Using the new DPI SSL/TSL, Linkedin does not open with Firefox on Mac

Linkedin does not open at all.

Parents Reply Children
  • PM sent!

    Luk

    Security Architect

    UTM Certified Architect - XG Certified Architect

  • FYI:

    just moved to EAP 3 and still Linkedin, ebay and amazon.it do not open on MAC OS Catalina and Firefox latest releases, if DPI is on. See the screenshot.

    This should be investigated by Sophos before GA release. Same computer, same websites with Safari, they open as expected. Browsing through FF is very slow compared to web proxy or compared to Safari with DPI enabled.

    Regards

    Luk

    Security Architect

    UTM Certified Architect - XG Certified Architect

  • It seems I am alone with this issue. Even on eap 3, I have disabled DPI.

    This is sad for me as I would like to use and test the new dpi engine.

    Luk

    Security Architect

    UTM Certified Architect - XG Certified Architect

  • Well your not alone, same thing happens with me with DPI. But Isn't common to happen.

     

    EDIT: It's not only in Firefox, same thing is happening on Chrome.

    To "fix" this, I've created exceptions on the websites that has been giving this error.

  • Can someone look at this issue?

    Thanks

    Luk

    Security Architect

    UTM Certified Architect - XG Certified Architect

  • Hi folks,

    you might not be alone!

    I get that error on some sites, but when I reload the page the connection goes through. This issue only started about 2 hours after EAP 3 was installed.

    Next little thing, I tried setting creating my own SSL/TLS rule but no traffic went through it. So I disabled the two default rules and still no traffic. You cannot place your rule higher than the default rules which is sort of defeating being able to create your own rules.

    The only SSL/TLS rule passing traffic is default rule 1. Nothing in the logs about the other failures.

    Ian

     
    V18.0.x - e3-1225v5 6gb ram on 4 port MB with 2 x APX120 - 20w. 
    If a post solves your question use the 'This helped me' link.
  •  

    can you ask to some developers to look at this thread?

    With my XG and FF, I am not able to open at all:

    ebay.it

    amazon.it

    I am not able to test DPI at all and this is frustrating me. Same MAC with Safari, the same sites work as expected.

    Regards

    Luk

    Security Architect

    UTM Certified Architect - XG Certified Architect

  • Luk

    Security Architect

    UTM Certified Architect - XG Certified Architect

  • Most of the people, including myself are on holiday right now. 

    So i do have any way to contact anybody. 

     

    But lets wrap this up, I do not have any Mac right now to reproduce this. 

    Did you regenerate all your certificates and reimport them into Firefox? 

    It looks like your Firefox do not like the decryption at all. 

    Based on your tcpdump, the client is killing the connection quickly. 

     

     

    Could you please show us your DPI Profiles?

    Which certificate do you use to decrypted? 

    __________________________________________________________________________________________________________________

  • Sophos CA is imported. Take note I am using Decrypt and Scan since 2016 and no problem at all. I tried to reimport the CA in Firefox nothing changes. Safari works as expected on the same Mac.

    DPI profile is the default one. Same profile, same computer, different browsers different behaviours.

    If anyone is on holiday and no one is reachable after January, Merry Christmas to all Sophos Staff and Community members.

    [

    Luk

    Security Architect

    UTM Certified Architect - XG Certified Architect