This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Windows 7 x64 freezing - Sophos Firewall

Hello all.

All machines in discussion are domain joined, Windows 7 x64

We have had over time some random Windows 7 machines behave as if they are locked up completely. No network access at all although still respond to ping. Will also allow a remote session via powerShell. Windows explorer locks up, applications freeze as they are opened or work is saved to the network.

These machines are dead in the water until the Sophos Firewall Services is stopped. Then the machine will react almost instantly. Start the service again and the machine locks.

The fix until now was to re-protect the endpoints. Maybe 7 in total over a period of weeks.

Today we had approximately nine endpoints freeze with the only solution to stop the firewall service to allow the end user to gracefully shut down the machine. The first time this happened was mid-morning for a particular group. The second was at 5.00.pm with the bulk of our staff having left for the day.

Notably one machine I found that Sophos was indicating an update was in progress. It was the last machine I was looking at so may be a bad lead.

Also, on machine I connected to via a PowerShell Remote Session. The firewall service was turned off to allow the user to get work saved. The machine was left with the user logged in, Firewall Service NOT running for maybe an hour and a half. When I went to this machine and resumed the Firewall service everything was fine? Also logged in as another user and still fine?

I look after Active Directory and our Sophos management so can say with some certainty that nothing was pushed, altered or changed at the time. (Maybe Windows updates - will check tomorrow.)

I could see no firewall updates in the update log.

Hopefully I won't be walking into a shambles tomorrow morning when the bulk of staff return.

Any ideas?

Oh and sorry for the long post.

:45105


This thread was automatically locked due to age.
Parents
  • Hopefully someone will find this useful.

    We still see the above randomly on single machines which boils down to corrupt op_data.mdb file.  We have in place a fix for this which comprises of remotely stopping the firewall service, deleting the op_data.mdb file then restarting the service.  All done remotely using a powershell script.

    Generally these machines show up in the SEC with "Failed to connect to database" and or "Failed to repair database" errors.

    We have since seen multiple machines at one time give symptoms of locking up which also boils down to the firewall blockng traffic but this is not caused by a corrupt log file.  We have a "historic" setting of "Block IPv6 packets" turned on.  It would seem the networking chaps are testing or beginning to implement IPv6 in our environment.  Hence we would see multiple machines suddenly have issues but not all machines.  Probably to do with a single router or switch they are connected to.

    So we two different root causes creating the exact same symptoms on the client machine.

    We now do not block IPv6 packets.  So fare there are no further issues with multiple machines freezing at one time.

    :46307
Reply
  • Hopefully someone will find this useful.

    We still see the above randomly on single machines which boils down to corrupt op_data.mdb file.  We have in place a fix for this which comprises of remotely stopping the firewall service, deleting the op_data.mdb file then restarting the service.  All done remotely using a powershell script.

    Generally these machines show up in the SEC with "Failed to connect to database" and or "Failed to repair database" errors.

    We have since seen multiple machines at one time give symptoms of locking up which also boils down to the firewall blockng traffic but this is not caused by a corrupt log file.  We have a "historic" setting of "Block IPv6 packets" turned on.  It would seem the networking chaps are testing or beginning to implement IPv6 in our environment.  Hence we would see multiple machines suddenly have issues but not all machines.  Probably to do with a single router or switch they are connected to.

    So we two different root causes creating the exact same symptoms on the client machine.

    We now do not block IPv6 packets.  So fare there are no further issues with multiple machines freezing at one time.

    :46307
Children
No Data