This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

WebFilter and https://outlook.office.com or https://outlook.office365.com "Host not found" HELP

Okay, so I have setup the Web Filtering and using the transparent mode. I have added exceptions for Office 365 as we're using Microsoft Office 365 for SharePoint and Exchange. Which all has been working well and I cannot tell by the error what is occurring here when the Outlook Web Access (OWA) is reporting invalid HTTPS cert (from the UTM) as well the error reads Host not found.

UTM Error Page:

While trying to retrieve the URL:
The content could not be delivered due to the following condition:
Host not found
Your cache administrator is:
MyEmail@apexanalog.com
Testing done:
I have reviewed  the web filter live log (if you would like to see) which shows status codes 200, 502 then final of 304.
The Base Policy is one that states blocks when testing https://outlook.office.com/owa the exception is listed. The Reason is Host not found. So, I am really lost with this error reason. https://outlook.office365.com/owa works with the Policy HelpDesk. Is this a DNS issue cause testing this in browser it varies from outlook.office.com to outlook.office365.com.
I cannot figure out where this is getting hung up. I have web filter options to allow many Office 365 items. This is the only one complaining. The SSL warning before reaching the page is from Astaro the UTM, and I did not think I would get such since I am using transparent mode web filtering.
Please let me know what I can look at, at this point I am drawing a blank. There is no reason I see as to why this should be occurring.
Any assistance would be greatly appreciated. Thanks in advance!


This thread was automatically locked due to age.
Parents
  • 200 means the request was successfully proxied. 304 means the client set a conditional GET and the server is saying that the document wasn't modified. 502 often means a compatibility issue between the Proxy and the server. Please show us the log line(s) related to one of these problem accesses.
    .Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • 200 means the request was successfully proxied. 304 means the client set a conditional GET and the server is saying that the document wasn't modified. 502 often means a compatibility issue between the Proxy and the server. Please show us the log line(s) related to one of these problem accesses.
    .Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
  • Bob, thank you for grabbing this.

    As requested here is log showing block today:

    Hope this format works (its messy as logs often are) any suggestion for posting logs is appreciated.


    2016:01:14-12:14:54 apex-ualpha httpproxy[6557]: id="0002" severity="info" sys="SecureWeb" sub="http" name="web request blocked" action="block" method="CONNECT" srcip="192.168.101.89" dstip="" user="" ad_domain="" statuscode="502" cached="0" profile="REF_DefaultHTTPProfile (Default Web Filter Profile)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="0" request="0xdd00c800" url="https://outlook.office.com/" referer="" error="Host not found" authtime="0" dnstime="184" cattime="0" avscantime="0" fullreqtime="254369" device="0" auth="0" ua="" exceptions="content,url,mime,cache,fileextension,size"

    2016:01:14-12:14:54 apex-ualpha httpproxy[6557]: id="0002" severity="info" sys="SecureWeb" sub="http" name="web request blocked" action="block" method="CONNECT" srcip="192.168.101.89" dstip="" user="" ad_domain="" statuscode="502" cached="0" profile="REF_DefaultHTTPProfile (Default Web Filter Profile)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="0" request="0xe12b7800" url="https://outlook.office.com/" referer="" error="Host not found" authtime="0" dnstime="13" cattime="0" avscantime="0" fullreqtime="222755" device="0" auth="0" ua="" exceptions="content,url,mime,cache,fileextension,size"

    2016:01:14-12:14:55 apex-ualpha httpproxy[6557]: id="0002" severity="info" sys="SecureWeb" sub="http" name="web request blocked" action="block" method="CONNECT" srcip="192.168.101.89" dstip="" user="" ad_domain="" statuscode="502" cached="0" profile="REF_DefaultHTTPProfile (Default Web Filter Profile)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="0" request="0xa231800" url="https://outlook.office.com/" referer="" error="Host not found" authtime="0" dnstime="3" cattime="0" avscantime="0" fullreqtime="214847" device="0" auth="0" ua="" exceptions="content,url,mime,cache,fileextension,size"

    2016:01:14-12:14:58 apex-ualpha httpproxy[6557]: id="0002" severity="info" sys="SecureWeb" sub="http" name="web request blocked" action="block" method="CONNECT" srcip="192.168.101.89" dstip="" user="" ad_domain="" statuscode="502" cached="0" profile="REF_DefaultHTTPProfile (Default Web Filter Profile)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="0" request="0xdd2e5000" url="https://outlook.office.com/" referer="" error="Host not found" authtime="0" dnstime="3" cattime="0" avscantime="0" fullreqtime="206980" device="0" auth="0" ua="" exceptions="content,url,mime,cache,fileextension,size"

