This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos UTM Web Filtering is blocking Steam download at a specific chunk, due to suspected virus... ?

So this is a slightly interesting problem that I ran into while trying to download a 45Gig game via Steam.

I kept getting to 37.5Gig download, and then suddenly it would drop to a few kb/sec and then stop completely for 1 full minute then restart and repeat the same cycle. Prior to hitting this depot I was getting 3MB/sec downloads, so it wasn't a base networking issue (plus other games I'd download at the same time, would get full speed).

So I dug into steam, opened a ticket with them, they sent me to ubisoft, who after a little bit sent me back to steam. Looking at steam's logs, i kept getting 403's from a specific depot (read chunk) that kept failing to download. So naturally my thought was that the source was corrupted. After exposing this to steam's support, they went and checked, and told me that they had initiated the download and tested that depot to be fully functional and working correctly. 

So naturally at this point, I start to suspect my firewall (Sophos UTM v.9.506-2). I opened my Web filtering log, and sure enough, while the download was occuring a bunch of different steamcontent.com ports (and a few akamai CDN's urls) were being blocked.

So I copied one of the URLs into my browser and got:

"While trying to retrieve the URL:

 
The content is blocked due to the following condition:
The item you have requested is infected by a virus. It will not be downloaded.
 
Report: Nutcracker-Fam "
 
I reported this to steam, but they said they regularly scan all depots and suspect its a false positive from my firewall's AV.
 
Here's the interesting part, and the part I'm confused about:
 
I added both:
"^https?://([A-Za-z0-9.-]*\.)?steampowered\.com/"
and
"^https?://([A-Za-z0-9.-]*\.)?steamcdn-a\.akamaihd\.net/"
 
to an exception list entry and told it to not block for authentification, antivirus, extensions, mime-types, url-filter, contentfilter, ssl-scn, trust check, certificate date check , but it kept blocking it regardless of what I set.
 
 
So now, other than turning off web filtering to get past this problem, I'm stumped on how to solve this problem for future scenarios.
 
How should I have resolved this issue, without turning off web filtering?


This thread was automatically locked due to age.
Parents Reply Children