This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Websites blocked in full transparent mode

Hello,

I currently have a ASG320 and it is set up as full transparent proxy. When the transparent proxy is inline, we are not able to access certain sites (Cisco.com, youtube.com, 123rescute.com, slack.com, for example). Looking through the logs, we receive these messages:

 

2017:01:18-19:50:39 UTM9 httpproxy[26799]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="plain_write_vector" file="epoll.c" line="1117" message="Write error on the epoll handler 84 (Broken pipe)"
2017:01:18-19:50:39 UTM9 httpproxy[26799]: id="0002" severity="info" sys="SecureWeb" sub="http" name="web request blocked" action="block" method="CONNECT" srcip="192.168.50.205" dstip="52.84.18.239" user="" group="" ad_domain="" statuscode="500" cached="0" profile="REF_DefaultHTTPProfile (Default Web Filter Profile)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="517" request="0xdfda3200" url="https://xxxxxx.slack.com/" referer="" error="Connection refused" authtime="0" dnstime="3" cattime="190" avscantime="0" fullreqtime="1020" device="0" auth="0" ua="" exceptions="" category="170" reputation="trusted" categoryname="Personal Network Storage"
2017:01:18-19:50:39 UTM9 httpproxy[26799]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="plain_write_vector" file="epoll.c" line="1117" message="Write error on the epoll handler 83 (Broken pipe)"
2017:01:18-19:50:39 UTM9 httpproxy[26799]: id="0002" severity="info" sys="SecureWeb" sub="http" name="web request blocked" action="block" method="CONNECT" srcip="192.168.50.66" dstip="52.84.18.239" user="" group="" ad_domain="" statuscode="500" cached="0" profile="REF_DefaultHTTPProfile (Default Web Filter Profile)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="517" request="0xa21f600" url="https://xxxxxx.slack.com/" referer="" error="Connection refused" authtime="0" dnstime="3" cattime="117" avscantime="0" fullreqtime="1032" device="0" auth="0" ua="" exceptions="" category="170" reputation="trusted" categoryname="Personal Network Storage"
2017:01:18-19:50:39 UTM9 httpproxy[26799]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="plain_write_vector" file="epoll.c" line="1117" message="Write error on the epoll handler 84 (Broken pipe)"
2017:01:18-19:50:39 UTM9 httpproxy[26799]: id="0002" severity="info" sys="SecureWeb" sub="http" name="web request blocked" action="block" method="CONNECT" srcip="192.168.50.205" dstip="52.84.18.239" user="" group="" ad_domain="" statuscode="500" cached="0" profile="REF_DefaultHTTPProfile (Default Web Filter Profile)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="517" request="0xa21c000" url="https://xxxxxx.slack.com/" referer="" error="Connection refused" authtime="0" dnstime="3" cattime="234" avscantime="0" fullreqtime="1106" device="0" auth="0" ua="" exceptions="" category="170" reputation="trusted" categoryname="Personal Network Storage"
2017:01:18-19:50:39 UTM9 httpproxy[26799]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="plain_write_vector" file="epoll.c" line="1117" message="Write error on the epoll handler 83 (Broken pipe)"
