Quantcast
Channel: Sophos User Bulletin Board
Viewing all 14361 articles
Browse latest View live

Out of Office

$
0
0
Using "out of office" option in my webmail
UTM marks this messages as SPAM

Exchange 2013 mailflow

$
0
0
Greetings,

I am having trouble getting external email flowing. I can send email internal but email sent external from owa/outlook goes to the sent folder and nothing is received nor do I receive bounce backs.

Exchange is setup to use the UTM as a smarthost and the UTM is set to send it through my ISP.

I have gone through http://www.astaro.org/gateway-produc...how-setup.html and still receive the above.

Any ideas?

Transparent Web Proxy and Playstation 3 Updating

$
0
0
I made a report to Sony in their forum; they didn't respond however:

Playstation 3 Download Bug (Playstation Store Upda... - PlayStation® Community Forums

I was the only one who replied, however, I encountered this strange bug when downloading updates for the Playstation 3. I made two videos. The first one showed the end of the issue:

Playstation 3: Download Past 100 Percent Bug - YouTube

The second one I captured during the download of Mortal Kombat updates:

Playstation 3 Bug: Mortal Kombat Network Update - YouTube

I disabled the Transparent Proxy and the system applied the updates.

I'm using firmware version 9.100-8 of Sophos UTM 9. The downloads will run past 100 percent for some reason.

Transparent vs. Standard Proxy - Recommendation

$
0
0
I am new to Sophos UTM, evaluating the Home Edition for my family after having used Endian UTM for a few years. One thing I'm trying to wrap my head around is Transparent vs. Standard for the web proxy. I've been through quite a few posts on the board and just want to make sure I am making the right choice.

My primary reason for putting in a UTM device a few years ago was for smart devices and players (smartphones, tablets, blu-ray players, etc.), so that I could generally provide more control over what those devices could do on our home network. Filtering of course is one part of that. Having said that, Transparent mode seems like the best choice (and what I've been using with Endian).

My understanding (if correct) is that one of the key downsides to Transparent mode is that only HTTP traffic is handled. So HTTPS, FTP, and other ports would (1) have to be opened via the firewall to even get out, and (2) not be filtered. The one exception of course would be ticking the HTTPS scanning checkbox, but from other posts in this forum that seems to be problematic at best. I'm okay with opening ports when needed, but how concerned should I be about the filtering? My initial thought is not really that concerned.

The problem with Standard mode for me is at least two-fold: (1) smart devices (I have no idea how to properly manage those in that case), and (2) forcing the proxy settings on standard computers (we have OS X and Windows 7 and 8). I could install a domain controller and force settings on the Windows boxes via Group Policy, but that seems overkill and doesn't help with OS X which gets a little trickier.

So, my stance right now is Transparent mode. Is my understanding and thought process off base? Any other recommendations or concerns?

Any help is much appreciated!

SSL VPN DNS issue

$
0
0
Hi,

Here is the issue:

Windows 7 64bit with SSL VPN client. For some reasons, 1-2 computers can't get the DNS solved, still use the external DNS or the DNS assigned in SSL-VPN.

Everytime I need manually assign the internl DNS before connecting VPN client.

Not all the computers have this issue, most users work fine.

All the users have Admin rights.

how to fix this problem?

Thanks,

License Expiry Notification >14 days?

$
0
0
Is it possible to set this to an earlier warning?

At my office it can take up to a month to purchase things with a high price tag such as this. I was wondering if there was a way to have the Sophos UTM warn me 30 days or more ahead of time?

I know I can set a reminder elsewhere like in my mail or calendar, but I would trust my UTM to send me an email over anything else.

Just a thought!

Thanks!

Reporting - One eMail address but multiple entries in DB

$
0
0
Hello,

when I look in my Executive Reports at the TOP10 eMail reciepients or in the WebAdmin reporting section, there's one email address at multiple positions:






So for example if you get mails to one address but with different formats, like:

TO:john.doe@domain.tld
TO:John Doe <john.doe@domain.tld>
TO:"john.doe@domain.tld" <john.doe@domain.tld>

they will be handled as three different email addresses and not as one.


