This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Webpages are not showing correctly - UTM in transparent mode

Hi,

We currently have a Sophos UTM SG330 cluster.

We are in the process of setting up web content filtering and have run into some issues by where certain webpages don't display correctly. - The sites appear to have lots of their graphic content striped from the site, even though the site is on the allow list. I'm not sure if it specific to flash based content or content being pulled from external sources from other sites.

We are on the most up-date available firmware version, which we recently updated to.

The UTM is in transparent mode and most sites appear correctly.

Any help would be much appreciated.

Regards,

Daniel.



This thread was automatically locked due to age.
  • If the content is being pulled from external sources that are blocked it will not be shown, even if the original site is listed as allowed. Same stands for application control items, like blocked Flash in App Control rule.

    For example, if you blocked booking.com URL and Facebook app, all related content on all websites will be stripped.

  • Thanks for the response.

    We pretty much have an "allow" on most of the default categories. It would seem strange that the external sources would be blocked. Do you know if the UTM has somesort of block on externally pulled content from other sites by default?

  • "Pretty much" is still more restricted than "Allow All"...;), so there must be a reason for some content blocking.
    Open Web Filtering live log and put internal IP address in Filter box while browsing problem sites, then look at the block lines and examine URLs and the reasons for blocking.

  • If using transparent proxy, I have found that if you use "WARN" in any of the categories within your policy filter action it can create this issue. This is particularly true if you use WARN for Uncategorized Websites.

    When a category group is set to WARN, when a user first goes to a warned page, they get the option to proceed. That works fine but if the resulting page has content that comes from other "warned" sites, then the web page breaks and of course, there is no option to proceed with content on the page. I think this is more problematic on iFrame pages as well.

    Essentially, this makes the WARN option pretty much useless. Some sites will work and many others will not work.

    Also, this can break applications (non-browser applications) that use http/https to connect to outside servers. The applications will stop working with WARN selected. I would say if you have any categories set to WARN or if you have set Uncategorized to WARN, that is what is causing the problem.

    I am not sure how to get around this or how Astaro can get around this issue. The WARN option was added not all that long ago and I think it is a work in progress.

  • I have the same issues, only intermittently using a clustered UTM 9 Community edition on my own hardware.  Periodically, websites will display in a sort of text only mode with their graphics and structure stripped.  I've attached a screen shot.  At other times these pages display correctly.  Per my appliance logs, there are no pages being blocked, and my web filtering currently filters nothing.   

  • Try disabling caching if you have it on as a test.

    Really, you need to check the http logs to see what traffic is being blocked. I find a lot of people have issues with pages part loading because Ads are set to be blocked.

    Is this with every website? 

  • In my case cache is disabled, and it is only for one or two webpages, and the issue clears itself up.  

    I also have an issue with certain domains stop resolving and I need to flush the resolver cache to correct it.

  • This sounds like a client/browser issue.  If the off chance that it isn't, show us the line(s) from the Web Filtering log when this occurs.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Thanks for the reply.  It's been pretty well behaved since the latest update, but I also noticed transparent mode has been off.  I just turned it back on again.  It's definitely not a client side thing, because it happens on multiple devices, and in multiple browsers on each device.  If I switch gateways to a different edge device the site loads fine (same DNS servers, etc, just changed the internet route).

    I use Splunk to monitor the live log, and if it happens again, I'll happily post a ss showing no drops during one of the occurrences.

  • Sorry for the delay Bob.  Finally got a chance to catch this happening again.  The images below indicate another website failing to format properly, blocks/drops coming from my laptop and what the page formats when I change my gateway.