This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Decrypt & Scan HTTPS Troubleshooting ?

Hi to everibody

 

I'm in the process of change my utm320 cluster with a new xg330 (SFOS 17.0.6 MR-6) cluster and i have a fully functional cluster.

Webfilter using port 3128, integrated in A/D, with some rules (3) one for every A/D group i want to have different web browsing right.

All is runnning well.

 

This morning i try to change the default port 3128 to 8080 and accordingly i change too the Mozilla Proxy settings.

Nothing to do, no web browsing is possible.

maybe a restart ? i restart the XG cluster from the console.

nothing change.

I reset the Proxy Port on 3128 and restart the XG but the result is the same, nothing is changed.

 

all web sites are blocked.

so i open my rule and disable all checking (scan http, scan https, malware for ftp and sandstorm), this time web browsing are running (except the fact that now I'm verifing nothing)

i enable one control at a time and find that i can't enable "scan http" and/or "decrypt and scan https", if i do the web are blocked (sometime page is blank, some other time is partially loaded like in the google example).

 

the certificate for https decryption is correctly installed in the browser (see the google image)

searching in the log i finally found that from webfilter pov it's OK (image attached) but the malware log is full of events)...

 

Any idea ?

 

 

 

 

 

Last Minute : seeing that all errors seems to indicate a Scan/Malware malfunction I go to Web -> General Settings and change from "Single Engine" to "Dual Engine" and now the web is again reachable with all control turned on..

 

umhhhh a Sophos Engine trouble ?

 

 



This thread was automatically locked due to age.
Parents Reply Children
  • Thank you for the log lines, putting the information here for other to refer.

    A potential find from the logs is that the SAVI update for Sophos AV Engine failed during the time when the website was blocked as the malware. 

    2018-04-23 11:35:46 AM: Got the lock for updating savi (savi_12506-12507.tar.gz)
    2018-04-23 11:35:46 AM: applying incremental update update
    2018-04-23 11:35:46 AM: updating /sdisk/savi/engine signatures
    2018-04-23 11:35:46 AM: updating /sdisk/savi/vdl signatures
    2018-04-23 11:35:48 AM: New savi full update Failed

    The update was successful at 

    2018-04-23 06:30:56 PM: Got the lock for updating savi (savi_12508.tar.gz)
    2018-04-23 06:30:59 PM:Installing Full sophos update
    2018-04-23 06:31:07 PM: New savi full update successfully done

    I believe it was an issue related to the update failure for Sophos AV patterns. 

    Hope that helps someone. 

  • Thanks Sachingurung for your Help :-)