Quantcast
Channel: Sophos User Bulletin Board
Viewing all 14361 articles
Browse latest View live

Virtual image not in directory

$
0
0
Hello, I have just registered for the virtual image trial and found the directory listed is empty (except for a text file).
Is there any news when the image will be available?
url visited:Index of /UTM/v9/virtual_appliance/

RDP via (Android+iOS) application blocked by UTM

$
0
0
Hey All, thank you for the help thus far. I really appreciate it!

I am able to connect to the RDP server via RD Gateway using a Microsoft Client. The successful logs look as follows:
---------------------------------------------------------------------------------------------------------------

2014:06:10-06:51:12 utm reverseproxy: [Tue Jun 10 06:51:12.350196 2014] [url_hardening:error] [pid 10353:tid 3979213680] [client 14.14.14.14:49519] No signature found, URI: https://tech.wan.com.au/remoteDesktopGateway/
2014:06:10-06:51:12 utm reverseproxy: srcip="14.14.14.14" localip="11.11.11.11" size="284" user="-" host="14.14.14.14" method="RDG_OUT_DATA" statuscode="403" reason="url hardening" extra="No signature found" exceptions="-" time="342736" url="/remoteDesktopGateway/" server="tech.wan.com.au" referer="-" cookie="-" set-cookie="-"
2014:06:10-06:51:13 utm reverseproxy: srcip="14.14.14.14" localip="11.11.11.11" size="13" user="-" host="14.14.14.14" method="RPC_IN_DATA" statuscode="401" reason="-" extra="-" exceptions="SkipURLHardening" time="744980" url="/rpc/rpcproxy.dll" server="tech.wan.com.au" referer="-" cookie="-" set-cookie="-"
2014:06:10-06:51:13 utm reverseproxy: srcip="14.14.14.14" localip="11.11.11.11" size="13" user="-" host="14.14.14.14" method="RPC_OUT_DATA" statuscode="401" reason="-" extra="-" exceptions="SkipURLHardening" time="197524" url="/rpc/rpcproxy.dll" server="tech.wan.com.au" referer="-" cookie="-" set-cookie="-"

However I am unable to connect via the Microsoft RDP app on any other platform. The error log is as follows:
---------------------------------------------------------------------------------------------------------

2014:06:10-06:50:09 utm reverseproxy: [Tue Jun 10 06:50:09.655723 2014] [url_hardening:error] [pid 10353:tid 3995999088] [client 14.14.14.14:52726] URI prefix does not match, URI: https://tech.wan.com.au:443/rpc/rpcproxy.dll?localhost:3388
2014:06:10-06:50:09 utm reverseproxy: [Tue Jun 10 06:50:09.655746 2014] [url_hardening:error] [pid 10353:tid 3987606384] [client 14.14.14.14:52727] URI prefix does not match, URI: https://tech.wan.com.au:443/rpc/rpcproxy.dll?localhost:3388
2014:06:10-06:50:09 utm reverseproxy: srcip="14.14.14.14" localip="11.11.11.11" size="286" user="-" host="14.14.14.14" method="RPC_IN_DATA" statuscode="403" reason="url hardening" extra="URI prefix does not match" exceptions="-" time="3054527" url="/rpc/rpcproxy.dll" server="tech.wan.com.au" referer="-" cookie="-" set-cookie="-"
2014:06:10-06:50:09 utm reverseproxy: srcip="14.14.14.14" localip="11.11.11.11" size="286" user="-" host="14.14.14.14" method="RPC_OUT_DATA" statuscode="403" reason="url hardening" extra="URI prefix does not match" exceptions="-" time="3049346" url="/rpc/rpcproxy.dll" server="tech.wan.com.au" referer="-" cookie="-" set-cookie="-"

The things I have tried are as follows:
-----------------------------------------------------------------

1. Connecting directly to the server via the app and bypass the utm = working! (So issue is definitely the firewall and not the server or iis publishing...etc).

2. Adding the full uri to the url hardening list:
"https://tech.wan.com.au:443/rpc/rpcproxy.dll?localhost:3388" - I still get the same error.

3. Adding the partial uri to the url hardening list:
"/rpc/rpcproxy.dll?localhost:3388" - I still get the same error

More info about APT Advanced Threat Protection

$
0
0
Hi,
recently I was update to versin 9.2 and enable APT. I have some questions about.

In to field with name Network/Host Exceptions:
I was put all my internal networks it is correct ?

In to field with name Threat Exceptions:
I was put all my specified DNS Forwarders for example google and the others.

If APT detect some threat and I have set up action DROP it automatically drop whole connections from source to destination network ?