    2016:01:14-12:14:58 apex-ualpha httpproxy[6557]: id="0002" severity="info" sys="SecureWeb" sub="http" name="web request blocked" action="block" method="CONNECT" srcip="192.168.101.89" dstip="" user="" ad_domain="" statuscode="502" cached="0" profile="REF_DefaultHTTPProfile (Default Web Filter Profile)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="0" request="0xdc650800" url="https://outlook.office.com/" referer="" error="Host not found" authtime="0" dnstime="2" cattime="0" avscantime="0" fullreqtime="228903" device="0" auth="0" ua="" exceptions="content,url,mime,cache,fileextension,size"

    2016:01:14-12:14:58 apex-ualpha httpproxy[6557]: id="0002" severity="info" sys="SecureWeb" sub="http" name="web request blocked" action="block" method="CONNECT" srcip="192.168.101.89" dstip="" user="" ad_domain="" statuscode="502" cached="0" profile="REF_DefaultHTTPProfile (Default Web Filter Profile)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="0" request="0xe16f2800" url="https://outlook.office.com/" referer="" error="Host not found" authtime="0" dnstime="13" cattime="0" avscantime="0" fullreqtime="208951" device="0" auth="0" ua="" exceptions="content,url,mime,cache,fileextension,size"

    2016:01:14-12:14:59 apex-ualpha httpproxy[6557]: id="0002" severity="info" sys="SecureWeb" sub="http" name="web request blocked" action="block" method="CONNECT" srcip="192.168.101.89" dstip="" user="" ad_domain="" statuscode="502" cached="0" profile="REF_DefaultHTTPProfile (Default Web Filter Profile)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="2552" request="0xdfa6f800" url="https://outlook.office.com/" referer="" error="Host not found" authtime="0" dnstime="3" cattime="0" avscantime="0" fullreqtime="212043" device="0" auth="0" ua="" exceptions="content,url,mime,cache,fileextension,size"

    2016:01:14-12:14:59 apex-ualpha httpproxy[6557]: id="0001" severity="info" sys="SecureWeb" sub="http" name="http access" action="pass" method="CONNECT" srcip="192.168.101.89" dstip="64.4.54.165" user="" ad_domain="" statuscode="200" cached="0" profile="REF_DefaultHTTPProfile (Default Web Filter Profile)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="7668" request="0xd8ac7800" url="https://urs.microsoft.com/" referer="" error="" authtime="0" dnstime="3" cattime="0" avscantime="0" fullreqtime="240078" device="0" auth="0" ua="" exceptions="av,content,url,ssl,mime,cache,fileextension,size"
    2016:01:14-12:14:59 apex-ualpha httpproxy[6557]: id="0001" severity="info" sys="SecureWeb" sub="http" name="http access" action="pass" method="CONNECT" srcip="192.168.101.89" dstip="132.245.47.82" user="" ad_domain="" statuscode="200" cached="0" profile="REF_DefaultHTTPProfile (Default Web Filter Profile)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="8269" request="0xdda61800" url="outlook.office365.com/" referer="" error="" authtime="0" dnstime="3" cattime="0" avscantime="0" fullreqtime="121796319" device="0" auth="0" ua="" exceptions="content,url,mime,cache,fileextension,size"

    2016:01:14-12:14:59 apex-ualpha httpproxy[6557]: id="0002" severity="info" sys="SecureWeb" sub="http" name="web request blocked" action="block" method="CONNECT" srcip="192.168.101.89" dstip="" user="" ad_domain="" statuscode="502" cached="0" profile="REF_DefaultHTTPProfile (Default Web Filter Profile)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="0" request="0xdeefe800" url="https://outlook.office.com/" referer="" error="Host not found" authtime="0" dnstime="2" cattime="0" avscantime="0" fullreqtime="237435" device="0" auth="0" ua="" exceptions="content,url,mime,cache,fileextension,size"

    2016:01:14-12:14:59 apex-ualpha httpproxy[6557]: id="0002" severity="info" sys="SecureWeb" sub="http" name="web request blocked" action="block" method="CONNECT" srcip="192.168.101.89" dstip="" user="" ad_domain="" statuscode="502" cached="0" profile="REF_DefaultHTTPProfile (Default Web Filter Profile)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="0" request="0xd92bb800" url="https://outlook.office.com/" referer="" error="Host not found" authtime="0" dnstime="3" cattime="0" avscantime="0" fullreqtime="237698" device="0" auth="0" ua="" exceptions="content,url,mime,cache,fileextension,size"

