Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

TCP Retransmission / RST, ACK - some websites not answering

Hello,

I have a strange behaviour with Sophos XG.

It is happening now on 2 sites.

On one site I Have HA (A/P) XG2300 with v19 MR-1.

On second I have HA (A/A) XG2100 with v19.

I tried 18.5 MR-3 with the same issues.

Most of the traffic seems OK.

But some websites are not reachable from LAN and some other start to get ERR_CONN_RST in google chrome after a while.

At the same time in log viewer I get "could not associate packet to any connection" or "Invalid packet." or "Invalid TCP state."

And timestamp/IP dest of these errors corresponds.

Most of the websites that gets error are on Microsoft Azure but not only.

And from the Wireshark trace, they are all TLS1.2.

I have changed FW rules, removed any filtering I think possible.

When connected to the VPN, it works OK.

From LAN not.

Any hint welcome.

Fab



This thread was automatically locked due to age.
Parents Reply Children
No Data
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?