Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Having Problems with WAF with Nextcloud behind it. Error: "413 Request Entity too large"

Hi,

 

I am using a Nextcloud behind a XG with WAF enabled. This worked until version 18 of XG. Now I am getting 413 Request Enitity too large Errors as soon as I am enabling "Common threat filter", Antivirus or Cookie Signing in the Protection Policy.

The WebServerProtection Log's in XG are showing the requests as allowed, but with HTTP Status Code 413. In the Logs of the server, there's nothing found.

Could someone advise me how to fix this?

 

P.S. After some research, I've read in the Nextcloud Forums that if a NGINX Reverseproxy is used, the configuration key "client_max_body_size" has to be set to a higher value.



This thread was automatically locked due to age.
Parents
  • Hi,

     

    I'am using the standard Mode which is 4(Most Restrictive).

    I've already looked in the advanced shell, but there is nothing logged as restricted.

    _______________________________________________

    Sophos XG User

  • Please enable the debug logging as suggested here:

  • Hi,

    I've found the following error related to the upload:

    [Thu Feb 27 22:44:15.948735 2020] [security2:error] [pid 23885:tid 139679122720512] [client ***.***.***.***:51412] [client ***.***.***.***] ModSecurity: Request body no files data length is larger than the configured limit (1048576).. Deny with code (413) [hostname "***********"] [uri "/remote.php/dav/uploads/**********/501f9459ceeb6f12bbee63637795811e/0000000000000000-0000000002256745"] [unique_id "Xlg4L38AAAEAAF1NhhMAAAAf"]

    But now the question is, how to fix this?

    Regards

    _______________________________________________

    Sophos XG User

Reply
  • Hi,

    I've found the following error related to the upload:

    [Thu Feb 27 22:44:15.948735 2020] [security2:error] [pid 23885:tid 139679122720512] [client ***.***.***.***:51412] [client ***.***.***.***] ModSecurity: Request body no files data length is larger than the configured limit (1048576).. Deny with code (413) [hostname "***********"] [uri "/remote.php/dav/uploads/**********/501f9459ceeb6f12bbee63637795811e/0000000000000000-0000000002256745"] [unique_id "Xlg4L38AAAEAAF1NhhMAAAAf"]

    But now the question is, how to fix this?

    Regards

    _______________________________________________

    Sophos XG User

Children