This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Some Websites are not loading or getting error when passing the traffic through one ISP

I'm new to Sophos XG Firewalls.

I'm facing a very peculiar issue with my Sophos XG firewalls. The firewalls are in HA (Active-Passive). My client has three ISPs. One ISP is terminated directly on Sophos and other two ISPs are PPPoE connection. Since the Sophos X doesn't support PPPoE connection in HA, for ISPs which are PPPoE (say ISP 2 and ISP 3 ) are terminated on a router and from there it is connected to Sophos XG.

The problem i'm facing is when the user internet traffic is passed through ISP 2 and ISP 3 some websites are not loading at all or sometimes loading not properly. This problem is not constant and it is occurring randomly.

 

I don't know what is causing this issue and the customer is really pissed about this.

 

If I pass the traffic through ISP 1 which is terminated directly on Sophos I'm not facing any issues at all.

 

To check if it is the issue from ISP side, I disconnected and connected the cable directly to my laptop and i checked and everything seems working fine. So the issue is related to XG and i have no idea where to look at.

I created a plain firewall From LAN to WAN without http or https scanning, without IPS,Webfilter and application filter and still the same issue through ISP 2 and ISP 3.

I even changed the firewall dns to public DNS and still the issue persists.

I checked in chrome, IE and mozilla and all same outcome.

 

Any help would really welcome and great.

 

Thank You.

Janish



This thread was automatically locked due to age.
Parents Reply Children
  • Hi,

     

    Thank you so much.

     

    I would test it by disabling the NAT on modem and I will update you.

     

    Is there any command we can see whether the problem is happening between XG and modem like drop-packet-capture or tcpdump?

     

    Thank You.

  • Hi,

     

    I disabled the NAT and the internet wasn't working after that.

    So i added it again.

     

    Can this issue be related to mtu and mss value? If so is there any recommendation how much we should reduce it (the value)?

     

    Also does anyone know if the new version V17 MR5 support PPPoE in HA(Active-Passive)?

     

    Thank You.