Just my 2c,
Dino

Attached Images
File Type: gif astaro_ex_rep_email.gif (21.5 KB)
File Type: gif astaro_ex_rep_email2.gif (37.1 KB)

Proxy Profiles match not as intended

$
0
0
Hi Folks,

I am writing this a second time since I got logged out while writing my first attempt which then got "lost" when I wanted to preview it. :mad: so this is my second try (stripped version, less bla):

I have a brandnew UTM for my home network. I am highly interested in the Proxy Profile feature since I have a little brother (nine years) with his own laptop (Windows 7, own profile/password). I don't have any directory services in my network, so i have local users on the UTM. I want to get rid of the FireFoxPlugin Pro Con Latte which until now handled URL Filtering for my brother.

A short description of what I wanted to accomplish:
"minor" users have to use a profile with strict URL-filtering. grown up users have a less strict profile. Authentication for known users is done via SAA since no directory server is available. Guest users cannot authenticate and should have an even stricter profile with advanced virusscanning.

Here's what I setup, I hope this is comprehensible:
- UTM version 9.006
- I've created two user groups "minors" (including my little brother) and "grown ups" including me
- I've distributed the SAA to the clients, auth seems to be working fine according to the log
- I've put very strict settings into the main web proxy, since I want this to be the fallback for guests (default filter action)
- I've setup two filter actions:
-- "grown ups" (less strict, no URL blocking)
-- "minors" (very strict, lots of blocking)
- I've created two new filter assignments
-- "grown ups, less strict" with the corresponding users and filter actions
-- "minors, very strict" with the corresponding users and filter actions
- I've setup two proxy profiles (in that order):
-- Position 1. "LAN guest proxy": Source: Internal Network, no filter assignments, fallback is default filter action, OP Mode transparent, no authentication
-- Position 2. "LAN SAA-authenticated proxy": Source: Internal Network, filter assignments 1. "minors" 2. "grown ups", fallback is default filter action, OP Mode transparent, authentication via agent (hence the first proxy, since unauthed users (guests) would have gotten a blocked content info, is this a correct approach?)

The problem I'm expriecing: Every client, authed or unauthed seems to apply the fallback action with the strictest proxy (the main proxy). It doesn't seem as if my filter assignments match. AFAIK the UTM applies rules by first match and exits. I think this is some sort of "wrong order" matter. Maybe you have an eye for that and can point me to the right direction or even find the flaw I've built into the setup.

Any help is highly appreciated and also thank you for reading and taking your time for my issue. If you need additional info like screenshots or logfiles, please let me know.

Best regards
smueff

[9.100][BUG]wireless protection - cosmetic

$
0
0
In the wireless tab - 2 APs with 6 clients and 0 wireless networks. Connections by magic?

Ian:):):)

Attached Images
File Type: jpg wireless.jpg (14.5 KB)

Web Filtering causes distorted, overlapping HTTP elements

$
0
0
ASG220 FW: 8.309
Web Filter Global: Std. Mode, AD SSO, AD Users Allowed
Default URL Filter: Allow, no categories blocked, safe search on.

Though we're not aware of recent rule changes on the ASG220, our client recently noticed that Website Design and Hosting | Domains | Website Builder | NetworkSolutions.com page display is distorted, with many HTTP elements overlapping.

Using the same browser, HTTPS://www.networksolutions.com displays normally.

I added "networksolutions.com" to an existing Exceptions rule that skips Caching/URL Filtering/SSL Scanning. This immediately blocked ALL HTTP traffic. I removed "networksolutions.com" from the exception list and had to reboot the Astaro, before HTTP traffic was restored.

Any ideas what would suddenly cause the web filtering to distort this one particular URL, and why adding the URL to an existing exclusion rule would block HTTP to all URLs?

