This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Randomly no connection to internet websites but could ping urls works.

Hi guys.
I know there are some thread similar, but this one is different and very strange.

Randomly, once or twice a day, for about one to 5 minutes, we are loosing connection to internet.
Right after that time every thing go back to normal again.

Few thing to noticed:

1. We still can ping Urls

2. DNS seems to work.

3. Accessing URL which are in the DMZ doesn't work as well.

4. I'm not sure if there are more fore shorter time, but this what i know of from my customers.

 

Any help will be appreciate.
[:)]

Goldy



This thread was automatically locked due to age.
  • Hi,

     

    no, we aren't getting the root partition filling up messages. I guess disk space is not an issue with us.

     

    Franc.

  • I was obviously not doing a good job of multitasking, Franc!  I saw that the directory was taking up 3.5 GB and thought that it was on dev/sda6 - the / directory that only has 5.2GB, regardless of disk size.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Sophos just confirmed with us that this is a known issue in the latest version 9.703-3 with specific configurations (I don't know the details yet). It will be fixed in the next update which will be released in the coming weeks. They are looking if they can supply a hotfix for the issue and install it on our systems.

  • yippee ki-yay.

    At least we are going somewhere.

    Strangely, I think there was some similar issues before the last update.

     

    Goldy.

     

  • We're having a very similar issue (proxy times out intermittently while other services such as routing,NAT,firewall,antispam work normally) with 9.702. Also experienced the same problem with 9.604 and 9.605 back in October 2019, although at that time we were informed that vmotioning the UTM nodes (both nodes are vms and the HA's active/passive) without rebooting them can cause some weird stuff. We started shutting the nodes down during vmotion and had no reported instability for months until this past June, with it worsening in July.

    We use standard web filtering. I have firewall rules set up for my system to bypass the proxy, so it is easy to confirm Internet access is up when these outages occur. I did some playing around with transparent filter as well, and that had the same issue as the standard filter.

    I put a ticket in with Sophos and am following this particular thread with great interest. Hopefully a solution'll be found!

  • Our machines aren't VM's. They are two SG330's in HA.

     

    Franc.

  • Since Snort is all the same, my suspect that there was an update in the snort that cause this issue.

  • Hi Guys.

    Not sure if it's the reason, but I have switched the antivirus from Sophos to Avira in the Firewall, and for about 6 hours all is quite....
    I'll keep monitoring and let you know. [:O]

  • Hi Guys.

    Just got it from Sophos Support:

    We had found http was reloading multiple times and as per the update from our GES Team, the below workaround solution should help resolve the issue :-

    1. <M> mhgate:/root # cc

    2. 127.0.0.1 MAIN > http

    3. 127.0.0.1 MAIN http > sc_local_db$

    4. 127.0.0.1 MAIN http/sc_local_db (LISTPICK) > none

    This should not be causing any impact to connections

     

  • Did this work for you? Sophos is working on our case for 2 weeks now, but they can’t find a cause and don’t have a solution yet. Do you have a case ID so that I can give that to Sophos support for more info?