This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Cross-Origin - page not reachable

I have two Sophos XG330 (SFOS 18.0.3 MR-3).
A page is blocked, which loads some more data from external pages.

Error:
Uncaught ReferenceError: YUI is not defined
Cross-source (cross-origin) request blocked: The same-source rule prohibits reading the external resource at cdn.smugmug.com/.../icons-large-defs-RANDOME-STUFF.svg. (Reason: CORS request failed).
Cross-source (Cross-Origin) request blocked: The same-source rule prohibits reading the external resource on cdn.smugmug.com/.../icons-small-defs-RANDOME-STUFF2.svg. (Reason: CORS request failed).

As soon as I put the client in a firewall rule which allows anything (LAN : Any -> WAN : Any) the page works.
I have a firewall rule so cloud services (Dropbox, OneDrive,...) are blocked.
Data is loaded from smugmug.com which is blocked.



I have created a firewall rule which includes all domains that need to be accessed here. I have also allowed all services.
I have also created an exception with RegEx.

The access is still prevented.
It seems that the FW rule is working, because traffic is going through it, but the firewall doesn't seem to care about the data being passed through.
I can also activate or deactivate all checks (HTTP/S-Scan,...). Still absolutely nothing works.

When calling the blocked data, I get the following message in Firefox:
Error: Secured connection failed.

The connection to the server was reset while the page was loading.
    The website cannot be displayed because the authenticity of the data received could not be verified.
    Please contact the owner of the website to inform him about this problem.



In Chrome the whole thing only in short:
This page does not work
cdn.smugmug.com has not sent any data.
ERR_EMPTY_RESPONSE




What am I doing wrong, or what is ehr Sophos doing wrong to make the share not pull?




This thread was automatically locked due to age.
Parents Reply
  • FormerMember
    0 FormerMember in reply to Anonymous User

    Hi ,

    Sincerest apologies for the delays in getting back to you. 

    Did you notice any requests being blocked on the firewall while accessing the website? 

    I would suggest you capture packets on the client-side and determine if the requested domain is part of the firewall rule you configured. 

    Thanks,

Children
No Data