Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Some websites get ERR_TIMED_OUT

Hello

I have been looking for this problem for a while now.

Support was useless.

On 2 different sites, at random moments, some websites are returning ERR_TIMED_OUT .

Site https://www.bankinter.com/ or another one point on a server on Azure.

I know they work because on the third site with Ubiquiti or from home, it works.

I have : 

1. pretty much any filtering from Firewall rules

2. checked and changed the DNS

3. upgraded to 19.5MR1

4. Disabled HA (no matter if it is disabled / A/P or A/A)

5. changed the internet connection

I already have a post about this but never really got help.

This is my last attempt before I ditch these Sophos.

Any clue is appreciated.

Don't hesitate to ask for screens or logs, I can provide.

Thanks

Fab



This thread was automatically locked due to age.
Parents Reply Children
  • Hi Erick Jan,

    Thank you for looking.

    Funny to see how cases like that are closed by Sophos. But that's the past.

    Anyway, it seems a lot faster and to the point here. Let's give it a try !

    This is what I get in the Firewall logs for one of the site I am trying to reach :

    I will add the exceptions as you suggested.
    Would I have to continue adding any other site that doesn't work when Sophos is in the chain ?

    For the TLS/SSL, could you guide me on where you want me to grab that ? 

    I went to TLS/SSL inspection but there is nothing there.

    Thank you very mush for your help.

    Fab

  • Hi again,

    I went to the Exceptions... and apparently I tried that already (sorry it has been so long we have this issue...)

    Is this correct ? 

  • Hi Fjay,

    Upon checking your FW logs, It is being denied.

    • Can you create a test policy to allow the said site on the very top.
    • Also, create an SSL/TLS Policy with the following if what you said that "I went to TLS/SSL inspection but there is nothing there."

    • For Exception, you can try to follow the following link:

     Server did not respond to client hello 

    • Can you share your SSL/TLS log after accessing the site like below

    Erick Jan
    Community Support Engineer | Sophos Technical Support
    Sophos Support Videos Product Documentation  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.

  • Hi Erick Jan,

    Thank you again.

    I have created a rule at the top : no go.

    I added the TLS rule as shown : to no avail. Still ERR_TIMED_OUT.

    Here is what I have in logs : 

    Does it help ? 

    Fab

  • Hi FJay,

    The screenshot you've attached are not visible.

    based on the previous FW rule log. It isnt hitting any FW rule logs and is being denied.

    Also, kindly add more information concerning the issue,

    1. What sites are experiencing err_timed_out

    2. Create a test policy to allow any without Web policy

    3. Screenshot of  FW logs and the FW rule you've created

    4. Screenshot of SSL/TLS configuration and logs after accessing the site.

    I would recommend creating a case so that it can be properly investigated,

    Erick Jan
    Community Support Engineer | Sophos Technical Support
    Sophos Support Videos Product Documentation  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.