This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

UTM blocking many but not all https

I created a Web Protection profile and am seeing strange behavior.
The firewall log is fulling up with blocks on port 443 from the device and
the web protection logs also show hundreds of http access requests being passed.

Many programs like my New York Times app can't connect (it says it's offline) but my web browser does.

I'm not sure how to troubleshoot given the Web Filtering is port 443 and it's logs are showing it's managing traffic from this device.
Why is it managing only some of the https traffic?



This thread was automatically locked due to age.
Parents
  • Copy here a line or two from the Firewall log where 443 is blocked from the device.  In 'Web Filtering', on the 'HTTPS' tab, is 'Decrypt and scan' selected, or ??? Also, confirm that there's nothing related in the 'Transparent Mode Skiplists' on the 'Misc' tab.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • Copy here a line or two from the Firewall log where 443 is blocked from the device.  In 'Web Filtering', on the 'HTTPS' tab, is 'Decrypt and scan' selected, or ??? Also, confirm that there's nothing related in the 'Transparent Mode Skiplists' on the 'Misc' tab.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
No Data