Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Xg - strange application behaviour

Hi folks,

I have been investigating an issue with my Apple devices using an application called manual proxy surfing.

The strange behaviour is if I block proxy and tunnel then I get error rs in the application log and in the daily reports. If I don't block it then there is no entries application log  and nothing appears in the firewall log.

The application uses port 80 and if not blocked is shown as browser based, general internet connecting to safe browsing googleapis?

What is causing this error in classification and as a results blocks the connections?

Ian



This thread was automatically locked due to age.
Parents
  • Hi Ian,

    Unfortunately I don't understand some things ...

    1. if you block "proxy and tunnel" your application "manual proxy surfing" is blocked ... where is the error?

    2. how do you do "don't block" ... there are different options and because sometimes the application-control isn't active anymore, you have no logging.

    The web-category is different to the application-category. If you filter for application, this category is correct:
    appCategory

  • Very simple the error show in the application log as access denied, the daily reports and the gui.

    i unblock it by changing application control to allow all in the firewall rule and the manual proxy surfing does not show against the destination ip addresses that appear in the blocked report.

    ian

Reply
  • Very simple the error show in the application log as access denied, the daily reports and the gui.

    i unblock it by changing application control to allow all in the firewall rule and the manual proxy surfing does not show against the destination ip addresses that appear in the blocked report.

    ian

Children
  • My application log shows only blocked apps too.

    If you allow the app "unblock it by changing application control" ... why it should be blocked and logged anymore?

  • It should show up in a log as do other applications that are allowed. When allowed the classification changes, so there is an issue with some part of the classification process.

    If I search the various logs for 'Tunnel and Proxy' after having allowed all in applications it does not show.

    The application should show in the daily reports and doesn't.

    Ian