This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Unable to SSH to any server. Even FTP/SFTP does not work.

Hi all,

I've recently installed Sophos utm9 in my home lab, and these are my very first few weeks. 
I have been facing a very strange issue lately.. and hence i need your help with this.

Two days back, i was trying to transfer files from a remote server using sftp connection through filezilla, and the entire file transfer was choppy, the connection would keep disconnecting every few seconds, and then resume transfer, this went on for couple of mins, the connecrtion would terminate and then reconnect again, and transfer would resume, but after few mins, the connection completely got disconnected, and since them i am not able to ssh to that server using putty nor through filezilla (ftp client).

The remote server is online, and i have tried connecting to this server from work (a different location from home), and it works fine from home, i can file transfer without any issues.

Its only here at home where i have sophos installed.

Prior to sohos i was able to file transfer and connect to the server without issues. 

Is there something that is completely blocking the ssh connection to a remote server or even file transfer in the firewall that i need to check or enable or create a rule?



This thread was automatically locked due to age.
Parents
  • To add on to my woes, even speed test is not working any more.

    It shows..

    The speed test starts and the counter goes upto 350 mb/sec, and then gradually starts returning back to zero and subsequently shows this error message.

  • Researched a bit here on the forum, and created a rule, its working now, but i dont like the sound of this rule. Looks like enabling this rule is providing me bare minimum protection.

    Got to Network Protection -> Firewall.

    Network Object "Internal (Network)" into the Source field (drag & drop) and "Any" into Destination.
    Service Definition "Any" into the Service field.

    Although now i can ssh and ftp to a remote site, can i just restrict this to one single ip? Or is there a better alternative and more secure option to this?

  • Update..

    Although I can now connect to the remote server using ssh over putty... i am still unable to download flawlessly over ftp.

    The entire internet on the network disconnects, the connection is intermittent and keeps disconnecting every few seconds, and then reconnects.

    Every equipment over the network disconnects from the internet, and then reconnects, its like the firewall is choking the internet connection.

Reply
  • Update..

    Although I can now connect to the remote server using ssh over putty... i am still unable to download flawlessly over ftp.

    The entire internet on the network disconnects, the connection is intermittent and keeps disconnecting every few seconds, and then reconnects.

    Every equipment over the network disconnects from the internet, and then reconnects, its like the firewall is choking the internet connection.

Children
  • Its pretty depressing with this product and with this forum, no one wants to help a new comer/user.

    i've had some luck with disabling IPS (been reading around with pain, trying to find self solution), and now the connection doesnt fail that often while downloading large files, but still its not stable. The packets/network does dropped and i loose connectivity network-wide and the connection resumes within few seconds. Although while transfering 300GB of data last night, the internet choked, and i had to reboot the firewall server and then connection to internet was restored.

  • Here's the latest update on my issue. I am still struggling with the internet connectivity issue while downloading large files, both over sftp or torrents, or even on IDM. The internet disconnects, throttles, chokes and then i have to reboot the firewall server for the internet to reconnect again.

     

    I have disabled IPS and my utorrent download seems to work for longer durations as compared to the time when utorrent download will choke the sophos firewall and disconnect me completely from the internet. After restarting the sophos server the internet would resume.

    However now after disabling the IPS the internet seems to work for an hour or two while utorrent is downloading.. and an hour or two later the earlier symptoms returns.

    I have used this utorrent guide and also enabled a rule under IPS Exceptions.. see below.

    1. Create the Definition for the computer running uTorrent

    Definition and Users -> Network Definitions -> New Network Definition ->

    Name: uTorrent host (or whatever you want to call your seedbox)
    Type: Host
    Interface: Any
    IPv4 Adress: 192.168.10.100 (or whatverver LAN address your seedbox has)
    Comment: Whatever you want


    2. Create the Service Definition

    Definition and Users -> Service Definitions -> New Service Definition ->

    Name: uTorrent
    Type of Definition: TCP/UDP
    Destination port: 55555 (or whatver port you have set in uTorrent)
    Source port 1:65535
    Comment: Whatever

    3. Create NAT Rule

    Network Security -> NAT -> DNAT/SNAT -> New NAT rule

    Traffic Source: Any
    Traffic Service: uTorrent
    Traffic Destination: External (WAN) Network - (I dont really understand why it shouldn´t be Any to Internal......but it must be External)
    Nat Mode: DNAT
    Destination: uTorrent Host (the host definition created under p. 1 above)
    Destination Service: uTorrent (the service definition created under p. 2 above)
    Automatic Firewall rule: On

    Turn it on, i.e. press the red/green switch

    4. Create the outbound firewall rule

    Firewall -> New Rule

    Source: uTorrent Host
    Service: Any
    Destination: Any

    Turn it on, i.e. press the red/green switch

    This will open all outbound communication from the uTorrent host

    5. Create the inbound firewall rule

    Firewall -> New Rule

    Source: Any
    Service: uTorrent
    Destination: uTorrent Host

     

    I have also enabled the IPS Exception as seen here...

