This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Internal application only works if you disable the Sophos XG SSL / TLS Inspection function.

Hello gentlemen, greetings to all.

I have a very curious problem in a customer's environment.

I implemented a Sophos XG 330, all working well, but there is an application on a client server, which needs to communicate on TCP port 443 with another application on the internet, it is an application for authorization of medical examinations. Whenever the application sends the packet, a communication error occurs, I created an outbound rule, where the source is the application server, destination all over the internet, any port, I disabled AV, IPS, Web Filter, App Filter and any another type of filter, yet the error persists. I created an exception rule for SSL / TLS Inspection, the error persists.

So it only works if I disable the SSL / TLS of the equipment, stop this feature, but with that the Web Filter does not work correctly, it does not block the https sites, so this cannot be a solution. Attached is the image where I disable SSL / TLS inspection.

Does anyone here have any idea what I can do?



This thread was automatically locked due to age.
Parents
  • FormerMember
    0 FormerMember

    Hi ,

    Thank you for reaching out to the Community! 

    What is the firmware version on your firewall? When you use legacy web proxy and bypass the application, does it works? 

    Thanks,

  • Firmware: XG330 (SFOS 18.0.3 MR-3)

    It is a specific application, developed by the company, for sending electronic transactions, for authorization of health plan procedures. This application uses TCP port 443 to send the transaction, it cannot be via a browser. The application is not part of the category of apps recognized by the app filter.

Reply
  • Firmware: XG330 (SFOS 18.0.3 MR-3)

    It is a specific application, developed by the company, for sending electronic transactions, for authorization of health plan procedures. This application uses TCP port 443 to send the transaction, it cannot be via a browser. The application is not part of the category of apps recognized by the app filter.

Children