Hi guys,
I was advised to post my problem here since my origianl post was in Sophos UTM update 9.411-3 released.
I just updated 2 days ago our SG310 to 9.411-3 from 9.409-9. The box was was configured not to allow download more than 100MB of file to users not listed in the exception in which I included in the exception. It has been configured for more that a year but the recent upgrade to 9.411-3 broke that rule.
I can no longer download (direct download from browser) files more that 100MB with the following info:
2017:03:24-18:14:35 ta-utm-lnx_01p httpproxy[5853]: id="0070" severity="info" sys="SecureWeb" sub="http"
name="web request blocked, download exceeds maximum allowable size" action="block" method="GET"
srcip="10.10.10.119" dstip="149.202.99.44" user="" group="" ad_domain="" statuscode="403" cached="0"
profile="REF_HttProContaInterNetwo2 (For Internal Network)" filteraction="REF_HttCffBlocksites (BlockSites)"
size="3063" request="0xbde15000" url="http://ddl8.digiboy.ir/vmware/6.0/update-from-esxi6.0-6.0_update03.zip"
referer="www.digiboy.ir/.../" error="" authtime="0" dnstime="95"
cattime="152" avscantime="0" fullreqtime="725130" device="0" auth="0"
ua="Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko)
Chrome/56.0.2924.87 Safari/537.36" exceptions="application" category="175" reputation="neutral"
categoryname="Software/Hardware" reason="size"
My ip (10.10.10.119) was included in the exception list with skip block download size. But to my surprise, I was able to download latest release of pfSense with the following log:
2017:03:24-18:28:28 ta-utm-lnx_01p httpproxy[5853]: id="0001" severity="info" sys="SecureWeb" sub="http"
name="http access" action="pass" method="CONNECT" srcip="10.10.10.119" dstip="139.59.224.27" user="" group=""
ad_domain="" statuscode="200" cached="0" profile="REF_HttProContaInterNetwo2 (For Internal Network)"
filteraction="REF_HttCffBlocksites (BlockSites)" size="322982130" request="0xe4806600"
url="https://sgpfiles.pfsense.org/" referer="" error="" authtime="0" dnstime="2" cattime="106"
avscantime="0" fullreqtime="819146008" device="0" auth="0" ua="" exceptions="application"
category="175" reputation="neutral" categoryname="Software/Hardware"
Can someone explain the reason behind this issue?
Jeanar
This thread was automatically locked due to age.