This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

new XG installs are causing ScreenConnect 'last connected' timer resets even though NO security services are enabled.

I have now set up two firewalls for two different clients who also use our screenconnect software on their machines for us to remotely connect for repair, diagnostics, etc. The screenconnect software on the client machine will regularly poll back to the screenconnect server (located in my office) to let the server know that it is available and online. This shows as a 'time connected' counter in the screenconnect dashboard. This has always been very stable, and has not been blocked or otherwise interfered with by any other firewall or security appliance. All clients that do not have sophos firewalls do not exhibit this behavior. However, the two XG (115 and 210) firewalls that I have installed in the last two days are causing that counter to reset every 5 minutes (I can see the activity in the screenconnect logs). Both firewalls are in gateway mode, directly connected to the ISP and have NO security services enabled yet. No AV, no IPS, No web filter...nothing. Just the default rule in the firewall that is put in place during the initial configuration wizard.

FYI, the client is set to relay out to the screenconnect server on port 80 and 443, so I don't understand why that would get reset every 5 minutes.



This thread was automatically locked due to age.
  • Paul,

    please upload some firewall logs and web filtering logs for the IP that are experiencing the issue.

    Thanks

  • There is no filtering log available, filtering is not on and it is blank. A screenshot of the firewall log is below. This is the best I can do tonight, there is no obvious way to export the firewall log in an excel file or txt or anything simple. Anyway, it looks like every time the screenconnect client calls out to my server on port 443, I can go look at the server and the time connected has been reset. It coincides almost perfectly...each time it calls out, the time is reset again. Since the client phones home every 5 minutes...it's reset every 5 minutes. The sophos must be re-writing something in the packet to make the server think that it is different in some important way?

    I filtered for only traffic going out to my server...the other traffic on 8080 etc is for another system.

  • Same issue here. Every 5 minutes, a connection reset.

    Sophos XG105w / Firmware: SFOS 16.01.1

    ScreenConnect client version: 6.0.11622.6115

    I use ScreenConnect (SC) cloud account.  I contacted SC support - there are no default SC schedules running every 5 minutes.  There is a 1 minute "check-in" and a 20 minute "update guest info"

    While in a session, that sessions does not "reset" - all others do.

    No extra software running on remote computer.

    SC Timeline looks like this

    Firewall logs:

    Default LAN2WAN rule:

     

     

  • Sounds like a potential TCP/UDP Timeout. Have you tried modifying this value via the Console and the advanced-firewall Comandset?

    Please send me Spam gueselkuebel@sg-utm.also-solutions.ch

  • Glad to see (but also sorry to see!) that someone else is having this issue. Hopefully someone in the know will take a closer look at this!

  • Checked Intrusion Prevention: 0 blocked traffic

    To be sure, disabled any DOS prevention, unchecked all apply flags:

    Same result, 5 minute resets (time-outs).

  • Hi Paul,

    Check #1 in my guide here. Capture drops on the destination/ source IP and port. If you do not see any drops, take a pcap and verify who generates the RESET packet.

    Thanks

    Sachin Gurung
    Team Lead | Sophos Technical Support
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.

  • Upgraded to latest firmware.  SFOS 16.01.2

    No improvement

  • console> drop-packet-capture 'host 192.168.1.249'
    [See packet capture below]

    from the GUI

     Any help interpreting this would be appreciated

  • Hi Sam,

    These are general UDP drops on port 137 for Net Bios traffic. Can you describe to me how screen connect works. Is there any destination IP address on which we can capture dumps? I hope the screen connect clients are not used to connect to an internal system instead of a system connected on WAN.

    Thanks

    Sachin Gurung
    Team Lead | Sophos Technical Support
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.