Managing several Sophos UTMs and Sophos XGs both at work and at some home locations, dedicated to continuously improve IT-security and feeling well helping others with their IT-security challenges.
Sometimes I post some useful tips on my blog, see blog.pijnappels.eu/category/sophos/ for Sophos related posts.
Managing several Sophos UTMs and Sophos XGs both at work and at some home locations, dedicated to continuously improve IT-security and feeling well helping others with their IT-security challenges.
Sometimes I post some useful tips on my blog, see blog.pijnappels.eu/category/sophos/ for Sophos related posts.
Managing several Sophos UTMs and Sophos XGs both at work and at some home locations, dedicated to continuously improve IT-security and feeling well helping others with their IT-security challenges.
Sometimes I post some useful tips on my blog, see blog.pijnappels.eu/category/sophos/ for Sophos related posts.
Three things I see in your log:
1) You are using an endpoint, but the endpoint is not configured by the UTM (or at least EP Web Control is not on). Can you confirm this?
2) Three requests (at the same time) has a slow categorization lookup that timed out after 6 seconds. This is somewhat expected, everyone will get a couple every day because we dynamically bring servers up and down. It might just be a co-incidence but it may also be something to monitor. Bridge mode will make no difference.
3) You have several log lines like "Connection to KNMI - Koninklijk Nederlands Meteorologisch Instituut using IPv6 timed out, re-trying to connect using IPv4" and the corresponding request takes 60 seconds. Sometime about your non-bridged configuration does not like IPv6.
In summary:
You had (most likely) a bad IPv6 configuration in non-bridge mode.
You had what looks like SXL categorization timeouts. Can you run the following command, which will tell me how often you get these:
zgrep -c -E 'cattime="[0-9]{7}"' /var/log/http/2013/12/http*
utm:/root # zgrep -c -E 'cattime="[0-9]{7}"' /var/log/http/2013/12/http*
/var/log/http/2013/12/http-2013-12-02.log.gz:7
/var/log/http/2013/12/http-2013-12-03.log.gz:2
/var/log/http/2013/12/http-2013-12-04.log.gz:0
/var/log/http/2013/12/http-2013-12-05.log.gz:9
/var/log/http/2013/12/http-2013-12-06.log.gz:0
/var/log/http/2013/12/http-2013-12-07.log.gz:23
/var/log/http/2013/12/http-2013-12-08.log.gz:43
/var/log/http/2013/12/http-2013-12-09.log.gz:117
/var/log/http/2013/12/http-2013-12-10.log.gz:24
Finally, if you intend to be running an endpoint that is managed by the UTM including Web Control, something is not correct. The endpoint is not receiving web control configuration from the UTM.
Managing several Sophos UTMs and Sophos XGs both at work and at some home locations, dedicated to continuously improve IT-security and feeling well helping others with their IT-security challenges.
Sometimes I post some useful tips on my blog, see blog.pijnappels.eu/category/sophos/ for Sophos related posts.