    2016:01:14-12:14:59 apex-ualpha httpproxy[6557]: id="0001" severity="info" sys="SecureWeb" sub="http" name="http access" action="pass" method="CONNECT" srcip="192.168.101.89" dstip="64.4.54.165" user="" ad_domain="" statuscode="200" cached="0" profile="REF_DefaultHTTPProfile (Default Web Filter Profile)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="7668" request="0xdc36b800" url="https://urs.microsoft.com/" referer="" error="" authtime="0" dnstime="3" cattime="0" avscantime="0" fullreqtime="253547" device="0" auth="0" ua="" exceptions="av,content,url,ssl,mime,cache,fileextension,size"

    2016:01:14-12:14:59 apex-ualpha httpproxy[6557]: id="0002" severity="info" sys="SecureWeb" sub="http" name="web request blocked" action="block" method="CONNECT" srcip="192.168.101.89" dstip="" user="" ad_domain="" statuscode="502" cached="0" profile="REF_DefaultHTTPProfile (Default Web Filter Profile)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="0" request="0xdf0c8800" url="https://outlook.office.com/" referer="" error="Host not found" authtime="0" dnstime="14" cattime="0" avscantime="0" fullreqtime="209556" device="0" auth="0" ua="" exceptions="content,url,mime,cache,fileextension,size"

    2016:01:14-12:15:10 apex-ualpha httpproxy[6557]: id="0001" severity="info" sys="SecureWeb" sub="http" name="http access" action="pass" method="CONNECT" srcip="192.168.101.89" dstip="23.7.136.70" user="" ad_domain="" statuscode="200" cached="0" profile="REF_DefaultHTTPProfile (Default Web Filter Profile)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="4233" request="0xe1916000" url="https://auth.gfx.ms/" referer="" error="" authtime="0" dnstime="63369" cattime="0" avscantime="0" fullreqtime="20091013" device="0" auth="0" ua="" exceptions="content,url,mime,cache,fileextension,size"

    2016:01:14-12:15:10 apex-ualpha httpproxy[6557]: id="0001" severity="info" sys="SecureWeb" sub="http" name="http access" action="pass" method="CONNECT" srcip="192.168.101.89" dstip="23.7.136.70" user="" ad_domain="" statuscode="200" cached="0" profile="REF_DefaultHTTPProfile (Default Web Filter Profile)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="4233" request="0xa232800" url="https://auth.gfx.ms/" referer="" error="" authtime="0" dnstime="65714" cattime="0" avscantime="0" fullreqtime="20097027" device="0" auth="0" ua="" exceptions="content,url,mime,cache,fileextension,size"

    2016:01:14-12:15:10 apex-ualpha httpproxy[6557]: id="0001" severity="info" sys="SecureWeb" sub="http" name="http access" action="pass" method="CONNECT" srcip="192.168.101.89" dstip="23.7.136.70" user="" ad_domain="" statuscode="200" cached="0" profile="REF_DefaultHTTPProfile (Default Web Filter Profile)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="4233" request="0xdc049000" url="https://auth.gfx.ms/" referer="" error="" authtime="0" dnstime="65129" cattime="0" avscantime="0" fullreqtime="20096881" device="0" auth="0" ua="" exceptions="content,url,mime,cache,fileextension,size"

    2016:01:14-12:15:10 apex-ualpha httpproxy[6557]: id="0001" severity="info" sys="SecureWeb" sub="http" name="http access" action="pass" method="CONNECT" srcip="192.168.101.89" dstip="23.7.136.70" user="" ad_domain="" statuscode="200" cached="0" profile="REF_DefaultHTTPProfile (Default Web Filter Profile)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="4233" request="0xe1814800" url="https://auth.gfx.ms/" referer="" error="" authtime="0" dnstime="3" cattime="0" avscantime="0" fullreqtime="20028278" device="0" auth="0" ua="" exceptions="content,url,mime,cache,fileextension,size"

    Anything else, please let me know.

    Thanks in advance,

    Joel \

  • Yes, you need to skip the proxy for outlook.office.com and auth.gfx.ms. Although you might be able to solve the problem by skipping AV and maybe SSL scanning altogether for them.

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA