Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

TCP Retransmission / RST, ACK - some websites not answering

Hello,

I have a strange behaviour with Sophos XG.

It is happening now on 2 sites.

On one site I Have HA (A/P) XG2300 with v19 MR-1.

On second I have HA (A/A) XG2100 with v19.

I tried 18.5 MR-3 with the same issues.

Most of the traffic seems OK.

But some websites are not reachable from LAN and some other start to get ERR_CONN_RST in google chrome after a while.

At the same time in log viewer I get "could not associate packet to any connection" or "Invalid packet." or "Invalid TCP state."

And timestamp/IP dest of these errors corresponds.

Most of the websites that gets error are on Microsoft Azure but not only.

And from the Wireshark trace, they are all TLS1.2.

I have changed FW rules, removed any filtering I think possible.

When connected to the VPN, it works OK.

From LAN not.

Any hint welcome.

Fab



This thread was automatically locked due to age.
Parents Reply
  • please set the filter to a single src-port ... so we can see a specific session.


    Dirk

    Systema Gesellschaft für angewandte Datentechnik mbH  // Sophos Platinum Partner
    Sophos Solution Partner since 2003
    If a post solves your question, click the 'Verify Answer' link at this post.

Children