This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

IPS blocking even if FW rule says to not

Hi,

Firmware : SFOS 17.1.3 MR-3

Sophos support are not able to solve issues related to signature 15 (Potentially bad traffic). We are having issues with an Amazon service and Crashplan presently. Not sure if related to Pattern update or recent firmware upgrade.

As an example: 

Crashplan is used to back up a server files to the cloud and IPS is blocking it. So I created a rule (LAN,ANY­­>>WAN,*.crashplan.com) and I set all protections (Scan HTTP, IPS, Web Policy) to "none". The log shows that traffic to this web site go through this new rule but IPS is still blocking it.

Am I the only one having issue?

Tks



This thread was automatically locked due to age.
Parents
  • Hi Speatech,

     

    I have had the same issue with MULTIPLE clients and the XG firewall now on 17.1.3 MR-3. I have had to call Sophos Support multiple times and each time it was this IPS Signature 15 error. They are calling it an "anomaly" detection.  The issue is I have not heard anything from Sophos regarding a patch for this, even though Support is calling it a "known bug".

    Would love to hear from Sophos. 

Reply
  • Hi Speatech,

     

    I have had the same issue with MULTIPLE clients and the XG firewall now on 17.1.3 MR-3. I have had to call Sophos Support multiple times and each time it was this IPS Signature 15 error. They are calling it an "anomaly" detection.  The issue is I have not heard anything from Sophos regarding a patch for this, even though Support is calling it a "known bug".

    Would love to hear from Sophos. 

Children