Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

new XG installs are causing ScreenConnect 'last connected' timer resets even though NO security services are enabled.

I have now set up two firewalls for two different clients who also use our screenconnect software on their machines for us to remotely connect for repair, diagnostics, etc. The screenconnect software on the client machine will regularly poll back to the screenconnect server (located in my office) to let the server know that it is available and online. This shows as a 'time connected' counter in the screenconnect dashboard. This has always been very stable, and has not been blocked or otherwise interfered with by any other firewall or security appliance. All clients that do not have sophos firewalls do not exhibit this behavior. However, the two XG (115 and 210) firewalls that I have installed in the last two days are causing that counter to reset every 5 minutes (I can see the activity in the screenconnect logs). Both firewalls are in gateway mode, directly connected to the ISP and have NO security services enabled yet. No AV, no IPS, No web filter...nothing. Just the default rule in the firewall that is put in place during the initial configuration wizard.

FYI, the client is set to relay out to the screenconnect server on port 80 and 443, so I don't understand why that would get reset every 5 minutes.



This thread was automatically locked due to age.
Parents
  • It looks like this thread kind of died out. I have some more information, hopefully it will be helpful. I recently installed an XG210 in my local network as an evaluation and training exercise. It is setup in bridge mode between my existing gateway router (a unifi security gateway pro 4) and my core switch (a unifi 48 port switch). I have a number of internal VLANs set up on the system, so the communication between vlans has to be routed through that gateway. I have two firewall rules set up in the XG right now. One from WAN to LAN, and one for LAN to WAN. Since the existing gaterway handles perimeter security and port forwarding, no additional rules are needed in the XG for now.

    I noticed something interesting. I have screenconnect on all of my internal machines. The screenconnect server is hosted inside our network as well, but on a separate VLAN along with a unifi controller. The internal machines are experiencing this same disconnect issue on a 5 minute cycle just as external client machines are. EXCEPT, the two servers on the same VLAN as the screenconnect server are NOT.

     

    The way traffic flows in this network is each vlan uses the USG as it's gateway, then there are firewall rules in the USG that allow inter-vlan traffic to flow. So traffic from let's say register1 travels to the USG through the XG in bridge mode, then back through the XG tagged on a different vlan to the screenconnect server. In that trip, the issue occurs. BUT, traffic from the UNIFI to the screenconnect server isn't effected, presumably becasue it is never going through the XG and just passing through the switch.

Reply
  • It looks like this thread kind of died out. I have some more information, hopefully it will be helpful. I recently installed an XG210 in my local network as an evaluation and training exercise. It is setup in bridge mode between my existing gateway router (a unifi security gateway pro 4) and my core switch (a unifi 48 port switch). I have a number of internal VLANs set up on the system, so the communication between vlans has to be routed through that gateway. I have two firewall rules set up in the XG right now. One from WAN to LAN, and one for LAN to WAN. Since the existing gaterway handles perimeter security and port forwarding, no additional rules are needed in the XG for now.

    I noticed something interesting. I have screenconnect on all of my internal machines. The screenconnect server is hosted inside our network as well, but on a separate VLAN along with a unifi controller. The internal machines are experiencing this same disconnect issue on a 5 minute cycle just as external client machines are. EXCEPT, the two servers on the same VLAN as the screenconnect server are NOT.

     

    The way traffic flows in this network is each vlan uses the USG as it's gateway, then there are firewall rules in the USG that allow inter-vlan traffic to flow. So traffic from let's say register1 travels to the USG through the XG in bridge mode, then back through the XG tagged on a different vlan to the screenconnect server. In that trip, the issue occurs. BUT, traffic from the UNIFI to the screenconnect server isn't effected, presumably becasue it is never going through the XG and just passing through the switch.

Children
No Data