Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

How to figure out what is blocking specific traffic.

I am a new user to Sophos XG but have experience with other routing equipment, primarily SonicWall. I apologize if this is lengthy, I just want to get all the information out.  I am attempting to figure out why specific traffic is getting blocked but the logs are proving to be useless.

I have a device on my network which is a HDHomerun Prime Tuner. Their software attempts to connect to it via my.hdhomerun.com from a PC on the local LAN. Using any other router, including Sophos UTM 9, I am able to see the device via this process, when using the XG it states that no device was detected. I can connect directly to the device using its IP but for their licensing practice it has to see it via the my.hdhomerun.com detection method.

I currently have IPS and Malware scanning disabled on the default lan to wan rule for testing this issue.

The logging shows nothing dropped, etc for the device IP. I attempted to do a packet capture but found no traffic going to that device IP.

Any suggestions on what to attempt next to get more info as to why something is getting blocked in this process?

Thanks in advance for any help!



This thread was automatically locked due to age.
Parents Reply Children
  • Thanks for the help. drop-packet-capture did not show anything. I did a tcpdump but can't really make much sense of it. I'll include the pcap file if you would be kind enough to take a look. IP 138 is my desktop which is making the request, IP 118 is the device itself, both attempt to connect to the same external IP during this process.  I did find on the device the only thing that shows in the log is "webclient error (http error 400)" which I can also see on one of the last lines in the pcap for 118: "400 BAD REQUEST"

    I'll attempt to contact the manufacturer tomorrow to see if they have any insight, but since it works with other firewalls I assume they are not going to be much help.

    Thanks again!

    Nick

    0285.tcpdump.zip

  • Nick,

    thanks for the pcap file. Send me a PM and I will have a look at your config.

    Regards