This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

unable to connect to SUM4.

I actually had this issue popup using ACC3.  My Sophos v9 is dropping 4433(which is the acc protocol) by default even though i have it set to be open.  Sophos 9 will simply not allow that port tob e open and it'sd a bit frustrating..[:)]


This thread was automatically locked due to age.
  • ok i've verified that it is sum4 not looking for the acc protocol on any port i give it..any ideas?

    Owner:  Emmanuel Technology Consulting

    http://etc-md.com

    Former Sophos SG(Astaro) advocate/researcher/Silver Partner

    PfSense w/Suricata, ntopng, 

    Other addons to follow

  • Check your NAT / packet filter rules, works fine here.

    Make sure you have SUM configured to allow access from the hosts that are connecting to it; I find folks forget about this setting sometimes.

    CTO, Convergent Information Security Solutions, LLC

    https://www.convergesecurity.com

    Sophos Platinum Partner

    --------------------------------------

    Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries.  Use the advice given at your own risk.

  • here's what the remote astaros have to say:
    2012:12:27-15:54:53 hhab device-agent[31956]: [1] ACC connection failure, retrying (ip=98.233.178.9, port=4433). SSL-connect: 'IO::Socket::INET configuration failederror:00000000:lib(0):func(0):reason(0)'
    2012:12:27-15:54:59 hhab device-agent[31956]: [1] ACC connection failure, retrying (ip=98.233.178.9, port=4433). SSL-connect: 'IO::Socket::INET configuration failederror:00000000:lib(0):func(0):reason(0)'
    2012:12:27-15:55:00 hhab device-agent[31956]: [1] Connection failed (ip=98.233.178.9, port=4433).

    now my own astaro can reach the sum4 jsut fine..but the packets are getting dropped by the sophos 9 machine:
    2012:12:27-15:55:58 firewall ulogd[4191]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60001" initf="eth1" srcmac="0:1:5c:32:e7:1" dstmac="0:f4:cd:46:f3:a2" srcip="71.176.140.97" dstip="98.233.178.9" proto="6" length="60" tos="0x00" prec="0x20" ttl="52" srcport="51742" dstport="8080" tcpflags="SYN" 

    i have ips and http and all other proxies off..only thing that's going is nat and firewall.

    Owner:  Emmanuel Technology Consulting

    http://etc-md.com

    Former Sophos SG(Astaro) advocate/researcher/Silver Partner

    PfSense w/Suricata, ntopng, 

    Other addons to follow

  • Check your NAT / packet filter rules, works fine here.

    Make sure you have SUM configured to allow access from the hosts that are connecting to it; I find folks forget about this setting sometimes.


    the interesting thing is my rule hasn't changed in years:
    DNAT
    Traffic selector: Any → Astaro Command Center (ACC) → External (WAN) (Address)
    Destination translation: ACC
    Automatic Firewall rule:
    Initial packets are logged:
    the port def for the Astaro Command Center is 4433.

    Owner:  Emmanuel Technology Consulting

    http://etc-md.com

    Former Sophos SG(Astaro) advocate/researcher/Silver Partner

    PfSense w/Suricata, ntopng, 

    Other addons to follow

  • I don't know why but i would up having to blow out the dns host listing inside of sum for the affected machines and recreating them..that fixed it..weird.

    Owner:  Emmanuel Technology Consulting

    http://etc-md.com

    Former Sophos SG(Astaro) advocate/researcher/Silver Partner

    PfSense w/Suricata, ntopng, 

    Other addons to follow

  • I just encountered this exact problem,
    My solutions was actually stupidly easy but also easily missed.
    My external Firewalls are connecting to the SUM4 via a DNS Host defenition. this defenition in turn was set to use the wrong external interface.
    A few easy clicks changed that for me.
    Definitions & Users > Network Definitions > Look for the SUM Host in question > Edit > Advanced > Interface.

    I hope this helps
  • I am having somewhat the same issue but for me everything worked great until I installed and updated 220. The original 220 was at 8.3 and this new one is at 9.2... I cannot figure out why this new 220 will not talk to my UTM 4. HELP!!!!!!!   :-)