Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

"Allow All" web filter policy blocks request allowed when there is no web filter policy

Hi all

I am having difficulty troubleshooting a problem with a request from a mobile phone 2-factor authentication app being blocked by our XG firewall (XG125 SFOS 19.0.0 GA-Build317).

To test this, I have created a new top-most firewall rule for traffic from the user's phone's IP address to the WAN Any Network and Any Service. There is no web filter, app control, or IPS policy configured. None of the checkboxes associated with web filtering is checked. The user's app works.

Then I add a web filter policy with only one rule defined: the Default action of allow. Now the user's app does not work - when they acknowledge the request to confirm the authentication challenge, the app just hangs.

So just applying a web filter policy that blocks nothing is causing the request from this app to fail in some way. What other firewall behaviours come into play when you have a web filter policy applied that would be causing this?

Any help is much appreciated.

David



This thread was automatically locked due to age.
Parents Reply Children
  • Thanks Ian

    I have looked at the ssl/tls logs in log viewer. There are no errors arising from requests from the user's IP address. Everything is "Do not decrypt". The user device is an android phone and due to SSL/TLS inspection now working with Android, there are no rules configured for android devices - so all SSL/TLS logs for the user device are from the default rule that is don't decrypt.

    I have even turned off all SSL/TLS inspection and it has not changed anything.

  • Hi,

    you need to start packet capture to identify the traffic.

    ian

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.