Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

new XG installs are causing ScreenConnect 'last connected' timer resets even though NO security services are enabled.

I have now set up two firewalls for two different clients who also use our screenconnect software on their machines for us to remotely connect for repair, diagnostics, etc. The screenconnect software on the client machine will regularly poll back to the screenconnect server (located in my office) to let the server know that it is available and online. This shows as a 'time connected' counter in the screenconnect dashboard. This has always been very stable, and has not been blocked or otherwise interfered with by any other firewall or security appliance. All clients that do not have sophos firewalls do not exhibit this behavior. However, the two XG (115 and 210) firewalls that I have installed in the last two days are causing that counter to reset every 5 minutes (I can see the activity in the screenconnect logs). Both firewalls are in gateway mode, directly connected to the ISP and have NO security services enabled yet. No AV, no IPS, No web filter...nothing. Just the default rule in the firewall that is put in place during the initial configuration wizard.

FYI, the client is set to relay out to the screenconnect server on port 80 and 443, so I don't understand why that would get reset every 5 minutes.



This thread was automatically locked due to age.
Parents Reply Children
  • There is no filtering log available, filtering is not on and it is blank. A screenshot of the firewall log is below. This is the best I can do tonight, there is no obvious way to export the firewall log in an excel file or txt or anything simple. Anyway, it looks like every time the screenconnect client calls out to my server on port 443, I can go look at the server and the time connected has been reset. It coincides almost perfectly...each time it calls out, the time is reset again. Since the client phones home every 5 minutes...it's reset every 5 minutes. The sophos must be re-writing something in the packet to make the server think that it is different in some important way?

    I filtered for only traffic going out to my server...the other traffic on 8080 etc is for another system.