This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Trouble with Web Filtering.. maybe

Hi PPL. This is my first post so excuse me if I post in the wrong area etc. I am also VERY new to SOPHOS. I work for a small company and probably overbought, but wanted to get the best bang for the buck.

I am having trouble downloading a Bill of Lading from our freight company. I can access the main site and see our overview of BOLs. When I click to see an individual BOL it comes back with cannot connect. This action is redirected to another URL:8081. I have entered various exceptions and rules for the URL and added the 8081 port to the web surfing Firewall group. I do not see any blocking on the Firewall log or in the Web protection log. If I connect to my wireless ( which I setup via the setup wizard ) No added rules for the wireless connection other than what the wizard created, I can pull of the BOL with no trouble. Any ideas? I don't know how to be more specific but I can supply whatever is needed to try and get a solution.

TIA

Cooper



This thread was automatically locked due to age.
Parents
  • Without knowing what your running your proxy as, transparent/standard etc etc and even if your wireless is surfing through the proxy? I'd check to see if the port is allowed via the target services

     

    Web protection - Filtering Options - Misc

    Add 8081 and see if that works. But there should be a log entry. I'd also try running that through the policy helpdesk and see if it tells you  "Target service not allowed"

  • Thanks for the reply. I have tested it and the domain is allowed and the actual URL link to the file is allowed. I have no proxy configured, (or don't know where to look) just took the setup wizard with no content filtering enabled.

    I don't know where else to look to try and find what could be blocking the file. 

    TIA

  • Do you have different DNS assigned when connecting to your wifi (that works) compared to when it doesn't work plugged into your LAN? When it isn't working, can you nslookup that address and it resolves? That site seems to work fine for me (prodintgrtn.cloudapp.net:8081/), it looks like a IIS test page.

     

    Judging by your screenshot you are surfing through the base policy on your proxy, so....something is setup I'm guessing. We protection, Web filtering and Web Filtering Profiles. I'd also check the web filtering log

  • First I apologize for asking such newbie setup questions. I am very new to Sophos Verbiage and setup coming from a Netgear Firewall which was a very basic setup compared to this. I ran through the setup wizard and entered all the information I was asked. I am trying to find my DNS settings. I am not having DNS issues first off. Websites are resolving. However I have no DNS forwarders in my setup. I have a check by use forwarders provided by ISP but it states none are assigned. I am assuming I should add my ISP DNS's to the forwarders list.

    I can get to the page listed above, the last screen shot is the direct file link which fails, the same link listed in the 2nd picture which states it is allowed.

    Here is a pic of my DNS forwarders and I do appreciate whatever help I get.

  • I'm not overly concerned about the UTM DNS. Can your PC resolve, what is it's DNS setting? The UTM IP is the PC's DNS? I don't think it's a DNS issue either as you can surf the web. Check your web filtering log, intrusion prevention

  • 192.168.2.1
    8.8.8.8

    Web Filter log:

    2017:01:12-12:40:52 bonesafety httpproxy[5785]: id="0001" severity="info" sys="SecureWeb" sub="http" name="http access" action="pass" method="GET" srcip="192.168.2.95" dstip="23.96.6.76" user="" group="" ad_domain="" statuscode="302" cached="0" profile="REF_DefaultHTTPProfile (Default Web Filter Profile)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="213" request="0xe09d0400"...
     
    IPS Filter log:
    2017:01:12-10:25:47 bonesafety snort[11473]: Unrecognized records: 151
    2017:01:12-10:25:47 bonesafety snort[11473]: Completed handshakes: 0
    2017:01:12-10:25:47 bonesafety snort[11473]: Bad handshakes: 0
    2017:01:12-10:25:47 bonesafety snort[11473]: Sessions ignored: 4
    2017:01:12-10:25:47 bonesafety snort[11473]: Detection disabled: 0
    2017:01:12-10:25:47 bonesafety snort[11473]: ===============================================================================
    2017:01:12-10:25:47 bonesafety snort[11473]: SIP Preprocessor Statistics
    2017:01:12-10:25:47 bonesafety snort[11473]: Total sessions: 0
    2017:01:12-10:25:47 bonesafety snort[11473]: ===============================================================================
    2017:01:12-10:25:47 bonesafety snort[11473]: Snort exiting
Reply
  • 192.168.2.1
    8.8.8.8

    Web Filter log:

    2017:01:12-12:40:52 bonesafety httpproxy[5785]: id="0001" severity="info" sys="SecureWeb" sub="http" name="http access" action="pass" method="GET" srcip="192.168.2.95" dstip="23.96.6.76" user="" group="" ad_domain="" statuscode="302" cached="0" profile="REF_DefaultHTTPProfile (Default Web Filter Profile)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="213" request="0xe09d0400"...
     
    IPS Filter log:
    2017:01:12-10:25:47 bonesafety snort[11473]: Unrecognized records: 151
    2017:01:12-10:25:47 bonesafety snort[11473]: Completed handshakes: 0
    2017:01:12-10:25:47 bonesafety snort[11473]: Bad handshakes: 0
    2017:01:12-10:25:47 bonesafety snort[11473]: Sessions ignored: 4
    2017:01:12-10:25:47 bonesafety snort[11473]: Detection disabled: 0
    2017:01:12-10:25:47 bonesafety snort[11473]: ===============================================================================
    2017:01:12-10:25:47 bonesafety snort[11473]: SIP Preprocessor Statistics
    2017:01:12-10:25:47 bonesafety snort[11473]: Total sessions: 0
    2017:01:12-10:25:47 bonesafety snort[11473]: ===============================================================================
    2017:01:12-10:25:47 bonesafety snort[11473]: Snort exiting
Children
No Data