I need help with WAF UTM220 / 9.2

$
0
0
I need help with WAF UTM220 / 9.2

What I am trying to do:

External access Port 8444 to an internal Webserver Port 80
1. I have created a Firewall rule. Internet IPv4 > External Internet Address Port 8444

Firewall Log
Packet filter rule #8 TCP External public IP : 31896 → External Internet Address interface: 8444
Everthing seems OK

2. I have created a real Webserver with the internal IP
3. I have created a virtual Webserver
interface = internal
type= http
port= 8444
domain = extern.domain.tv
FW profile = None
Advanced = nothing

The WAF Log shows only this:
2014:06:10-10:34:36 Sophos_1 reverseproxy: [Tue Jun 10 10:34:36.000543 2014] [security2:notice] [pid 20126:tid 4147431104] ModSecurity: APR compiled version="1.4.6"; loaded version="1.4.6"
2014:06:10-10:34:36 Sophos_1 reverseproxy: [Tue Jun 10 10:34:36.000552 2014] [security2:notice] [pid 20126:tid 4147431104] ModSecurity: PCRE compiled version="7.8 "; loaded version="7.8 2008-09-05"
2014:06:10-10:34:36 Sophos_1 reverseproxy: [Tue Jun 10 10:34:36.000556 2014] [security2:notice] [pid 20126:tid 4147431104] ModSecurity: LIBXML compiled version="2.7.6"
2014:06:10-10:34:36 Sophos_1 reverseproxy: [Tue Jun 10 10:34:36.016350 2014] [core:warn] [pid 20126:tid 4147431104] AH00111: Config variable ${URLHardening_HTTP_Hostname} is not defined
2014:06:10-10:34:37 Sophos_1 reverseproxy: [Tue Jun 10 10:34:37.004189 2014] [mpm_worker:notice] [pid 20138:tid 4147431104] AH00292: Apache/2.4.4 (Unix) OpenSSL/1.0.1g configured -- resuming normal operations
2014:06:10-10:34:37 Sophos_1 reverseproxy: [Tue Jun 10 10:34:37.004850 2014] [core:notice] [pid 20138:tid 4147431104] AH00094: Command line: '/usr/apache/bin/httpd'
2014:06:10-10:49:49 Sophos_1 reverseproxy: srcip="127.0.0.1" localip="127.0.0.1" size="57" user="-" host="127.0.0.1" method="GET" statuscode="200" reason="-" extra="-" exceptions="-" time="708" url="/lb-status" server="localhost" referer="-" cookie="-" set-cookie="-"
2014:06:10-10:49:49 Sophos_1 reverseproxy: srcip="127.0.0.1" localip="127.0.0.1" size="57" user="-" host="127.0.0.1" method="GET" statuscode="200" reason="-" extra="-" exceptions="-" time="422" url="/lb-status" server="localhost" referer="-" cookie="-" set-cookie="-"
2014:06:10-11:19:36 Sophos_1 reverseproxy: srcip="127.0.0.1" localip="127.0.0.1" size="57" user="-" host="127.0.0.1" method="GET" statuscode="200" reason="-" extra="-" exceptions="-" time="420" url="/lb-status" server="localhost" referer="-" cookie="-" set-cookie="-"
2014:06:10-11:20:20 Sophos_1 reverseproxy: srcip="127.0.0.1" localip="127.0.0.1" size="57" user="-" host="127.0.0.1" method="GET" statuscode="200" reason="-" extra="-" exceptions="-" time="392" url="/lb-status" server="localhost" referer="-" cookie="-" set-cookie="-"

No incoming Traffic on the Webserver

Second try with DNAT.

1. I have created a DNAT Rule:
Traffic from: Internet IPv4
Service: Port 8444
Going to: Internet (External Address Interface)
Change Destination to: Internal Webserver IP
and Service to Port 80

Firewall Log:
NAT rule #4 TCP External Public IP:4246 → Internal Webserver:8444

With this solution I can see the incoming/ outgoing Traffic on the Webserver

Webserver Logs:
Internal Address: Httpd.exe – Internal Server IP Port 80
Remote Address – The external public IP: Port 4246

No Access from External, i do not know what i am doing wrong.

Restore SUM Configuration

$
0
0
I guess my question is not as much technical as it is procedural. After attempting to upgrade to 4.2, I keep getting a message that the UTM Manager is inactive and cannot login to the gateway manager.

No big deal, I thought. I started working with support on the issue, and did a clean install of 4.2 on another box. When I restored the config file from the original SUM, a lot of things were missing. Display names of the UTMs, site to site VPNs, definitions of hosts and services and active directory sync were all things that I have found so far that did not restore.

Has anyone else out there run into a situation like this? How do you work around it or configure the SUM and UTMs so that this is not an issue?

FTP-Proxy: Berechtigungen anhand einer MS AD-Sicherheitsgruppe?

$
0
0
Hallo,

kann ich ftp-Berechtigungen für den ftp-proxy anhand einer MS Active-Directory Gruppe setzen?

