This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Skype sending and receiving inconsistent

Hello guys.

 

I'm having trouble with skype windows 10 . Even creating a rule with any destination, services any, Intrusion Prevention is NONE, Web Policy is NONE, Application Control is NONE. And even then Skype does not connect correctly. Sometimes it receives but it does not send. Sometimes it does not receive and it does not send. Sometimes it works normal. For several moments he is connecting and not charging.

 

In the logs it does not show any blocking and in the packet capture there is no violation. I suspect you have some internal inspection yet that is breaking the connection. Sophos Support is not identifying. I am using version 17.1.3.

I ended up stopping the IPS service because even the rule configured with NONE was logging in "Reset outside window".

 

-microapp disable.

console> system application_classification microapp-discovery show

Off

console> show advanced-firewall
Strict Policy : on
FtpBounce Prevention : control
Tcp Conn. Establishment Idle Timeout : 10800
UDP Timeout Stream : 60
Fragmented Traffic Policy : allow
Midstream Connection Pickup : off
TCP Seq Checking : on
TCP Window Scaling : on
TCP Appropriate Byte Count : on
TCP Selective Acknowledgements : on
TCP Forward RTO-Recovery[F-RTO] : off
TCP TIMESTAMPS : off
Strict ICMP Tracking : off
ICMP Error Message : allow
IPv6 Unknown Extension Header : deny


Bypass Stateful Firewall
------------------------
Source Genmask Destination Genmask


NAT policy for system originated traffic
---------------------
Destination Network Destination Netmask Interface SNAT IP

 

console> show ips
ips-settings ips_conf
console> show ips-settings
-------------IPS Settings-------------
stream on
lowmem off
maxsesbytes 0
maxpkts 8
enable_appsignatures on
http_response_scan_limit 65535
search_method hyperscan
sip_preproc enabled
sip_ignore_call_channel enabled

-------------IPS Instances------------
IPS CPU
1 0
2 1

Anyone with similar issues in this release?

 

 

 


This thread was automatically locked due to age.
Parents Reply Children
  • Hi Cpsilva,

     Could you check if there is any packet loss in the ISP line ?

    You may run this command to check the consistancy of your connection. 

    Option 4 Console> sys dia uti ping count 1000 size 1000 8.8.8.8

    Also let us know when this issue is experenced , you may check your bandwidth utilization there. It could be a simple case of Bandwidth mismanagement or packets drops in your network to external servers.

  • Hi,

    Follow the return. Our link has been left over.

    console> sys dia uti ping count 1000 size 1000 8.8.8.8
    PING 8.8.8.8 (8.8.8.8): 1000 data bytes
    1008 bytes from 8.8.8.8: seq=0 ttl=116 time=25.316 ms
    1008 bytes from 8.8.8.8: seq=1 ttl=116 time=25.249 ms
    1008 bytes from 8.8.8.8: seq=2 ttl=116 time=25.132 ms
    1008 bytes from 8.8.8.8: seq=3 ttl=116 time=25.136 ms
    1008 bytes from 8.8.8.8: seq=4 ttl=117 time=33.296 ms
    1008 bytes from 8.8.8.8: seq=5 ttl=117 time=33.292 ms
    1008 bytes from 8.8.8.8: seq=6 ttl=116 time=25.172 ms
    1008 bytes from 8.8.8.8: seq=7 ttl=116 time=25.273 ms
    1008 bytes from 8.8.8.8: seq=8 ttl=117 time=33.292 ms
    ^C
    --- 8.8.8.8 ping statistics ---
    9 packets transmitted, 9 packets received, 0% packet loss
    round-trip min/avg/max = 25.132/27.906/33.296 ms

     

     

    I spent the afternoon trying to identify the reason. With the rule all released, I still have trouble sending and receiving.

    Follows screens of errors captured in the packet monitor. Shows some Microsoft IPs as invalid traffic. The rule is all released and still does not work. The rest like sites, whatsapp, other services, are working.

    log packet monitor:

  • What that report shows is that none of your outgoing traffic is being seen as valid eg you are restricting the wrong IP address.

    Ian

  • Hi

    I filtered for the violations. If you filter by forward, it shows the connections. But something is blocking.

    I realize that when I enable the web policy, it makes it more difficult. But in the web filter logs it does not show locks. Sophos support said that sometimes it does not show the logs the locks. Does it proceed?
    Any idea of command to solve the problem?