Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Error code 502 quand le "web filtering" est actif

(Google translation to English below.)

Bonjour,

Lorsque j'active le "web filtering" dans l'UTM 9, quel que soit la policies associé (même no filtering) il y a certains sites qui ne se chargent plus avec Chrome, mais qui fonctionnent avec Internet Explorer. Sous chrome cela se fini avec un "connexion reset by peer" après 20 sec, alors que sans le web filtering cela fonctionne bien avec tous les navigateurs. (c'est répétable sur d'autres ordinateurs du domaine)

Dans le live log j'ai par exemple pour le site http://www.20min.ch/ro/ :

2017:06:25-22:42:23 sophaigle httpproxy[8241]:
id="0002"
severity="info"
sys="SecureWeb"
sub="http"
name="web request blocked"
action="block"
method="GET"
srcip="192.168.1.31"
dstip="107.154.117.172"
user=""
group=""
ad_domain=""
statuscode="502"
cached="0"
profile="REF_DefaultHTTPProfile (Default Web Filter Profile)"
filteraction="REF_DefaultHTTPCFFAction (Default content filter action)"
size="0"
request="0x1654a400"
url="http://www.20min.ch/ro/"
referer=""
error="Connection reset by peer"
authtime="0"
dnstime="14549"
cattime="105"
avscantime="0"
fullreqtime="120066833"
device="0"
auth="0"
ua="Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36"
exceptions=""

J'ai tenté plusieurs solutions trouvées sur le forum comme augmenté le délai "autentification timeout" ou de taper dans la console la commande pour activer le paramètre relay_invalid_traffic afin de laisser passer le trafic invalide.... comme proposé dans l'article : https://community.sophos.com/kb/en-us/123730

Ce Web filtering n'a jamais pu être activé par l'installateur de l'UTM qui na rien trouvé et a laissé ça en l'état....

Pour les paramètres, je suis en mode transparent, pas de paramètres particuliers.

Le réseau autorisé est le réseau interne.

Avez-vous déjà eu la cas ou est-ce que quelqu'un connait la commande relay_invalid_traffic pour l'UTM 9?

Mille mercis!

When I activate the "web filtering" in the UTM 9, whatever the associated policies (even no filtering) there are certain sites that no longer load with Chrome but that work with Internet Explorer. Under chrome this ends with a "connection reset by peer" after 20 sec, while without the web filtering it works well with all browsers. (This is repeatable on other computers in the domain)

In the live log I for example for the sitehttp://www.20min.ch/ro/ :

2017:06:25-22:42:23 sophaigle httpproxy[8241]:
id="0002"
severity="info"
sys="SecureWeb"
sub="http"
name="web request blocked"
action="block"
method="GET"
srcip="192.168.1.31"
dstip="107.154.117.172"
user=""
group=""
ad_domain=""
statuscode="502"
cached="0"
profile="REF_DefaultHTTPProfile (Default Web Filter Profile)"
filteraction="REF_DefaultHTTPCFFAction (Default content filter action)"
size="0"
request="0x1654a400"
url="http://www.20min.ch/ro/"
referer=""
error="Connection reset by peer"
authtime="0"
dnstime="14549"
cattime="105"
avscantime="0"
fullreqtime="120066833"
device="0"
auth="0"
ua="Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36"
exceptions=""

I tried several solutions found on the forum as increased the timeout "authentication timeout" or typing in the console command to activate the relay_invalid_traffic parameter in order to pass invalid traffic .... as proposed in the article: https://community.sophos.com/kb/en-us/123730

This Web filtering could never be activated by the installer of the UTM who found nothing and left it as is.

For settings, I'm in transparent mode, no special settings.

The authorized network is the internal network.

Have you ever had the case or does anyone know the relay_invalid_traffic command for UTM 9?

Many thanks!


This thread was automatically locked due to age.
Parents
  • Salut Nicolas et bienvenue dans la communauté de l'UTM !

