Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos XG block telegram but i don't want

Hi,

i don't understand why sophos xg mark telegram as DDOS attack.. i have disabled DDOS protection tryied to disable IPS etc from Firewall rule but nothing change...

i attached last test i did

maybe i'm loosing some configuration?

thank you



This thread was automatically locked due to age.
Parents Reply
  • Hi,

    do you have the XG CA installed on the testing PC?

    There appears to be a configuration issue that I cannot see from what you have posted. I do not have those exceptions on my system and can at least connect the initial telegram page. I have quite a restrictive set of firewall rues and policies in place and use scan and decrypt in my firewall rules for most devices that can have a CA installed..

    Ian

Children
  • yes, it is installed on device,

    no problem to go on the initial page but when you use Telegram after few seconds going into loop for "connecting" and never change the state (no message sync etc)

  • Hi,

    next issue with your firewall rule, change web to allow all, disable the boxes you have ticked and try again. XG my see the looping as an attack because of the continuous packets from the same source with the same data.

    Further you can build your own IPS policy that excludes the item detecting the issue and use th policy on your telegram firewalll rule only.

    Ian