Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Google Chrome Behavior

Using Chrome Version 57.0.2987.133, I have a Netgear R7800, Youtube works fine, Facebook, The Weather Channel, Slickdeals, Pinterest all work fine. 

I put the UTM in-line with only firewall and IPS on and all of the above work sporadically. I do not see any denies in teh FW log. I see a LOT of ICMP traffic initially coming from mostly Google Ip's so I let the ICMP come all the way through and that helps but eventually (2-3 hours later) It starts failing again, ERR_DISCONNECT or TIMEOUT.

I followed the DNS best practice, and setup Windows 2012 inside with DNS and DHCP. I set the DNS to forward to UTM then out to OpenDNS. On the UTM unchecked the Use ISP DNS forwarders and removed the Local network in allowed networks.

 

Nearly everything else works flawlessly, I have 135mb download and 5 mb up, so speed loss, streaming Netflix, PSVue, Hulu, Amazon all work great. These web issues are the only problem. And it appears to be something Chrome or Google trying to talk to Chrome is doing, yes?  When these issues start to appear on Chrome another tell tale sign I see is If I go to Google.com, in the upper right corner no picture of me form my gogle profile nor the 9 squares to activate the google apps dropdown icon menu. On Firefox I can get to google and get my chance to login and once I do things deteriorate from there, youtube will come up, but not as me being logged into Google.  

My wifes Mac has none of these issues at anytime, only on Windows machines.

Is there something I am missing as far as a UTM setting?? I am not seeing any RST in the FW log, nor any denies (other than some Country & telnet, SSH denies I expect)

 

Thanks for any input or advice.

 

John



This thread was automatically locked due to age.
Parents
  • Hi, John, and welcome to the UTM Community!

    Does doing #1 in Rulz give you any hints?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • It helped me get to the point am I at now by revealing the large amounts of ICMP traffic that google relies on for their Chrome features. After adding a bunch of those rules I have been able to make most of the ChaosMonkey's go away :)  There was not much being denied other than ssh/telnet attempts. I have IPS on now, and Web filtering in transparent mode and HTTPS URL filtering only. This morning I connected the machine that it most happened on to a wired ethernet and ran flawlessly like that for about 4 hours, so I went to Dell and got their recommended drivers for my wireless NIC ,uninstalled the latest greatest, installed the Dell recommended. So far it has been without error.

Reply
  • It helped me get to the point am I at now by revealing the large amounts of ICMP traffic that google relies on for their Chrome features. After adding a bunch of those rules I have been able to make most of the ChaosMonkey's go away :)  There was not much being denied other than ssh/telnet attempts. I have IPS on now, and Web filtering in transparent mode and HTTPS URL filtering only. This morning I connected the machine that it most happened on to a wired ethernet and ran flawlessly like that for about 4 hours, so I went to Dell and got their recommended drivers for my wireless NIC ,uninstalled the latest greatest, installed the Dell recommended. So far it has been without error.

Children
No Data