Guest User!

You are not Sophos Staff.

Internet stops working then comes up again

Hello,
I use astaro 8.201 free edition, the Internet works fine if I only use one thing at the same time, example surfing on the web.

But when 2 persons or if I use multiple Internet access programs (example Spotify, surfing, and running a game) at the same time the server stops working.

When this occurs I can ping IP addresses, but not access the ip address over HTTP. All DNS function stops working, for example i can ping 8.8.8.8 but not ping google.com. And other programs that doesn't rely on addresses (example spotify or skype) still works

Also, when this occurs I cant access my ASG server over HTTPS.

This is just some of the DNS proxy log when the problem occurs
2011:09:08-20:47:06 asgv8 named[5640]: unexpected RCODE (REFUSED) resolving '40.48.194.173.in-addr.arpa/PTR/IN': 216.239.36.10#53

2011:09:08-20:47:06 asgv8 named[5640]: unexpected RCODE (REFUSED) resolving '40.48.194.173.in-addr.arpa/PTR/IN': 216.239.32.10#53
2011:09:08-20:47:06 asgv8 named[5640]: unexpected RCODE (REFUSED) resolving '40.48.194.173.in-addr.arpa/PTR/IN': 216.239.34.10#53
2011:09:08-20:47:06 asgv8 named[5640]: unexpected RCODE (REFUSED) resolving '40.48.194.173.in-addr.arpa/PTR/IN': 216.239.38.10#53
2011:09:08-20:47:07 asgv8 named[5640]: unexpected RCODE (REFUSED) resolving '40.48.194.173.in-addr.arpa/PTR/IN': 216.239.32.10#53
2011:09:08-20:47:07 asgv8 named[5640]: unexpected RCODE (REFUSED) resolving '40.48.194.173.in-addr.arpa/PTR/IN': 216.239.34.10#53
2011:09:08-20:47:07 asgv8 named[5640]: unexpected RCODE (REFUSED) resolving '40.48.194.173.in-addr.arpa/PTR/IN': 216.239.36.10#53
2011:09:08-20:47:07 asgv8 named[5640]: unexpected RCODE (REFUSED) resolving '40.48.194.173.in-addr.arpa/PTR/IN': 216.239.38.10#53
2011:09:08-21:02:06 asgv8 named[5640]: unexpected RCODE (REFUSED) resolving '40.48.194.173.in-addr.arpa/PTR/IN': 216.239.32.10#53
2011:09:08-21:02:06 asgv8 named[5640]: unexpected RCODE (REFUSED) resolving '40.48.194.173.in-addr.arpa/PTR/IN': 216.239.36.10#53
2011:09:08-21:02:06 asgv8 named[5640]: unexpected RCODE (REFUSED) resolving '40.48.194.173.in-addr.arpa/PTR/IN': 216.239.34.10#53
2011:09:08-21:02:07 asgv8 named[5640]: unexpected RCODE (REFUSED) resolving '40.48.194.173.in-addr.arpa/PTR/IN': 216.239.38.10#53
2011:09:08-21:02:07 asgv8 named[5640]: unexpected RCODE (REFUSED) resolving '40.48.194.173.in-addr.arpa/PTR/IN': 216.239.36.10#53
2011:09:08-21:02:07 asgv8 named[5640]: unexpected RCODE (REFUSED) resolving '40.48.194.173.in-addr.arpa/PTR/IN': 216.239.34.10#53
2011:09:08-21:02:07 asgv8 named[5640]: unexpected RCODE (REFUSED) resolving '40.48.194.173.in-addr.arpa/PTR/IN': 216.239.32.10#53
2011:09:08-21:02:07 asgv8 named[5640]: unexpected RCODE (REFUSED) resolving '40.48.194.173.in-addr.arpa/PTR/IN': 216.239.38.10#53
2011:09:08-21:17:06 asgv8 named[5640]: unexpected RCODE (REFUSED) resolving '40.48.194.173.in-addr.arpa/PTR/IN': 216.239.32.10#53
2011:09:08-21:17:06 asgv8 named[5640]: unexpected RCODE (REFUSED) resolving '40.48.194.173.in-addr.arpa/PTR/IN': 216.239.34.10#53
2011:09:08-21:17:07 asgv8 named[5640]: unexpected RCODE (REFUSED) resolving '40.48.194.173.in-addr.arpa/PTR/IN': 216.239.38.10#53
2011:09:08-21:17:07 asgv8 named[5640]: unexpected RCODE (REFUSED) resolving '40.48.194.173.in-addr.arpa/PTR/IN': 216.239.36.10#53
2011:09:08-21:17:07 asgv8 named[5640]: unexpected RCODE (REFUSED) resolving '40.48.194.173.in-addr.arpa/PTR/IN': 216.239.32.10#53
2011:09:08-21:17:07 asgv8 named[5640]: unexpected RCODE (REFUSED) resolving '40.48.194.173.in-addr.arpa/PTR/IN': 216.239.34.10#53
2011:09:08-21:17:07 asgv8 named[5640]: unexpected RCODE (REFUSED) resolving '40.48.194.173.in-addr.arpa/PTR/IN': 216.239.36.10#53
2011:09:08-21:17:07 asgv8 named[5640]: unexpected RCODE (REFUSED) resolving '40.48.194.173.in-addr.arpa/PTR/IN': 216.239.38.10#53


Im sure its something wrong with the settings in the ASG8.2 server or something because I've tried to bypass the ASG8.2 and the problem doesn't remain without it.

What should I do ???
Parents
  • Hi, Holm, and welcome to the User BB!

    Just a guess...

    Check your SMTP log for 173.194.48.40 - I bet you find emails rejected for not having a valid RDNS entry.  If this is someone you want to receive emails from, you might want to add an exception for RDNS or suggest that they do a better job of managing their public DNS records at their ISP. [;)]

    The next time this happens, go to 'Support >> Advanced' to see what's using so much of the CPU.

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • Hi, Holm, and welcome to the User BB!

    Just a guess...

    Check your SMTP log for 173.194.48.40 - I bet you find emails rejected for not having a valid RDNS entry.  If this is someone you want to receive emails from, you might want to add an exception for RDNS or suggest that they do a better job of managing their public DNS records at their ISP. [;)]

    The next time this happens, go to 'Support >> Advanced' to see what's using so much of the CPU.

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
  • I cannot access the HTTPS to check when the problem occurs, however I checked it via SSH and there was no process taking up any significant amount of cpu.. I don't think the problem lies in the Hardware, maybe it can be fixed with rules??

    Because i cannot reproduce the problem (at least i haven't succeeded with it) when I use the rule ANY > ANY > ANY > ALLOW

    Heres some pictures with my settings.
    Ive also tried to use internal (network) instead of my own definition. But it has the same function and that didn't help.
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?