This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos Mobile Control + web protection. Problem with db.notify.windows.com

Hello,

I have a problem with connection from Sophos Mobile Control server to db3.notify.windows.com:443 through web protection module even I added exception for that domain. Has anyone had similar problem ?

On the proxy server I get:
 
2016:12:02-14:26:14 st3_router-1 httpproxy[6538]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="parse_request_line" file="request.c" line="1048" message="400: Bad request (invalid uri): db3.notify.windows.com"
2016:12:02-14:26:14 st3_router-1 httpproxy[6538]: id="0003" severity="info" sys="SecureWeb" sub="http" request="0xcd647600" function="read_request_headers" file="request.c" line="1612" message="invalid request line"

 

Logs from SMC system property check in attachment. 

 

2016-12-02 14:16:55 : Checking if proxy 192.168.70.1:8080 allows connect to: db3.notify.windows.com
2016-12-02 14:16:55 : Proxy host: 192.168.70.1
2016-12-02 14:16:55 : Proxy port: 8080
2016-12-02 14:16:55 : Check resolving of 192.168.70.1
2016-12-02 14:16:55 : DNS resolving successful: 192.168.70.1
2016-12-02 14:16:55 : Answer from proxy: HTTP/1.1 400 Received invalid request line from client
Date: Fri, 02 Dec 2016 13:17:00 GMT
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset="UTF-8"
Content-Length: 2445
Accept-Ranges: none
Proxy-Connection: close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />
    <title>The requested URL could not be retrieved</title>
    <link href="http://passthrough.fw-notify.net/static/default.css" rel="stylesheet" type="text/css" />
    <script type="text/javascript" src="http://passthrough.fw-notify.net/static/default.js"></script>
  </head>
  <body onload="checkResize();">
    <div id="emsg_large"></div>
    <div id="page">
      <div id="header">
        <div><img src="http://passthrough.fw-notify.net/static/topbar_left.png" width="6" height="72" border="0" /></div>
        <div id="company_logo"><img src="http://passthrough.fw-notify.net/static/logo.png" border="0" /></div>
        <div id="company_text"><h1 class="orange"></h1></div>
        <div><img src="http://passthrough.fw-notify.net/static/topbar_right.png" width="6" height="72" border="0" /></div>
      </div>
      <br class="clearer" />

      <div id="content">
        <img src="http://passthrough.fw-notify.net/static/warning.png" border="0" align="left" />
        <h1 class="orange">An error occurred while handling your request</h1>

        <div class="line">
          <div class="label">While trying to retrieve the URL:</div>
          <div class="desc"> 
            <span></span>
          </div>
        </div>

        <div class="line">
          <div class="label">The content could not be delivered due to the following condition:</div>
          <div class="desc"> 
            Received invalid request line from client
          </div>
        </div>

        <div class="line">
          <div class="label">Contact:</div>
          <div class="desc"> 
            it@st3-offshor
2016-12-02 14:16:55 : Proxy answered with http code != 200
2016-12-02 14:16:55 : db3.notify.windows.com blocked through proxy.
2016-12-02 14:16:55 : Checking connect to: db3.notify.windows.com:443
2016-12-02 14:16:55 : DNS resolving successful. Checking connect to: 191.232.139.143:443
2016-12-02 14:17:05 : Error: @error 10060
2016-12-02 14:17:05 : db3.notify.windows.com blocked.



This thread was automatically locked due to age.
Parents
  • Hi, Krzysztof, and welcome to the UTM Community!

    Try skipping the Proxy for db3.notify.windows.com.  In Transparent mode, put a DNS Host for that FQDN in the Destination box on the 'Misc' tab of 'Filtering Options'.  Any luck with that?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Hi Bob,

    No luck. The same problem

    2016-12-05 08:18:01 : DNS resolving successful. Checking connect to: 191.232.139.143:443
    2016-12-05 08:18:11 : Error: @error 10060
    2016-12-05 08:18:11 : db3.notify.windows.com blocked.

    It works only with enabled masquerade without proxy server

  • I don't recognize that log file, Krzysztof.  If it is an edited Web Filtering log, then the Proxy wasn't skipped.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • saludos estimados tambien estoy presentando el mismo problema, que solucion puede tener

Reply Children
No Data