125 which I just updated to 15.01.0 MR-2.  I have a very simple configuration, with one local policy that allows LAN and WiFI to access the WAN on any port.  As soon as I enable "Scan HTTP", all HTTP websites generate a 502 error message.  If I change the scanning from Batch to Real Time, what usually happens is it tries to load the website but it is missing all formatting/images.  I'll show you pictures later in this thread.  I have tried with App Control, Web FIlter, IPS, and Traffic Shaping to None.  I have tried with Web Filter set to Default Work Policy (the policy I plan to deploy it with)... it doesn't make a difference.

My Sophos IP is 10.0.0.1, my workstation's IP is 10.0.0.52, my workstation's gateway is 10.0.0.1, and my workstation's DNS is 10.0.0.1.  The Sophos DNS server is my ISP's DNS and the IPs are provided in a screenshot.

I'll include as many screenshots as I can as I am hoping for a speedy resolution here or I'll have to turn off all malware scanning for my client.

Error Code with Batch Mode ON:

Site example with Real Time Scanning ON:

Policies:

Malware Setting (I have tried Avira to no avail)

Web Content Filter:

DNS Setting:

Firmware:



This thread was automatically locked due to age.
Parents
  • Additionally, here is a screenshot of my malware logs and security logs.  When I generated traffic I noticed a bunch of Allowed Traffic as well as a bunch of Invalid Denied Traffic...

    I've attached an Interfaces SS as well.  Port 1 is my workstation and port 2 is the WAN port.

    Malware Log:

    Security Log:

    Interfaces:

Reply
  • Additionally, here is a screenshot of my malware logs and security logs.  When I generated traffic I noticed a bunch of Allowed Traffic as well as a bunch of Invalid Denied Traffic...

    I've attached an Interfaces SS as well.  Port 1 is my workstation and port 2 is the WAN port.

    Malware Log:

    Security Log:

    Interfaces:

Children
No Data