This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

[Pregunta] Trafico no valido desde ultimo parche

Muy buenas,

 

Desde la ultima actualización que sufrió nuestro sophos XG Firewall estamos notando problemas a la hora de acceder a sitios donde antes no teniamos dicho incidente, a continuación pongo una descripción del error a nivel Firewall:

2020-07-28 12:53:02Firewallmessageid="01001" log_type="Firewall" log_component="Invalid Traffic" log_subtype="Denied" status="Deny" con_duration="0" fw_rule_id="N/A" nat_rule_id="0" policy_type="0" user="" user_group="" web_policy_id="0" ips_policy_id="0" appfilter_policy_id="0" app_name="" app_risk="0" app_technology="" app_category="" vlan_id="" ether_type="IPv4 (0x0800)" bridge_name="" bridge_display_name="" in_interface="" in_display_interface="" out_interface="" out_display_interface="" src_mac="" dst_mac="" src_ip="10.129.2.228" src_country="" dst_ip="10.192.65.21" dst_country="" protocol="TCP" src_port="49318" dst_port="8080" packets_sent="0" packets_received="0" bytes_sent="0" bytes_received="0" src_trans_ip="" src_trans_port="0" dst_trans_ip="" dst_trans_port="0" src_zone_type="" src_zone="" dst_zone_type="" dst_zone="" con_direction="" con_id="" virt_con_id="" hb_status="No Heartbeat" message="Could not associate packet to any connection." appresolvedby="Signature" app_is_cloud="0" Copiar al portapapeles

 

Y una captura que demuestra como a nivel de politica si tiene los permisos el usuario para acceder:

 

¿Alguien más esta padeciendo estos incidentes con la ultima actualización? ¿hay una posible solución a esto?

 

Gracias!



This thread was automatically locked due to age.
  • FormerMember
    0 FormerMember

    Hi  

    Thank you for reaching out to the Community! 

    Could you please provide screenshots of web proxy settings and firewall rules? 

    Are you experiencing an issue with only specific websites? 

    Thanks,

  • Hi H_Patel,

     

    Thank you very much for your answer, I tell you that this is happening with specific sites which if web filtering are allowed, even what we notice is that some days these sites work well and others are practically inaccessible but if we try to access from another site for example no problem.

     

    Policy website:

     

    ADS_ALLOW include one of the website that doesn't work fine.

     

    Firewall Rules:

     

    In this case SOPHOS is using the default rules of standard navigation, do you need a screenshot of how they are configured inside?