This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Webfilter Websites are not opening

Hello,

I have Sophos UTM FW: 9.506-2 Version Webfiltering - Transparent Mode activated. In the last time, some websites are not opening. Checked with Firefox , Safari and Chrome to be sure its not a browser issue. When opening the websites on my Mobile with GSM Connection, the Websites open fine. 

 

WHen checking the following example urls, in Policy Helpdesk Test, they are allowed, but not open via the connection over the UTM.

 

http://xoco.no

http://www.viennatour.at

 

Any Idea what can be the Problem, how I can solve this. Other websites are working fine.

 

Thx

Best Regards

Sally

 



This thread was automatically locked due to age.
Parents Reply Children
  • Hello Bob,

    there are no blocks for xoco.no and www.viennatour.at in the Webfilter Log.

    What else I can check?

     

    Thx

    Regards

    Sally

     

  • So, the accesses are bypassing the proxy?  If that's the case and there are no blocks in the Firewall log, does #3.1 in Rulz help?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Hello Bob,

    I have the following configuration:

    Internal Network:

    192.168.0.0
    255.255.255.0
    GW: 192.168.0.1
    DNS: 192.168.0.1

    DMZ VPN Network:

    10.0.0.3
    255.0.0.0
    GW: 10.0.0.1
    DNS: 10.0.0.1

    Interfaces - Static Routing - Policy Routes:

    Target:  VPN Router DMZ
    Internal (Networks) - Internal - Any - Internet IPV4

    1. When I have the Policy Route activated Internet Connection is working but some Pages are not working like xoco.no, sovats.com etc.
    2. When I deactivate the Policy Route and the Internet Connection don't go over the VPN Connection, complete all Pages are working
    3. When I connect my Laptop directly to the VPN Router in the DMZ all Pages are working

    Web Filtering Global Allowed Networks:

    Internal Network
    DMZ VPN Network 

    What can be the issue? 

    Thx

    Regards

    Sally

  • It's not a good idea to use a 10.0.0.0/8 subnet.  What happens if you change that to a /24 subnet?

    I'm confused by your topology.  What is your VPN router doing?  Where is your WAN connection?  Maybe we could start with a picture of your 'Interfaces' tab...

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Hello Bob,

     

    i changed the subnet to 10.0.0.0 /24, same result, some of the websites are not opening.

     

     

    The VPN Router in the DMZ is configured as VPN Client and is connected to the PIA VPN Service. The Router is in Gateway Mode, and with the Policy Route all traffic from internal network should be routed over the VPN Connection to the Internet

     

    Thx

    Sally

  • Hello,

     

    I have still the issue, any idea how I can fix this?

     

    Thx

  • Hello,

     

    I updated the UTM to Firmware Version: 9.508-10. I still have the issue that some websites are not open, and nothing is in the logfile that the pages somehow get blocked.

     

    When I go to Interfaces & Routing - Static Routing - Policy Routes and turn off the following Policy Routes the Websites are working:

     

    Target: Linksys

    Selector: Internal Network - Internal - Any - Internet IPV4

     

    How can I get this fixed?

     

    Thanks a Lot!

     

    Best Regards

    Sally

  • The topology of your network is missing.
    Anyway UTM resolved this with Multipath Rules.
    Static Routes it is used only to access one device or network, but only by firewall rules. You have to Skip the host from Transparent Services to get it done (Web Filter/ Email Protection)
    Web Filter too has outgoing interface option (you have to enable it) 

  • Hello oldeda,

     

    thanks for your reply. Under Web Protection - Filtering Options - Misc - Transparent Mode Skiplist - Skip Transparent Mode Source Hosts/Nets I have already the Host defined. What you mean with Web Filter too has outgoing interface option, where I can enable this?

     

    Thx

    Best Regards

    Sally