Hi there,
Twice in three days I've had a network issue caused by Sophos XG210 and I would like some feedback on how to prevent it re-occurring or, at the very least, how to solve it in the future.
In both cases, connections to HTTP do not work, giving intermittent 502 errors on Chrome and Safari whilst only some connections to HTTPS work including Google (and its derivatives) and Facebook. Failed HTTPS connections would also give intermittent 502 errors. Pings and other protocols still worked as expected during the outage.
These issues were experienced regardless of the policies the traffic was governed by and were found with HTTP and HTTPS decryption turned on and off, and web and application filters turned on or off. I even set up a policy for a small Lab network with a *shudder* "Permit Any" policy and even this didn't solve the issue.
The device was fully updated. The last successful update occurred around 45 minutes before the last issue arose and involved the Avira and Sophos AV. This may be the place to start as another Sophos governed network in our company also experienced issues around the same time. Unfortunately there is no network admin at this location and I haven't been able to get a hold of the logs yet so I cannot compare the two.
The outages both resolved themselves after 1-1.5 hours. During this time I had to connect our internal network directly to the WAN links due to connectivity being more of an issue than security (not my words!). This situation cannot be allowed to become a common occurrence.
What troubleshooting steps can I now follow to find the source of this problem? Any help is greatly appreciated!
Tom
This thread was automatically locked due to age.