Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Dropped due to TLS engine error: FLOW_TIMEOUT[5]

I appreciate that other people have raised this issue before, but I am having problems with a specific IOT device trying to send a data packet to the cloud.

This particular device (which reports the salt quantity in a water softener) causes the following error:

2022-03-07 13:05:08SSL/TLS inspectionmessageid="19006" log_type="SSL" log_component="SSL" log_subtype="Error" severity="Information" user="" src_ip="192.168.1.193" dst_ip="18.193.34.83" user_group="" src_country="R1" dst_country="DEU" src_port="52708" dst_port="443" app_name="" app_id="0" category="Information Technology" category_id="29" con_id="1688866560" rule_id="1" profile_id="1" rule_name="Exclusions by website or category" profile_name="Maximum compatibility" bitmask="Valid" key_type="KEY_TYPE__RSA" key_param="RSA 2048 bits" fingerprint="a9:a0:f0:b5:bc:21:6f:26:a8:01:49:5d:33:c5:0e:dc:62:2f:3d:53" resumed="0" cert_chain_served="TRUE" cipher_suite="TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256" sni=".....aylanetworks.com" tls_version="TLS1.2" reason="Dropped due to TLS engine error: FLOW_TIMEOUT[5]" exception="" message=""

I have tried everything to try and exclude this device from all forms scanning (but clearly am doing something wrong). How can I ensure that this device stays clear of any form of firewall processing?

Thanks.



This thread was automatically locked due to age.
  • I am assuming that the connection is going to port 443 from the log below:

  • Next item, the ssl/tls will only work if the device has the XG ca installed otherwise the rule isN'T providing any functions.

    ian

    Fix typing mistake which made the post provide the wrong answer.

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.

  • Hi Ian. 

    I don't see it like that. I'm trying not to run packet inspection on the device - however, despite best effort, the outgoing packets get sent to the DPI engine anyway.

    There should be no need (and anyway, there is no way) to add a CA to the device. That should only be needed for inspecting inbound packets?

  • Hi Daniel,

    I have corrected my previous.s post, it left out a couple characters which changed the intent of the post.

    If you do  not want to use the DPI you have two choices as far as I can see,

    1/. enable the web proxy but not scanning

    2/. enable firewall bypass ( you would have to search the forum for those instructions).

    Ian

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.

Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?