Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

TCP Retransmission / RST, ACK - some websites not answering

Hello,

I have a strange behaviour with Sophos XG.

It is happening now on 2 sites.

On one site I Have HA (A/P) XG2300 with v19 MR-1.

On second I have HA (A/A) XG2100 with v19.

I tried 18.5 MR-3 with the same issues.

Most of the traffic seems OK.

But some websites are not reachable from LAN and some other start to get ERR_CONN_RST in google chrome after a while.

At the same time in log viewer I get "could not associate packet to any connection" or "Invalid packet." or "Invalid TCP state."

And timestamp/IP dest of these errors corresponds.

Most of the websites that gets error are on Microsoft Azure but not only.

And from the Wireshark trace, they are all TLS1.2.

I have changed FW rules, removed any filtering I think possible.

When connected to the VPN, it works OK.

From LAN not.

Any hint welcome.

Fab



This thread was automatically locked due to age.
Parents Reply
  • Check your TLS Logviewer on your firewall. Do you see drops there? It looks like the the TLS Connection is not getting established. Could be related to a policy you are using. 

    __________________________________________________________________________________________________________________

Children