Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

How to free skype?

How to free skype?

 

We have skype released for some user however skype accesses more does not send messages



This thread was automatically locked due to age.
Parents
  • Here the same issue. As soon I disable "Decrypt & Scan HTTPS" on my FW rule Skype can make calls.

    I have tried configuring different exeptions for HTTPS Scans without success.

  • hello,

     

    Same Issue.

    Exception not working.

     

    Erick.

  • Hi, everyone...

     

    I'm having the same problem, how why allow the Skype on Sophos XG 16.05?

     

    Thanks.

  • Hi ALL, 

    We have a Known issue with Skype at the moment and the BUG ID  NC-14551, In the mean time we have a Work Around , kindly follow the steps 

    Step1: Go to Web > Exceptions > Add Exceptions 

    Step 2 : Select Web Site Categories > Add new item >IP address

    Step 3: Check on HTTPS Decryption and save .

    Make sure the rule is enabled.

  • Hi,

    I try your workaround in the exception, but not fix the issue.

    Just unchek "Decrypt https" in the general rule fix the isssue.

    My UTM is XG230 (SFOS 16.01.1)

    Thanks,

    Erick.

  • Hi everyone,

     

    I found a solution to this issue:

     

    Go to "Application" > "Application Fliter" > take a look of the "Filters" on this tab and edit all to see wich one have the "Skype" and "uncheck them.

     

    In my case this works fine, but I had to open all "Filters" to found and disable the block of skype.

     

     

    If any one have another solution, please send to us.

  • Hi Aditya,

    I can only see some of the URL's in the screenshot above and you also have an IP list but don't share what they are?   Can you provide all of the required DNS entries and IP addresses for exclusion and we will test it out on our end?

     

    Cheers,

    Jason

  • Forget about Web Exception Rules. Temporary workaround for me was:

    1. To grab (or rather guess) the IPs used by Skype Client:

    XG310_WP01_SFOS 16.05.0 GA# tcpdump -i Port[X] tcp and src [MY_HOST_IP] and dst port 443

    or

    MONITOR & ANALYZE > Diagnostics > Connection List (with proper filter for interface, source IP and TCP:443)

    2. My IP list (may differ for your region - grab your own and update it here)

    40.84.51.249, 40.83.21.197, 40.77.226.192, 40.115.1.44, 40.101.72.114, 40.83.21.197, 13.107.8.50, 13.94.40.40, 13.69.157.102, 65.52.139.168, 13.75.43.188, 104.208.156.39, 40.83.21.197

    3.  Create the Firewall bypass rule for Destination Networks including grabbed IP list where Decrypt & Scan HTTPS option is left unchecked.

    Source Zone: LAN

    Source Networks and Devices: Any

    Destination Zone: WAN

    Destination Netoworks: Skype Services (my custom IP List object)

    Services: HTTP, HTTPS

    other rule options as default

     4. Please note it's a 'follow the white rabbit' game but it works. Now it's time to play with Skype for Business ... any volunteer?

  • @MarekDalke, I agree this is the only way that works for now - collect IP addresses and disable Decrypt & Scan HTTPS for them. But this can be done via Web Protection Exception rules as well - using the "IP addresses" box instead of "URL pattern matches". What are the advantages of creating a separate Firewall rule and a destination Network?

  • The advantage of Firewall Bypass Rule is that I can make Skype calls. With Web Protection Exception rule (same IPs used) I can't.

Reply Children