Also, alle Mitglieder der Sicherheitsgruppe FTP dürfen FTP Up/Downloads machen und alle anderen nicht?

Vielen Dank für die Hinweise

Leon

UTM Webprotection - Generelle Teamviewer Regel

$
0
0
Hallo,

ich würde gern Teamviewer immer erlauben, ohne das sich ein Benutzer authentifizieren muss. Wie kann ich das realisieren?

Gruesse

Leon

VPN durch FB 6360 Kabeldeutschland auf Astaro

$
0
0
Hallo,

ich bin seit einer Woche stolzer Zahler einer 100Mbit Leitung von Kabeldeutschland. Als Kabelmodem Habe ich dir Homebox 6360 dazu bekommen. Die Homebox ist über LAN1 an die WAN-Schnittstelle der Astaro
gekoppelt und die Schnittstelle auf "Kabelmodem(DHCP)" eingestellt. Läuft auch alles prima. Die Astaro hat von der Homebox die IP 192.168.178.22
bekommen und die 192.168.178.1 als Default GW. Sie routet den Internen Verkehr von Netz 192.168.2.X auch einwandfrei ins Internet.

IPsec-VPN Verbindungen mit dem Kaufclient aus meinem Netz auf unsere Astaro auf der Arbeit funktionieren tadellos. Nur in umgekehrter Richtung bekomme ich keine Verbindung mehr zustande. Die Firewall-Logs auf der Arbeit zeigen klar, dass die Verbindung durchgelassen wird. Der Versuch einer Verbindung zeigt auf dem Log zuhause aber leider keinen Eintrag. Irgendwie gehen keine VPN Pakete durch die Homebox. Geht das nur mit Bridge-Modus?

Früher mit normalem DSL hat alles wunderbar funktioniert.

Hat jemand eine ähnliche Konstellation und könnte mir Rat geben?

Grüße keeper

ftp-proxy: verbindung schlägt fehl - command not implemented

$
0
0
Hallo forum,

ich habe hier eine merkwürdigkeit:
Wenn ich filezilla als client und die utm als ftp-proxy benutze, habe ich folgendes Problem:

Verbindung schlägt fehl.
Logfile:
2014:06:10-15:59:55 proxy02 frox[27199]: Connect from xx.xx.15.62
2014:06:10-15:59:55 proxy02 frox[27199]: ... to 81.xx.xx.xx(daddeldu.com)
2014:06:10-15:59:55 proxy02 frox[27199]: Command OPTS not implemented
2014:06:10-15:59:55 proxy02 frox[27199]: PASV: 81.***.xx.***:29633
2014:06:10-15:59:55 proxy02 frox[27199]: Command MLSD not implemented
2014:06:10-15:59:55 proxy02 frox[27199]: Flushing server buffer

in filezilla habe ich folgendes format bei ftp-proxy benutzt:
Benutzerdefiniert:
USER %u@%h
PASS %p

proxyserver proxy.daddeldu.com:2121

Default Drop | PPStream | How to remove

$
0
0
Hi,

In Asia, Funshion is a extremely popular App people use on Android and iPhones for streaming Live or Downloading to play later.

On Sophos UTM 9.201-23 with ALL Security Modules Disabled (To Isolate problem).

1) LAN ->NAT-> WAN. (Masquerading)
2) LAN - ANY -> Internet = Allowed. (Only Rule, No other rule)
3) NO Other Modules (IPS, Application Controls, Web Proxy etc) enabled.

Funshion Downloads or Stream Extremely Badly and I see Numerous drops

Default Drop PPStream follow by the IP Addresses at port 2500

Their Website / Desktop (windows) Downloading / Streaming is fine.

ONLY Apps on iPhone and Android would trigger this Default Drop Rule.

How to Remove this Default Drop Rule?

Thank You

iPhone | Facebook App | Video Play Error

$
0
0
Sophos UTM 9.201-23
iPhone 4 iOS7.1.1 with All Apps Latest Version.

Problem: I noticed with Web Proxy, Most Videos that I want to play within Facebook Apps would Attempt to Play and you eventually sees Loading Error.

Troubleshooting:
1) It is definitely something in Web Proxy because if I put my iPhone to ByPass Proxy everything is fine but obviously we want everything to be protected.

2) The SAME Facebook Post - View from Internet Explorer, Firefox, Chrome on a Windows 7 Desktop play fine.

3) Attempt to click Open Link in Safari and the same video fails to play.

4) If that video is a YouTube - There is a button that we can press and it Opens YouTube App and playing within YouTube App is fine.

5) It is NOT only YouTube Videos that have this problem as some videos I have no idea what is the name or service.

6) It is NOT All Videos have problems. (Not everything is on youtube, some is video uploaded to FB and some I don't have any clue where it is trying to load)

The fact that the same thing seems to play fine on a Windows 7 Desktop logged into Facebook via different browsers seems to me that the Web Proxy is Not Blocking.

