This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Webfilter Websites are not opening

Hello,

I have Sophos UTM FW: 9.506-2 Version Webfiltering - Transparent Mode activated. In the last time, some websites are not opening. Checked with Firefox , Safari and Chrome to be sure its not a browser issue. When opening the websites on my Mobile with GSM Connection, the Websites open fine. 

 

WHen checking the following example urls, in Policy Helpdesk Test, they are allowed, but not open via the connection over the UTM.

 

http://xoco.no

http://www.viennatour.at

 

Any Idea what can be the Problem, how I can solve this. Other websites are working fine.

 

Thx

Best Regards

Sally

 



This thread was automatically locked due to age.
Parents Reply Children
  • Eth2 Gateway must be the VPN router ip

  • Hello,

     

    after your recommendation, to set router IP as Gateway for eth2 the Internet Connection works. When checking with traceroute, the internet traffic goes over the vpn tunnel to internet, thats perfect.

     

    But the following pages still not work:

    salsanena.at

    viennatour.at

    xoco.no

     

    Please see attached the masquerading rules, they are still active, do I have to change there yet also something?

     

    Thx

    Sally

  • ping those pages directly from UTM with their name not IP. Maybe is a DNS broblem. Or maybe skip those host in Web Filter to not check anything.

    One problem at a time [:D]

  • Ok, pinging the 3 Pages above from UTM over VPN Interface, there is no reply. Pinging other working websites I get an reply .

    Doing nslookup from Client, the DNS Resolution for the none working websites is working.

     

    Where can i try to skip the host from webfilter?

     

    Thx

     

     

  • Masquerading must be only 2 for internals networks Internal -> Uplink Interfaces. DMZ Media - Uplink Interfaces
    UTM will decide what to masquerade based on Multipath Routes and Priority in Uplink Balancing. Maybe you still have a policy route or static route there. And this can cause loopback proxy problems

  • Ok, I adapted the masquerading. But I have to leave also the rule Internal Network - DMZ Media, otherwise the RDP Connection to the media server isn't working ..

     

    Can you please tell me where I can exactly take out the filtering from Webfilter, to test if the problem comes from the Filter??

     

    Thx

    Sally

  • Under Interfaces - Uplink Balancing active Interfaces are the External (WAN) and second the DMZ VPN are included, do I have to sort there the interfaces like DMZ VPN first, and after the External (WAN) or is this not relevant?

  • Since you made the Multipath Rules it is not necessary sorting. 

    If You cant ping those pages from UTM the problem isn't in the web filter. I checked and the 3 pages respond to ping, two are hosted in Austria and one in USA

    Now the problem is excluded from webfilter, because ping has nothing to do with it. Is there any NAT Rules, Firewall Rules or Country Blocking?

  • I checked, there is no NAT Rule, Country Blocking is activated but off for Austria and United States. Firewall Rules are:

     

    Internal - Any - DMZ VPN (Network)

    DMZ VPN Network - DNS, FTP, HTTP, HTTPS, NTP, PING - Internet IPv4

     

    What I have still set from the previous Configuration is: 

    Web Protection - Filtering Options - Misc - Skip Transparent Source Mode Hosts / Nets - and have there defined Laptop, Phones, Printer etc.

     

     

     

  • Define those hosts in Skip Transparent Mode Destination Hosts/Nets. Just to see what happens