Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SOPHOS XG Home - Internet Connection loss

Hi Everybody,

I'am using the following configuration:

HYPERVISOR-Hardware:

  • LENOVO THINKCENTRE M70Q
  • i5-10400T
  • 256 GB SSD
  • 16 GB RAM
  • 1 LAN integrated LAN-Port
  • 1 UGREEN USB 3.0 Nics (ax88179_178a 2-1:1.0)


HYPERVISOR-Software:

Proxmox Virtual Environment 7.1-7

HYPERVISOR-VMs:

  • SOPHOS XG Home VM 18.5.2
  • 4 CPUs
  • 8 GB RAM
  • 2 VM-Bridges
    • Bridge 1 - LAN (Connected to NETGEAR JGS524E-20EUS Switch)
    • IP: 172.16.16.220
    • GW: 172.16.16.16
    • Bridge 2 - WAN
    • IP: 192.168.178.200 (Connected to FRITZ!Box)
    • GW: /

Problem:

First of all everything looks fine. My Clients (Wired [NETGEAR JGS524E-20EUS] and not Wired [NETGEAR EX3700]) receive IP-Adresses and can connect to the internet successful. I have only configured some Firewall-Rules like "Internet Access" with HTTP and HTTPS access and some other Port-Rules for WhatsApp and Gaming.
Anyway there is a problem which makes me crazy. If I start a WhatsApp-VideoCall or for example a Microsoft Teams-Video Call the internet connection on the mobile devices breake. I can only fix this when I plug the NIC-Cable of WAN-Port off an on again. When I have done this the connections is back again and everything is working till the next call. Mostly I recognized this with a mobile Client but yesterday I lost internet-connection an wired client too.

Can somebody help me please?

Kind Regards



This thread was automatically locked due to age.
Parents
  • Hi Simax

    Have you added HTTP and HTTPS under the Service on firewall rule?

    If yes then some ports is required to add on the same rule on which WhatsApp and Microsoft Teams work 

    To check which ports are getting drop 

    execute the below command to get the details of drop traffic and allow on the firewall rule

    console>drop-packet-capture 'host <ipaddress>'

    example drop-packet-capture 'host 192.168.10.20

    where 192.168.10.20 is PC IP

    share the logs for the above output to assist you further 

    support.sophos.com/.../KB-000036858

    Thanks and Regards

    "Sophos Partner: Infrassist Technologies Pvt Ltd".

    If a post solves your question please use the 'Verify Answer' button.

Reply
  • Hi Simax

    Have you added HTTP and HTTPS under the Service on firewall rule?

    If yes then some ports is required to add on the same rule on which WhatsApp and Microsoft Teams work 

    To check which ports are getting drop 

    execute the below command to get the details of drop traffic and allow on the firewall rule

    console>drop-packet-capture 'host <ipaddress>'

    example drop-packet-capture 'host 192.168.10.20

    where 192.168.10.20 is PC IP

    share the logs for the above output to assist you further 

    support.sophos.com/.../KB-000036858

    Thanks and Regards

    "Sophos Partner: Infrassist Technologies Pvt Ltd".

    If a post solves your question please use the 'Verify Answer' button.

Children
  • Hi 

    I will check this later and add HTTP and HTTPS to "WhatsAPP-" and "Microsoft Teams"-Rule. Also will then post if something is droped.

    It seems logical for me what you have written but what I do not understad is that my whole internet-connection is crahed in these moments.

    But I will write you later! Thanks! :)

    Just for your understanding, the Videocalls can be established but then they crashed after 30-60 seconds. And when this is happening the internet connections is lost too.

  • Here is a screenshot from my current rule-setting. But it does not seems correct for me or am I'm wrong?

  • Hi,

    most of your traffic will go out using your top rule. The rule using WhatsApp and fif22 are they FQDNs and do they cover all FQDNs sued by those the applications, You will also need to create exceptions for some parts gof the applications because they do not like being intercepted and scanned. Futhert have you disabled the scan video and audio in the web settings policy?

    Also check that you have set the CPU and memory assignment to fixed values and that the NICs have had power saving disabled.

    Ian 

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.

Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?