Hi everyone,
last week I have enabled web protection on our Sophos UTM. So far things work out - more or less - as expected. I still need to do some tweaking and get familiar with the settings etc. to improve filtering. However, this is not a real issue at the moment since I am forwarding mails from Sophos to a second spam filtering solution.
However, I have one issue that is quite strange. I have several sites connected to my central UTM and users from these sites can all access the "release" link in the quarantine mail without problems - all sites but one. Trying to access the internal IP of the main sophos utm shows a default drop for ports 80/443/3840 basically any port on that interface in the firewall log.
Does anyone have any idea what the issue might be?
FYI: I have web filtering and application filtering as well as intrusion prevention enabled. I already tried adding an exception for the problem site's IP range without any success.
FYI 2: I have also tried adding manual firewall rules at the very top of the rule list without success.
Thanks.
best regards
Martin
This thread was automatically locked due to age.