Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Intrusion Prevention Blocked Office 365 Attachments

Hi,

 

We have had our new XG310 in for about a week now, it has mostly been going ok.

Just today though, outgoing attachments from Outlook all of a sudden stopped sending. (Stayed in Outbox)

I found that all of sudden, IPS was blocking traffic to Office 365.

I removed IPS from the firewall rule and that fixed it... but obviously not ideal.

 

See screenshots, any idea why this might have happened?

We had a similar scenario with our VoIP system, IPS just decided one day that the traffic was no good and blocked it!

Thanks,

Matt



This thread was automatically locked due to age.
Parents
  •  Hey Matt,

     

    I had a client just encountered the same problem and I managed to fixed it by creating a new IPS policy allowing ALL packets instead of using the Sophos' default policy.

     

    I just checked IPS signature has been updated last night.

    Also my client's XG330 is still running on v16.05.01 with trail license but has been expired for 2 weeks. I originally suspected the issue is due to expired IPS module not functioning correctly but now I see your thread I am suspecting the latest IPS signatures are messing things up.

    Has your issue been fixed yet? How did you do it?

    po  

  • Hi Po,

    Glad I'm not the only one - The IPS signature was updated early this morning.

    Really weird that we got the issue in the middle of the day.

     

    I haven't resolved it, I just changed IPS to None on our firewall rule until I can get to the bottom of it.

    I will follow your suggestion and create a new IPS policy and update this thread if I find out anything more.

     

    Thanks,

    Matt

  • FormerMember
    0 FormerMember in reply to Matthew Trigg

    Hi,

    I think that Outlook uses a Untrusted certificate, so Sophos blocks.

    Its wreid, but it's the only way that sounds possible for me.

    Regards

  • Hi,

    same thing here, Cyberoam Firmware and Sophos Firmware appliances are dropping  

    connections to Exchange Online with the IPS signature: "SERVER-WEBAPP SSLv2 OpenSSl KEY_ARG buffer overflow attempt".

    Does anyone reported this issue to Sophos?

    Regards

Reply Children