Thanks for any assistance

JimM

Attached Images
File Type: jpg http-networksolutions.jpg (37.0 KB)
File Type: jpg webfilterExclusion.jpg (30.8 KB)

Unable to access one UTM from another.

$
0
0
I have UTM9 set up at my office, and now at my home. Mostly everything seems to be working OK, but I have a strange issue. First, I don't have any VPN's set up between the two sites.
If I try to access a web camera, or even the UTM9 management interface, located at my office, from my home network, it either fails, or sometimes works sporadically. If I access the office from my tablet with a cell connection, it works fine.

A few notes and weird symptoms that may or may not be relevant:
1) I just installed UTM9 at home. Everything pretty much seems to work, but I'm not 100% confident yet.
2) When I ran a test from Speedtest.net, Ping was usually extremely high, around 300ms, normally under 20ms.
3) I'm running UTM9 at home under ESXi 5 on an old Poweredge 1950. It's currently the only VM on the hardware, and the VM has 2GB RAM. There doesn't seem to be any swapping going on, and RAM is around 30% used.
4) Setting up Full NAT, so I could access local webservers and cameras locally, failed. I played with the settings, and found changing one parameter in the Full NAT config allowed it to work. This is likely a separate issue I'll ask about in another thread.
5) On my tablet, when I have Internet access, the Wifi icon turns blue. When it connects to the home network, it stays gray, even though I seem to have Internet access.


Any ideas?

FYI: DynDNS / dyn.com policy change

$
0
0
I received an email from dyn.com (aka dyndns.org et al); apparently they're going to free require users to manually login every month or they will expire accounts.

Quote:

Starting now, if you would like to maintain your free Dyn account, you must log into your account once a month. Failure to do so will result in expiration and loss of your hostname. This activity helps us eliminate hostnames that are no longer needed and/or dormant. Note that using an update client will no longer suffice for this monthly login.
(emphasis mine)

Barry

Snort Problem

$
0
0
Hallo ich habe ein Problem mit einer von meinen 3 Sophos Gateway Installationen und zwar wird bei der 24 Stunden Zwangstrennung Snort zwar neu gestartet aber irgendwie der alte Dienst nicht beendet das geht dann so lange bis der Kernel Snort von selber beendet weil nicht mehr genug Speicher vorhanden ist und dann wird Snort halt durch die Astaro Selbstüberwachung wieder neu gestartet und ich kriege eine Email hier mal der Kernel Log.Im übrigen ist mir aufgefallen das eine oder mehrere Warnungs Regeln fehlerhaft zu sein scheinen den der Speicherbedarf von Snort steigt um den Faktor 4 an während sich die Regelanzahl bloß verdoppelt.

Attached Files
File Type: txt kernel.txt (19.4 KB)

[9.100-16]where did this come from

$
0
0
One of my UTMs that was running the latest beta of 9.100-8 this morning downloaded 9.100-16, but I don't see any release notes in this forum. i will put the other one back on line tonight for it to update.

I have run the up2date package.

Ian

Access local webserver fails.

$
0
0
I have a local Apache webserver hosting multiple websites from one IP address. It's at 192.168.1.100. I'm not using WAF. I followed the directions below:


1) Click on Network Protection
2) Click on the NAT tab
3) Click on 'New NAT Rule'
4) Under 'Matching Condition', at 'Using Service:', click the trash can, then the Green Plus. In the Destination Port, enter 80. Click Save.
5) Under 'Matching Condition', at 'Going To', click the trash can, then the folder. Options show up on the left. click and hold on 'External (WAN) (Adddress)', and drag it to the empty space next to 'Going To'. Click Save.
6) Under 'Action', 'Change the destination to:', click the trash can, then the Green Plus. Leave everything default, and add 192.168.1.100 into the IPv4 Address box. Click Save
7) Under 'Action', 'And the service to:', click the trash can, then the Green Plus. Under Destination Port, enter 80.
8) Check the box 'Automatic Firewall Rule'.
9) If you want, fill in a description of the rule in 'Comment:'
10) Click Save
11) Under the Status column, make sure there is a green checkmark. If not, click on the grey circle next to the red X.

