Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

TLS engine error: FLOW_TIMEOUT through IPSec Remote Access Tunnel

Hello community,

we are facing a strange behavior since we´ve updated our XGS4500 to SFOS 19.5.0 GA-Build197. Some website are not fully accessible through IPSec Remote Access Tunnel (via Sophos Connect Client).

The first line of the above SSL/TLS inspection log shows the error while accessing a website from github.com through the tunnel.

The second line shows a successful access of the same website from an internal client.

Both traffic flows passing the same rules.

When the traffic goes through the tunnel it looks like that the tls specific informations get lost.

Firewall acceleration is enabled and loaded as well as IPsec acceleration is turned on.

This behavior is browser independent. We've tried same versions of Google Chrome and Microsoft Edge on both devices in normal and incognito mode.

I am grateful for any idea that solves the problem.

Best regards

Markus



This thread was automatically locked due to age.
Parents Reply
  • Hi Raphael,

    after disabling IPSec and firewall acceleration the FLOW_TIMEOUT errors with TLS version "unknown" are gone. The sites which are not accessible through IPsec Remote Access VPN are now accessible.

    But there are still FLOW_TIMEOUT errors in the SSL/TLS inspection log:

    These errors are also from internal clients, but it seems that there is no impact. Anyway, I don't get any feedback from my colleagues that there are problems when calling web pages. Also, I cannot reproduce these errors.

    Regarding MTU size I´ve done some testing from an internal server:

    As I understand it, the MTU (1500) and MSS (1460) values are set correctly in XGS.

    UPDATE: I take it all back. After disabling the acceleration features the log is full of "Dropped due to TLS engine error: OUT_OF_MEMORY[201]" errors regarding internal and remote clients.

    Best regards
    Markus

Children
No Data