2017:01:18-19:50:39 UTM9 httpproxy[26799]: id="0002" severity="info" sys="SecureWeb" sub="http" name="web request blocked" action="block" method="CONNECT" srcip="192.168.50.205" dstip="52.84.18.239" user="" group="" ad_domain="" statuscode="500" cached="0" profile="REF_DefaultHTTPProfile (Default Web Filter Profile)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="517" request="0xa21d800" url="https://xxxxxx.slack.com/" referer="" error="Connection refused" authtime="0" dnstime="3" cattime="170" avscantime="0" fullreqtime="1241" device="0" auth="0" ua="" exceptions="" category="170" reputation="trusted" categoryname="Personal Network Storage"
2017:01:18-19:50:39 UTM9 httpproxy[26799]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="plain_write_vector" file="epoll.c" line="1117" message="Write error on the epoll handler 83 (Broken pipe)"
2017:01:18-19:50:39 UTM9 httpproxy[26799]: id="0002" severity="info" sys="SecureWeb" sub="http" name="web request blocked" action="block" method="CONNECT" srcip="192.168.50.66" dstip="52.84.18.239" user="" group="" ad_domain="" statuscode="500" cached="0" profile="REF_DefaultHTTPProfile (Default Web Filter Profile)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="517" request="0xa343200" url="https://xxxxxx.slack.com/" referer="" error="Connection refused" authtime="0" dnstime="4" cattime="152" avscantime="0" fullreqtime="1169" device="0" auth="0" ua="" exceptions="" category="170" reputation="trusted" categoryname="Personal Network Storage"
2017:01:18-20:14:33 UTM9 httpproxy[26799]: id="0002" severity="info" sys="SecureWeb" sub="http" name="web request blocked" action="block" method="GET" srcip="192.168.50.125" dstip="23.58.115.155" user="" group="" ad_domain="" statuscode="502" cached="0" profile="REF_DefaultHTTPProfile (Default Web Filter Profile)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="2500" request="0xdedde400" url="http://www.cisco.com/" referer="" error="Connection refused" authtime="0" dnstime="386" cattime="28305" avscantime="0" fullreqtime="31161" device="0" auth="0" ua="Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.87 Safari/537.36" exceptions="" category="105" reputation="trusted" categoryname="Business"
2017:01:18-20:14:33 UTM9 httpproxy[26799]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="plain_write_vector" file="epoll.c" line="1117" message="Write error on the epoll handler 85 (Connection refused)"
2017:01:18-20:14:33 UTM9 httpproxy[26799]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="plain_write_vector" file="epoll.c" line="1117" message="Write error on the epoll handler 85 (Connection refused)"
2017:01:18-20:14:33 UTM9 httpproxy[26799]: id="0003" severity="info" sys="SecureWeb" sub="http" request="0xdfc33000" function="send_request_headers" file="request.c" line="907" message="write() on AF 2 socket to 23.58.115.155 failed: Connection refused"
2017:01:18-20:14:33 UTM9 httpproxy[26799]: id="0002" severity="info" sys="SecureWeb" sub="http" name="web request blocked" action="block" method="GET" srcip="192.168.50.125" dstip="23.58.115.155" user="" group="" ad_domain="" statuscode="502" cached="0" profile="REF_DefaultHTTPProfile (Default Web Filter Profile)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="2511" request="0xdfc33000" url="www.cisco.com/favicon.ico" referer="http://www.cisco.com/" error="Connection refused" authtime="0" dnstime="131" cattime="24687" avscantime="0" fullreqtime="25891" device="0" auth="0" ua="Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.87 Safari/537.36" exceptions="" category="105" reputation="trusted" categoryname="Business"