    Dans la communauté, il me plait beaucoup de voir les gens poster dans leur langue natale au lieu d’utiliser Google Traduction pour poster en anglais.  Néanmoins, l’anglais est la lingua franca de nos jours et c’est pour ça que j’ai rajouté le résultat de Google Traduction à ton post.  Je ferai pareil pour la partie de mon réponse en français.

    Hi Nicolas and welcome to the UTM community!

    In the community, I like to see people post in their native language instead of using Google Translate to post in English. Nevertheless, English is the lingua franca of today and that's why I added Google Translate to your post. I will do the same for the part of my answer in French.  (Wow!  I did not touch a thing and Google made a perfect translation!)

    That KnowledgeBase article applies to the XG, not the UTM - did you mean to join and post in the XG forum?  If so, we'll need to signal an administrator to move your question to that part of the Community.

    To solve the 502 error problem in the UTM, the first thing to try is an Exception for anti-virus scanning for the site.  If that doesn't work, the only thing one can do in Transparent mode is to add a DNS Host definition for www.20min.ch to the Destination Skiplist on the 'Advanced' tab in 'Filtering Options".

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Thanks for the answer Bob!

    At First this post is not a google translation, just Im not fluent in English...

    I tried to deactivate the antivirus scanning in the Web Filter Profiles -> Filter Actions but the results are the same.

    I tried to deactivate the PUA for this filter action too.

    The skip Transparent Mode Destination Hosts with the DNS hosts of www.20min.ch works, but this site is just an exemple, the blockage occur with bluewin.ch too and certainly many others.

    (url="http://su.ff.avast.com is blocked...) did you have a solution for every case, or must I read the Web Filtering live log to add every DNS?

    Thanks a lot

     

    --> That KnowledgeBase article applies to the XG, not the UTM - did you mean to join and post in the XG forum?  If so, we'll need to signal an administrator to move your question to that part of the Community.

    When I create the post I didnt find the category UTM 9.

  • I've tried these from here and have no problems with these sites.  For example from almost an hour ago:

    2017:06:29-15:13:34 secure httpproxy[1230]: id="0001" severity="info" sys="SecureWeb" sub="http" name="http access" action="pass" method="GET" srcip="172.17.1.65" dstip="107.154.108.172" user="" group="" ad_domain="" statuscode="200" cached="0" profile="REF_DefaultHTTPProfile (Default Web Filter Profile)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="0" request="0x95655000" url="http://www.20min.ch/_Incapsula_Resource?SWJIYLWA=2977d8d74f63d7f8fedbea018b7a1d05&ns=34" referer="http://www.20min.ch/leserreporter/upload_image_ro.html" error="" authtime="0" dnstime="1" cattime="96800" avscantime="22405148" fullreqtime="22637604" device="0" auth="0" ua="Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko" exceptions="" category="134" reputation="neutral" categoryname="General News" sandbox="-" content-type="application/javascript"

    I'm confused as to why you're having these problems.  Do you have a paid license, or is this a free home-use situation?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • I've tried these from here and have no problems with these sites.  For example from almost an hour ago:

    2017:06:29-15:13:34 secure httpproxy[1230]: id="0001" severity="info" sys="SecureWeb" sub="http" name="http access" action="pass" method="GET" srcip="172.17.1.65" dstip="107.154.108.172" user="" group="" ad_domain="" statuscode="200" cached="0" profile="REF_DefaultHTTPProfile (Default Web Filter Profile)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="0" request="0x95655000" url="http://www.20min.ch/_Incapsula_Resource?SWJIYLWA=2977d8d74f63d7f8fedbea018b7a1d05&ns=34" referer="http://www.20min.ch/leserreporter/upload_image_ro.html" error="" authtime="0" dnstime="1" cattime="96800" avscantime="22405148" fullreqtime="22637604" device="0" auth="0" ua="Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko" exceptions="" category="134" reputation="neutral" categoryname="General News" sandbox="-" content-type="application/javascript"

    I'm confused as to why you're having these problems.  Do you have a paid license, or is this a free home-use situation?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
No Data