     

    However please note, I've disabled IPS.. I'd like to keep IPS enabled, but without downloading choking and then disconnecting from the internet. Only by disabling the IPS, i am able to download for 1-2 hours before internet again chokes and goes down, thus having me to reboot the firewalls server.

    Here is my Hardware details.

    The time when i see the highest speed at which the downloads occuring, the interface looks like this...

    I hope something is not wrong with my network switch settings.. ? :(

    I've read the rulz page, and got some info from there, and have been scavenging around since then. Looks like none here ever got into this issue.. why is my download choking causing the internet to disconnect and the have to reboot the firewall for the internet to work again? :(

    This behaviour is not only wiht torrents, but even while downloading through a ftp client, while downloading using sftp connection. The session keeps getting terminated intermittently many times, and then finally disconnecting me from the internet, and then having to restart the firewall server for internet to work again.

    Uploading the logs, both live and real time.

    For download links for logs see at the end of this post.


    Live Log: Firewall
    Filter:
    Autoscroll
    Reload
    18:35:31 Default DROP UDP
    192.168.1.110 : 56385

    97.127.86.33 : 123

    len=76 ttl=62 tos=0x00 srcmac=2c:56:dc:57:4e:f0 dstmac=00:25:90:7c:01:af
    18:35:32 Default DROP TCP
    192.168.1.100 : 51222

    65.19.129.167 : 232

    [SYN] len=52 ttl=63 tos=0x00 srcmac=00:0e:8f:79:e3:21 dstmac=00:25:90:7c:01:af
    18:35:35 Default DROP TCP
    93.125.74.199 : 54849

    xx.xxx.xx.xx : 61144

    [SYN] len=60 ttl=43 tos=0x10 srcmac=00:01:5c:6a:ac:46 dstmac=00:25:90:7c:01:ae
    18:35:36 Default DROP UDP
    192.168.1.110 : 56385

    216.218.254.202 : 123

    len=76 ttl=62 tos=0x00 srcmac=2c:56:dc:57:4e:f0 dstmac=00:25:90:7c:01:af
    18:35:39 Default DROP TCP
    192.168.1.100 : 54013

    64.71.178.199 : 232

    [SYN] len=52 ttl=63 tos=0x00 srcmac=00:0e:8f:79:e3:21 dstmac=00:25:90:7c:01:af
    18:35:39 Default DROP UDP
    192.168.1.116 : 38164

    91.189.91.157 : 123

    len=76 ttl=63 tos=0x10 srcmac=00:0c:29:ab:6a:88 dstmac=00:25:90:7c:01:af
    18:35:41 Default DROP UDP
    192.168.1.110 : 56385

    74.82.59.150 : 123

    len=76 ttl=62 tos=0x00 srcmac=2c:56:dc:57:4e:f0 dstmac=00:25:90:7c:01:af
    18:35:42 Default DROP TCP
    192.168.1.100 : 54013

    64.71.178.199 : 232

    [SYN] len=52 ttl=63 tos=0x00 srcmac=00:0e:8f:79:e3:21 dstmac=00:25:90:7c:01:af
    18:35:42 Default DROP TCP
    93.125.74.199 : 54849

    xx.xxx.xx.xx : 61144

    [SYN] len=60 ttl=43 tos=0x10 srcmac=00:01:5c:6a:ac:46 dstmac=00:25:90:7c:01:ae
    18:35:42 Default DROP TCP
    185.33.236.121 : 35495

    xx.xxx.xx.xx : 61144

    [SYN] len=60 ttl=47 tos=0x10 srcmac=00:01:5c:6a:ac:46 dstmac=00:25:90:7c:01:ae
    18:35:46 Default DROP TCP
    185.33.236.121 : 35495

    xx.xxx.xx.xx : 61144

    [SYN] len=60 ttl=47 tos=0x10 srcmac=00:01:5c:6a:ac:46 dstmac=00:25:90:7c:01:ae
    18:35:46 Default DROP UDP
    192.168.1.110 : 56385

    66.7.96.1 : 123

    len=76 ttl=62 tos=0x00 srcmac=2c:56:dc:57:4e:f0 dstmac=00:25:90:7c:01:af
    18:35:50 Default DROP TCP
    192.168.1.100 : 54014

    64.71.178.199 : 232

    [SYN] len=52 ttl=63 tos=0x00 srcmac=00:0e:8f:79:e3:21 dstmac=00:25:90:7c:01:af
    18:35:50 Default DROP ICMP
    192.168.1.110

    8.8.8.8

    len=84 ttl=62 tos=0x00 srcmac=2c:56:dc:57:4e:f0 dstmac=00:25:90:7c:01:af
    18:35:50 Default DROP UDP
    192.168.1.116 : 48597

    91.189.89.199 : 123

    len=76 ttl=63 tos=0x10 srcmac=00:0c:29:ab:6a:88 dstmac=00:25:90:7c:01:af
    18:35:51 Default DROP ICMP
    192.168.1.110