I've tried adding in those websites in the exceptions list, and still am unable to access. I've worked with a couple of engineers, and still am unable to resolve. I've been looking through the different forums, and I have yet to find a solution regarding blocked websites in transparent mode.

Was just wondering if anybody has a solution to this.

Thank you in advance



This thread was automatically locked due to age.
Parents
  • With a statuscode in the 500s, Mark, if an Exception for Antivirus (plus 'SSL scanning' and 'Certificate trust check' for HTTPS) doesn't solve the problem, you will need to skip the Proxy for the site.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Hey Bob,

     

    Thanks for the reply. I made an exception for AV slack.com (the main messaging application that we use) and I am still unable to reach those sites. I've also added in cisco.com and slack.com to our "skip transparent mode destination hosts/nets" section in Misc. 

    Here are the logs that i pulled last night:

    2017:01:26-20:39:42 Sophos httpproxy[2306]: id="0002" severity="info" sys="SecureWeb" sub="http" name="web request blocked" action="block" method="GET" srcip="192.168.50.223" dstip="23.58.115.155" user="" group="" ad_domain="" statuscode="502" cached="0" profile="REF_DefaultHTTPProfile (Default Web Filter Profile)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="2500" request="0xe182a400" url="http://www.cisco.com/" referer="" error="Connection refused" authtime="0" dnstime="127" cattime="0" avscantime="0" fullreqtime="1220" device="0" auth="0" ua="Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.87 Safari/537.36" exceptions="" overridecategory="1" overridereputation="1"
    2017:01:26-20:39:42 Sophos httpproxy[2306]: id="0002" severity="info" sys="SecureWeb" sub="http" name="web request blocked" action="block" method="GET" srcip="192.168.50.223" dstip="23.58.115.155" user="" group="" ad_domain="" statuscode="502" cached="0" profile="REF_DefaultHTTPProfile (Default Web Filter Profile)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="2511" request="0xe0a5c600" url="www.cisco.com/favicon.ico" referer="http://www.cisco.com/" error="Connection refused" authtime="0" dnstime="123" cattime="0" avscantime="0" fullreqtime="1143" device="0" auth="0" ua="Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.87 Safari/537.36" exceptions="" overridecategory="1" overridereputation="1"
    2017:01:26-20:39:42 Sophos httpproxy[2306]: id="0002" severity="info" sys="SecureWeb" sub="http" name="web request blocked" action="block" method="GET" srcip="192.168.50.223" dstip="23.58.115.155" user="" group="" ad_domain="" statuscode="502" cached="0" profile="REF_DefaultHTTPProfile (Default Web Filter Profile)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="2500" request="0xdfed9600" url="http://www.cisco.com/" referer="" error="Connection refused" authtime="0" dnstime="120" cattime="0" avscantime="0" fullreqtime="1147" device="0" auth="0" ua="Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.87 Safari/537.36" exceptions="" overridecategory="1" overridereputation="1"
    2017:01:26-20:39:42 Sophos httpproxy[2306]: id="0002" severity="info" sys="SecureWeb" sub="http" name="web request blocked" action="block" method="GET" srcip="192.168.50.223" dstip="23.58.115.155" user="" group="" ad_domain="" statuscode="502" cached="0" profile="REF_DefaultHTTPProfile (Default Web Filter Profile)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="2511" request="0x8c0ec00" url="www.cisco.com/favicon.ico" referer="http://www.cisco.com/" error="Connection refused" authtime="0" dnstime="135" cattime="0" avscantime="0" fullreqtime="1201" device="0" auth="0" ua="Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.87 Safari/537.36" exceptions="" overridecategory="1" overridereputation="1"
    2017:01:26-20:39:42 Sophos httpproxy[2306]: id="0002" severity="info" sys="SecureWeb" sub="http" name="web request blocked" action="block" method="GET" srcip="192.168.50.223" dstip="23.58.115.155" user="" group="" ad_domain="" statuscode="502" cached="0" profile="REF_DefaultHTTPProfile (Default Web Filter Profile)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="2500" request="0x8c0f200" url="http://www.cisco.com/" referer="" error="Connection refused" authtime="0" dnstime="122" cattime="0" avscantime="0" fullreqtime="1131" device="0" auth="0" ua="Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.87 Safari/537.36" exceptions="" overridecategory="1" overridereputation="1"
