Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos User Portal - Not Allowing External Networks/No Connection

Hi all,

I'm currently struggling to set-up the Sophos UTM 9 User Portal. It works fine on our internal wireless network (which acts as an external network), but when I try connecting to the user portal through my iPhone or computer at home, I receive a "this page cannot be displayed" error. It seems something is blocking it, even though the user portal has been set to accept any networks. Has anyone come across this before? How should I go about resolving this? 



This thread was automatically locked due to age.
Parents
  • select "allow all users" apply it and try again.

    greets

    zaphod
    ___________________________________________

    Home: Zotac CI321 (8GB RAM / 120GB SSD)  with latest Sophos UTM
    Work: 2 SG430 Cluster / many other models like SG105/SG115/SG135/SG135w/...

  • This doesn't work - I'm not even sure why it would as it's a connection issue and not a user issue anyway. 

  • please try the userportal with other browsers like firefox, chrome maybe on a pc to see if it is working.


    i know there are issues with different browers not working any more cause of securtiy (something with old lts unsupported.. )

    i just tried mine on my iphone (ios 9.x) and safari shows the userportal...

    greets

    zaphod
    ___________________________________________

    Home: Zotac CI321 (8GB RAM / 120GB SSD)  with latest Sophos UTM
    Work: 2 SG430 Cluster / many other models like SG105/SG115/SG135/SG135w/...

  • also check the basics:

    advanced / Network Settings.. check for right port (443) and right adresses for your environment

    greets

    zaphod
    ___________________________________________

    Home: Zotac CI321 (8GB RAM / 120GB SSD)  with latest Sophos UTM
    Work: 2 SG430 Cluster / many other models like SG105/SG115/SG135/SG135w/...

  • I'm currently checking this on my iPhone 6 running the latest OS and using Safari - still no joy :( It says: "Safari cannot open the page because the network connection was lost".

    I've tried using the external address - i.e. x.x.x.x:443 

    I've also changed the hostname of the portal and added a DNS record pointing to the external address of the Sophos UTM on our DNS server, but Safari then says it can't find the server "company.co.uk". I suspect that's a different issue, though. 

Reply
  • I'm currently checking this on my iPhone 6 running the latest OS and using Safari - still no joy :( It says: "Safari cannot open the page because the network connection was lost".

    I've tried using the external address - i.e. x.x.x.x:443 

    I've also changed the hostname of the portal and added a DNS record pointing to the external address of the Sophos UTM on our DNS server, but Safari then says it can't find the server "company.co.uk". I suspect that's a different issue, though. 

Children
  • seems your dns-record is not right configured.. not the internal dns the dns record in the internet that points to your external ip adress of the wan interface..

    checking is simple:


    open cmd on a windows pc. type nslookup   / type server 8.8.8.8   / type your domain

    so you can check if the google dns server can find right adress for your dns-name...

    greets

    zaphod
    ___________________________________________

    Home: Zotac CI321 (8GB RAM / 120GB SSD)  with latest Sophos UTM
    Work: 2 SG430 Cluster / many other models like SG105/SG115/SG135/SG135w/...

  • It can find 'companyname.co.uk', but when I try 'company-portal.companyname.co.uk', it can't find it. But that is using Google as a DNS server. 

    I thought the query would come into our DNS server and it would resolve it, as long as the address was 'company-portal.companyname.co.uk' (considering companyname.co.uk works outside). 

  • However, there does still seem to be something wrong on the Sophos configuration because it still doesn't work, even when using the external address (and therefore completely bypassing this DNS issue). 

  • need more detailed description to help..


    - show your config page from user portal.

    - have you any NATs configured?

    - search log files....

    greets

    zaphod
    ___________________________________________

    Home: Zotac CI321 (8GB RAM / 120GB SSD)  with latest Sophos UTM
    Work: 2 SG430 Cluster / many other models like SG105/SG115/SG135/SG135w/...

  • This is the config page from the user portal:

    The only NATs we have configured are for customer VPNs. 

    I can't see anything in the log files (although, to be honest, I'm not entirely sure what I'm looking for). 

  • do you have ssl-vpn running at same interface / port ?

    greets

    zaphod
    ___________________________________________

    Home: Zotac CI321 (8GB RAM / 120GB SSD)  with latest Sophos UTM
    Work: 2 SG430 Cluster / many other models like SG105/SG115/SG135/SG135w/...

  • Yes - same port. Should it not be? 

  • i recommend to run at differnet ports... or if you have more than 1 wan line bind ssl-vpn to one wan and user portal to the other...

    if you run different port you need to use the ports then in the urls for the portal... or for the ssl-vpn-configuration...

    greets

    zaphod
    ___________________________________________

    Home: Zotac CI321 (8GB RAM / 120GB SSD)  with latest Sophos UTM
    Work: 2 SG430 Cluster / many other models like SG105/SG115/SG135/SG135w/...

  • I've tried changing the ports to no avail. It's still the same on the internal network - whether I use port 443 (same as the SSL VPN) or a different one like 1066, I can access the user portal internally. However, when trying to access it externally, the page doesn't load at all, regardless of what ports I try. There seems to be something blocking the connection, but I'm not really that up to speed with networking so I'm not entirely sure. 

  • how do you test the external behaviour?

    is it a real external client?

    if its a windows os please check also if firewall is configured right (or just deactivate this buggy so called firewall)..


    its hard to support more cause i need logs...


    what type of wan connection you got? is it a modem.. another router?

    greets

    zaphod
    ___________________________________________

    Home: Zotac CI321 (8GB RAM / 120GB SSD)  with latest Sophos UTM
    Work: 2 SG430 Cluster / many other models like SG105/SG115/SG135/SG135w/...