This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

IPS Blocking legit traffic speedtest.net / IPS impacting performance even if IPS is not enable in the rule

I get thousands of this alerts every time I use https://www.speedtest.net/

 

"Data sent on stream after TCP Reset received"

Does it make sense? how can I disable it or fix the issue?
The IP belongs to the service
 
It's a bug?


This thread was automatically locked due to age.
Parents Reply Children
  • Hi  

    • In 16.5 MR4 and later, the term microapp has been removed from the administrators UI, the CLI system application_classification microapp-discovery is defaulted to off. In previous releases the Application Filter contained an Enable Micro App Discovery and the system application_classification microapp-discovery was defaulted to on.
    • In 16.5 MR4 and later, applications using HTTPS (microapps) are detected based on the firewall's Decrypt & Scan HTTPS setting.
    • In 16.5 MR4 and later, the CLI system application_classification microapp-discovery is used for proof of concept. It forces all port 443 traffic to go through proxy with HTTPS scanning on regardless of Firewall Rule setting. It should be off for all normal production systems. 
    • Turning on microapp discovery will cause the problem described in this KB. 

    From: https://community.sophos.com/kb/en-us/125458