    2017:01:26-20:39:42 Sophos httpproxy[2306]: id="0002" severity="info" sys="SecureWeb" sub="http" name="web request blocked" action="block" method="GET" srcip="192.168.50.223" dstip="23.58.115.155" user="" group="" ad_domain="" statuscode="502" cached="0" profile="REF_DefaultHTTPProfile (Default Web Filter Profile)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="2511" request="0xc93ca00" url="www.cisco.com/favicon.ico" referer="http://www.cisco.com/" error="Connection refused" authtime="0" dnstime="115" cattime="0" avscantime="0" fullreqtime="1215" device="0" auth="0" ua="Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.87 Safari/537.36" exceptions="" overridecategory="1" overridereputation="1"
    2017:01:26-20:39:55 Sophos httpproxy[2306]: id="0002" severity="info" sys="SecureWeb" sub="http" name="web request blocked" action="block" method="CONNECT" srcip="192.168.50.223" dstip="35.160.210.76" user="" group="" ad_domain="" statuscode="500" cached="0" profile="REF_DefaultHTTPProfile (Default Web Filter Profile)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="178" request="0x8c0f200" url="https://4.sophosxl.net/" referer="" error="Connection refused" authtime="0" dnstime="4" cattime="0" avscantime="0" fullreqtime="692" device="0" auth="0" ua="" exceptions="av,sandbox,auth,content,url,ssl,certcheck,certdate,mime,cache,fileextension,size,patience"
    2017:01:26-20:40:18 Sophos httpproxy[2306]: id="0002" severity="info" sys="SecureWeb" sub="http" name="web request blocked" action="block" method="CONNECT" srcip="192.168.50.223" dstip="151.101.128.102" user="" group="" ad_domain="" statuscode="500" cached="0" profile="REF_DefaultHTTPProfile (Default Web Filter Profile)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="517" request="0xdfff6600" url="https://ca.slack-edge.com/" referer="" error="Connection refused" authtime="0" dnstime="1330" cattime="0" avscantime="0" fullreqtime="2512" device="0" auth="0" ua="" exceptions="av,auth,content,url,ssl,certcheck,mime,cache,fileextension,size,patience"
    2017:01:26-20:40:18 Sophos httpproxy[2306]: id="0002" severity="info" sys="SecureWeb" sub="http" name="web request blocked" action="block" method="CONNECT" srcip="192.168.50.223" dstip="151.101.128.102" user="" group="" ad_domain="" statuscode="500" cached="0" profile="REF_DefaultHTTPProfile (Default Web Filter Profile)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="517" request="0xe2182a00" url="https://ca.slack-edge.com/" referer="" error="Connection refused" authtime="0" dnstime="1478" cattime="0" avscantime="0" fullreqtime="3000" device="0" auth="0" ua="" exceptions="av,auth,content,url,ssl,certcheck,mime,cache,fileextension,size,patience"
    2017:01:26-20:40:18 Sophos httpproxy[2306]: id="0002" severity="info" sys="SecureWeb" sub="http" name="web request blocked" action="block" method="CONNECT" srcip="192.168.50.223" dstip="151.101.128.102" user="" group="" ad_domain="" statuscode="500" cached="0" profile="REF_DefaultHTTPProfile (Default Web Filter Profile)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="517" request="0xe1460000" url="https://ca.slack-edge.com/" referer="" error="Connection refused" authtime="0" dnstime="4" cattime="0" avscantime="0" fullreqtime="815" device="0" auth="0" ua="" exceptions="av,auth,content,url,ssl,certcheck,mime,cache,fileextension,size,patience"
    2017:01:26-20:40:18 Sophos httpproxy[2306]: id="0002" severity="info" sys="SecureWeb" sub="http" name="web request blocked" action="block" method="CONNECT" srcip="192.168.50.223" dstip="151.101.128.102" user="" group="" ad_domain="" statuscode="500" cached="0" profile="REF_DefaultHTTPProfile (Default Web Filter Profile)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="0" request="0xe0fe7000" url="https://ca.slack-edge.com/" referer="" error="Connection refused" authtime="0" dnstime="2" cattime="0" avscantime="0" fullreqtime="1024" device="0" auth="0" ua="" exceptions="av,auth,content,url,ssl,certcheck,mime,cache,fileextension,size,patience"