    8.8.8.8

    len=84 ttl=62 tos=0x00 srcmac=2c:56:dc:57:4e:f0 dstmac=00:25:90:7c:01:af
    18:35:52 Default DROP ICMP
    192.168.1.110

    8.8.8.8

    len=84 ttl=62 tos=0x00 srcmac=2c:56:dc:57:4e:f0 dstmac=00:25:90:7c:01:af
    18:35:52 Default DROP TCP
    185.33.236.121 : 35495

    xx.xxx.xx.xx : 61144

    [SYN] len=60 ttl=47 tos=0x10 srcmac=00:01:5c:6a:ac:46 dstmac=00:25:90:7c:01:ae
    18:35:52 Default DROP UDP
    192.168.1.110 : 37424

    216.218.254.202 : 123

    len=76 ttl=62 tos=0x00 srcmac=2c:56:dc:57:4e:f0 dstmac=00:25:90:7c:01:af
    18:35:52 Default DROP TCP
    192.168.1.100 : 54014

    64.71.178.199 : 232

    [SYN] len=52 ttl=63 tos=0x00 srcmac=00:0e:8f:79:e3:21 dstmac=00:25:90:7c:01:af
    18:35:53 Default DROP ICMP
    192.168.1.110

    8.8.8.8

    len=84 ttl=62 tos=0x00 srcmac=2c:56:dc:57:4e:f0 dstmac=00:25:90:7c:01:af
    18:35:53 Default DROP DNS
    14.1.112.12 : 53

    xx.xxx.xx.xx : 59072

    len=73 ttl=113 tos=0x10 srcmac=00:01:5c:6a:ac:46 dstmac=00:25:90:7c:01:ae
    18:35:53 Default DROP ICMP
    192.168.1.110

    8.8.8.8

    len=84 ttl=62 tos=0x00 srcmac=2c:56:dc:57:4e:f0 dstmac=00:25:90:7c:01:af
    18:35:54 Default DROP UDP
    192.168.1.110 : 47659

    23.23.78.13 : 33434

    len=187 ttl=62 tos=0x00 srcmac=2c:56:dc:57:4e:f0 dstmac=00:25:90:7c:01:af
    18:35:54 Default DROP ICMP
    192.168.1.110

    8.8.8.8

    len=84 ttl=62 tos=0x00 srcmac=2c:56:dc:57:4e:f0 dstmac=00:25:90:7c:01:af
    18:35:56 Default DROP ICMP
    192.168.1.110

    8.8.8.8

    len=84 ttl=62 tos=0x00 srcmac=2c:56:dc:57:4e:f0 dstmac=00:25:90:7c:01:af
    18:35:57 Default DROP ICMP
    192.168.1.110

    8.8.8.8

    len=84 ttl=62 tos=0x00 srcmac=2c:56:dc:57:4e:f0 dstmac=00:25:90:7c:01:af
    18:35:57 Default DROP UDP
    192.168.1.110 : 37424

    204.2.134.162 : 123

    len=76 ttl=62 tos=0x00 srcmac=2c:56:dc:57:4e:f0 dstmac=00:25:90:7c:01:af
    18:35:57 Default DROP ICMP
    192.168.1.110

    8.8.8.8

    len=84 ttl=62 tos=0x00 srcmac=2c:56:dc:57:4e:f0 dstmac=00:25:90:7c:01:af
    18:35:59 Default DROP ICMP
    192.168.1.110

    8.8.8.8

    len=84 ttl=62 tos=0x00 srcmac=2c:56:dc:57:4e:f0 dstmac=00:25:90:7c:01:af
    18:36:00 Default DROP TCP
    192.168.1.100 : 54016

    64.71.178.199 : 232

    [SYN] len=52 ttl=63 tos=0x00 srcmac=00:0e:8f:79:e3:21 dstmac=00:25:90:7c:01:af
    18:36:00 Default DROP UDP
    192.168.1.116 : 47708

    91.189.89.198 : 123

    len=76 ttl=63 tos=0x10 srcmac=00:0c:29:ab:6a:88 dstmac=00:25:90:7c:01:af
    18:36:02 Default DROP UDP
    192.168.1.110 : 37424

    74.82.59.150 : 123

    len=76 ttl=62 tos=0x00 srcmac=2c:56:dc:57:4e:f0 dstmac=00:25:90:7c:01:af
    18:36:02 Default DROP TCP
    192.168.1.100 : 54016

    64.71.178.199 : 232

    [SYN] len=52 ttl=63 tos=0x00 srcmac=00:0e:8f:79:e3:21 dstmac=00:25:90:7c:01:af
    18:36:04 Default DROP TCP
    185.33.236.121 : 35495

    xx.xxx.xx.xx : 61144

    [SYN] len=60 ttl=47 tos=0x10 srcmac=00:01:5c:6a:ac:46 dstmac=00:25:90:7c:01:ae

     

    Link for the logs.

    https://www.dropbox.com/s/r3njm831wfx5isv/logs.txt?dl=0

    P.S. I have masked my IP address to xx.xxx.xxx.xx