This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

LAN->WAN Problem - DST Port 443

Traffic from LAN->WAN that seem a destination port of 443 seems to be dropped, this is affecting several devcies on the network, in particular one of CAD software and its ability to updatre and our Synology products trying to update as well. 

 

messageid="01001" log_type="Firewall" log_component="Invalid Traffic" log_subtype="Denied" status="Deny" con_duration="0" fw_rule_id="0" policy_type="0" user="" user_group="" web_policy_id="0" ips_policy_id="0" appfilter_policy_id="0" app_name="" app_risk="0" app_technology="" app_category="" in_interface="" out_interface="" src_mac="" src_ip="192.168.0.92" src_country="" dst_ip="13.33.164.250" dst_country="" protocol="TCP" src_port="49890" dst_port="443" packets_sent="0" packets_received="0" bytes_sent="0" bytes_received="0" src_trans_ip="" src_trans_port="0" dst_trans_ip="" dst_trans_port="0" src_zone_type="" src_zone="" dst_zone_type="" dst_zone="" con_direction="" con_id="" virt_con_id="" hb_status="No Heartbeat" message="Invalid TCP RST." appresolvedby="Signature"

 



This thread was automatically locked due to age.
Parents
  • Hi,

     

    I am also experiencing an issue with "Invalid TCP RST" with a specific device on my home network.

     

    In my case, this is a Nixplay digital frame. The Nixplay gets its images online, so we're not able to update it through the XG. It obviously works fine on other non-XG connections.

     

    2018-02-03 23:53:18Firewallmessageid="01001" log_type="Firewall" log_component="Invalid Traffic" log_subtype="Denied" status="Deny" con_duration="0" fw_rule_id="0" policy_type="0" user="" user_group="" web_policy_id="0" ips_policy_id="0" appfilter_policy_id="0" app_name="" app_risk="0" app_technology="" app_category="" in_interface="" out_interface="" src_mac="" src_ip="192.168.2.103" src_country="" dst_ip="52.39.143.80" dst_country="" protocol="TCP" src_port="47005" dst_port="443" packets_sent="0" packets_received="0" bytes_sent="0" bytes_received="0" src_trans_ip="" src_trans_port="0" dst_trans_ip="" dst_trans_port="0" src_zone_type="" src_zone="" dst_zone_type="" dst_zone="" con_direction="" con_id="" virt_con_id="" hb_status="No Heartbeat" message="Invalid TCP RST." appresolvedby="Signature"

     

    As a side note, I am responsible for running a couple of Sophos UTM firewalls at my business and am testing XG at home to see if it makes sense for us to move over. I am running the latest firmware (SFOS 17.0.5 MR-5).

     

    Thanks, Assi.

Reply
  • Hi,

     

    I am also experiencing an issue with "Invalid TCP RST" with a specific device on my home network.

     

    In my case, this is a Nixplay digital frame. The Nixplay gets its images online, so we're not able to update it through the XG. It obviously works fine on other non-XG connections.

     

    2018-02-03 23:53:18Firewallmessageid="01001" log_type="Firewall" log_component="Invalid Traffic" log_subtype="Denied" status="Deny" con_duration="0" fw_rule_id="0" policy_type="0" user="" user_group="" web_policy_id="0" ips_policy_id="0" appfilter_policy_id="0" app_name="" app_risk="0" app_technology="" app_category="" in_interface="" out_interface="" src_mac="" src_ip="192.168.2.103" src_country="" dst_ip="52.39.143.80" dst_country="" protocol="TCP" src_port="47005" dst_port="443" packets_sent="0" packets_received="0" bytes_sent="0" bytes_received="0" src_trans_ip="" src_trans_port="0" dst_trans_ip="" dst_trans_port="0" src_zone_type="" src_zone="" dst_zone_type="" dst_zone="" con_direction="" con_id="" virt_con_id="" hb_status="No Heartbeat" message="Invalid TCP RST." appresolvedby="Signature"

     

    As a side note, I am responsible for running a couple of Sophos UTM firewalls at my business and am testing XG at home to see if it makes sense for us to move over. I am running the latest firmware (SFOS 17.0.5 MR-5).

     

    Thanks, Assi.

Children