    2017:01:26-20:40:18 Sophos httpproxy[2306]: id="0002" severity="info" sys="SecureWeb" sub="http" name="web request blocked" action="block" method="CONNECT" srcip="192.168.50.223" dstip="151.101.128.102" user="" group="" ad_domain="" statuscode="500" cached="0" profile="REF_DefaultHTTPProfile (Default Web Filter Profile)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="517" request="0xe1426400" url="https://ca.slack-edge.com/" referer="" error="Connection refused" authtime="0" dnstime="3" cattime="0" avscantime="0" fullreqtime="595" device="0" auth="0" ua="" exceptions="av,auth,content,url,ssl,certcheck,mime,cache,fileextension,size,patience"
    2017:01:26-20:40:18 Sophos httpproxy[2306]: id="0002" severity="info" sys="SecureWeb" sub="http" name="web request blocked" action="block" method="CONNECT" srcip="192.168.50.223" dstip="151.101.128.102" user="" group="" ad_domain="" statuscode="500" cached="0" profile="REF_DefaultHTTPProfile (Default Web Filter Profile)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="217" request="0xdfde9200" url="https://ca.slack-edge.com/" referer="" error="Connection refused" authtime="0" dnstime="4" cattime="0" avscantime="0" fullreqtime="561" device="0" auth="0" ua="" exceptions="av,auth,content,url,ssl,certcheck,mime,cache,fileextension,size,patience"
    2017:01:26-20:40:18 Sophos httpproxy[2306]: id="0002" severity="info" sys="SecureWeb" sub="http" name="web request blocked" action="block" method="CONNECT" srcip="192.168.50.223" dstip="151.101.128.102" user="" group="" ad_domain="" statuscode="500" cached="0" profile="REF_DefaultHTTPProfile (Default Web Filter Profile)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="217" request="0x8c4a600" url="https://ca.slack-edge.com/" referer="" error="Connection refused" authtime="0" dnstime="3" cattime="0" avscantime="0" fullreqtime="602" device="0" auth="0" ua="" exceptions="av,auth,content,url,ssl,certcheck,mime,cache,fileextension,size,patience"
    2017:01:26-20:40:18 Sophos httpproxy[2306]: id="0002" severity="info" sys="SecureWeb" sub="http" name="web request blocked" action="block" method="CONNECT" srcip="192.168.50.223" dstip="151.101.128.102" user="" group="" ad_domain="" statuscode="500" cached="0" profile="REF_DefaultHTTPProfile (Default Web Filter Profile)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="217" request="0xdfed6000" url="https://ca.slack-edge.com/" referer="" error="Connection refused" authtime="0" dnstime="3" cattime="0" avscantime="0" fullreqtime="563" device="0" auth="0" ua="" exceptions="av,auth,content,url,ssl,certcheck,mime,cache,fileextension,size,patience"
    2017:01:26-20:40:18 Sophos httpproxy[2306]: id="0002" severity="info" sys="SecureWeb" sub="http" name="web request blocked" action="block" method="CONNECT" srcip="192.168.50.223" dstip="151.101.128.102" user="" group="" ad_domain="" statuscode="500" cached="0" profile="REF_DefaultHTTPProfile (Default Web Filter Profile)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="217" request="0xe1679800" url="https://ca.slack-edge.com/" referer="" error="Connection refused" authtime="0" dnstime="3" cattime="0" avscantime="0" fullreqtime="542" device="0" auth="0" ua="" exceptions="av,auth,content,url,ssl,certcheck,mime,cache,fileextension,size,patience"
    2017:01:26-20:40:18 Sophos httpproxy[2306]: id="0002" severity="info" sys="SecureWeb" sub="http" name="web request blocked" action="block" method="CONNECT" srcip="192.168.50.223" dstip="151.101.128.102" user="" group="" ad_domain="" statuscode="500" cached="0" profile="REF_DefaultHTTPProfile (Default Web Filter Profile)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="217" request="0xe1b2fe00" url="https://ca.slack-edge.com/" referer="" error="Connection refused" authtime="0" dnstime="3" cattime="0" avscantime="0" fullreqtime="583" device="0" auth="0" ua="" exceptions="av,auth,content,url,ssl,certcheck,mime,cache,fileextension,size,patience"

     

    Misc:

  • Since these still appear in the Web Filtering log, the skip isn't working.  Insert a picture of an Edit of "slack" with 'Advanced' open.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • screenshot of Exceptions:

     

    Misc:

    it also resolves to '5 IPs total'

  • In the DNS Group for slack, change the Hostname field to ca.slack-edge.com.  In the one for Cisco, change it to www.cisco.com. Any better luck now?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • In the DNS Group for slack, change the Hostname field to ca.slack-edge.com.  In the one for Cisco, change it to www.cisco.com. Any better luck now?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children