Then,

Network Protection, NAT, NAT tab
New NAT Rule
Rule Type: Full NAT (Source + Destination)
For traffic from: Internal (Network)
Using service: HTTP
Going to: External (WAN)(Address)
Change the destination to: 192.168.1.100
And the service to: HTTP
Change the source to: Internal (Address)
And the service to: HTTP
Keep unchecked 'Automatic Firewall Rule'
Save

When I go to http://www.mydomain.com, mydomain2.com, or mydomain3.com from the LAN, it times out, and does not access the webserver. Accessing any of these domain names outside my LAN works fine. Checking Apache's log, it appears that, instead of accessing www.mydomain.com, it is trying to access Apache's default webpage, which isn't configured. I also have a number of smaller web devices, such as IP cameras, and these all work fine. Also, this was a working configuration with pfsense.

Any ideas?

Pri\Standby Internet Connections

$
0
0
Client has a Comcast connection as primary as well as an older T1 they want utilized if the Comcast connection goes down.

I can just enable uplink balancing and then update packet filter\NAT for the uplink interface correct? Do I need to do anything with multipath rules?

I also noticed the T1 interface has a 192.158.5.2/32 IP which confuses me a bit.. I'd expect this to be a public address and why a 255.255.255.255 mask?

Thanks!

Manual up2date issue

$
0
0
One box (on the otherside of the country) got the download so I thought I would grab it for my test box. Downloaded u2d-sys-9.006005-100016.tgz.gpg and began the manual package upload.

Got to 99% and then then login prompt appeared inside the upload dialog box.

(restarted the box and tried all three browsers)


Have I got the wrong file?


Tom

v8.309 -> UTM9 220 Active/Passive HA Upgrade Process

$
0
0
I have been running UTM9 on several of our sites for several months now on our sites that are not running Active/Passive HA setups and they seem to be running well. I think we're ready to upgrade our 220 HA to UTM9.

What is the recommend process? Will the one-touch upgrade just run or is there a special dance we need to do to get it right?

I'm envisioning it being simple like this:
  • Trigger One-Touch Upgrade on HA Master
  • HA Master Updates and Reboots
  • HA Slave Fails Over While HA Master Boots
  • HA Slave Upgrades to UTM9 and Reboots, completing upgrade
  • HA Master becomes primary again during failover from HA Slave

It sounds good on paper, but my gut tells me that there is more to it. I have seen in some early threads from late 2012 where one of the units had to be shut down but I'm wondering if that is correct or if that's still needed.

If this was covered somewhere else and I missed it, please direct me where this is laid out.

Thanks in advance.

L2tp VPN Connection Problems

$
0
0
Hi there

I have the following problem

Access the external ip from the internal network is difficult.
For the internal network i added a Full Nat rule. Internal Clients can now connect to the own external ip. They get redirected to the server.

However Clients connected with vpn cant.

For Internal Clients the following rule is active:

Internal Network --> ANY --> External IP
Change Source Internal IP
Change Target Server IP

However i cant do this for VPN Clients

L2TP Pool --> Any --> External IP
Change Source Internal IP
Change Target Server IP

doesn't work

Please help me out. I am trying since days

utorrent - DHT & Port forwarding

$
0
0
I am a little unsure how to set up the firewall in relation to the DHT aspect of my utorrent machine.

First I did some New Nat Rules & Firerule walls specific to my TCP/UDP port for utorrent (38507).

utorrent began working (downloading) but then got the red bars through the download/seeding lines which indicates DHT is failing.

Checking the firewall log, it seemed utorrent was trying to use a few other ports than 38507.

As an interim workaround I have simply made a new firewall rule to allow all ports (outbound) to be open on my utorrent machine.

Which has made DHT come alive.

But would prefer if it could be a specific port/s, but as I dont have a great understanding of DHT, i'm not sure how this could be done.

Any feedback on this?
Viewing all 14361 articles
Browse latest View live