Thus now it seems more of Web Proxy is NOT Compatible with talking to Facebook or Safari APP.

Do you all face this issue?

Thank You

Web Reputation | Do you find it a Pain?

$
0
0
Currently I set Block Web Reputation Below Suspicious ( Which is the lowest) and still there are Numerous Legitimate Sites being blocked.

Reason that it is starting to be a pain is the amount of effort to allow Numerous Domains by looking at the Web Logs as now a days there is a Lot More Domains they load from various "shortform name"

Example

YouTube = It does load stuff from You.be ( Forgive me if I remember wrongly)

TODAY News = Instead of just Today.com and Today.com.sg, it also uses Tdy.sg

The Problem is Significantly Problematic when people use APPS.

I understand that Web Reputation is Not Foolproof but it seems Real Bad on this UTM.

I persistently Checked Websites using VirusTotal, WebSense, Norton Safe Site, Sucuri Net, McAfee Site Advisor, Trend Micro Smart Network and 99.9999999% of the time whereby the UTM Reported Malicious or Suspicious = ALL these other vendors give it a CLEAN.

Is there a way to feedback to SOPHOS Other than that Webbased Form which is a PAIN because they say they take 5 working days and they do NOT have a automated system to follow up on the Result after a Review.

Expose WLAN - Bridged to AP LAN

$
0
0
I'm very interested in having the UTM display WLAN traffic that is set as 'Bridge to AP LAN'. Currently, only Separate Zones show up on the Dashboard, Network Usage logs, etc. When you view Logging & Reporting --> Wireless Protection, I have two SSID's being reported as wlan0 and wlan2, whilst my Guest Network happens to be wlan1, so they seem to be actual interfaces.

I'm curious if anyone has tinkered with the UTM Interface in order to achieve something like that or similar. I could understand that eventually it could get cluttered, especially in large environments. Perhaps the ability to control which are visible.

I'm considering tinkering on a Sandbox UTM Install, so anyone who has familiarity with that, any guidance is appreciated.

Cheers!

UTM as a transparent filter.

$
0
0
I know the UTM can do this, I'm hoping for some pointers where to go to do some further reading before I tackle this.

The background is that due to some networking changes in two of our offices involving one of our IT partners, we no longer have the option of running Internet traffic through the UTM and just routing private traffic to our partner's routers' VPN tunnels. I still like the UTM as a product so was hoping to keep it as our primary network firewall and web filter, running all traffic through the UTM, but run the UTM as a transparent filter.

First, is getting the thing into the network as simple as creating a bridge between two interfaces (leaving a third as a management port), setting up and Any - Any - Any rule, and then inserting the UTM in between the gateway router and switch?

Trying to block https://www.apple.com

$
0
0
I'm trying to block https://www.apple.com and https://apple.com through web filtering and URL filtering. I have these domains added to the web filtering, but they are still accessible. I spent 1 1/2 hours on the phone with support yesterday, but I had other things to do and had to cut the call short.

Anything I can try to block the above websites? I have firmware 9.111-7 installed.

Thank you,

John

Hosted Exchange and Sophos UTM

$
0
0
Does anyone have a best practice for filtering hosted exchange traffic with a Sophos UTM?

Our hosted exchange filter provides email filtering for spam and viruses. I have Sophos UTMs at all locations. Is it possible to filter the HTTPS hosted exchange traffic at the UTM level before the emails are delivered to their Outlook?

Cyberoam in the mix

$
0
0
Hey guys,

Before I start buying any hardware for my UTM build. I have to ask, I saw that back in February Sophos purchased cyberoam. At the time their was a blog post mentioning the strong possibility of a long term integration.

I am excited for the idea of better integration and more robust features, I am just curious if their is anything known at this time that would affect a new UTM build. ie. If 16gb of RAM would be better as compared to the current recommended minimum of 8gb, due to some new, soon to be introduced feature.

I just thought I would double check before purchasing my hardware.

Thanks,

Scott (ftballpack)

u2d-sys-9.111007-112012

$
0
0
Hi all,

any infos about the "High urgency" of "u2d-sys-9.111007-112012.tgz.gpg"???

it has a lot of "stuff" in it... and it is no "Soft Release"... my UTM just downloaded it...

Code:

Up2Date 9.112012 package description:

Remarks:
 System will be rebooted
 Configuration will be upgraded
 Connected Wifi APs will perform firmware upgrade
 Connected RED devices will perform firmware upgrade

News:
 Maintenance Release
 Fixed several issues with Intel netword cards
 Fixed several issues with SAA MacOS X client

Bugfixes:
 Fix [26130]: DHCP mapping comments gets lost by upgrading to 9.100
 Fix [30016]: Mix SSL and WAF and SharePoint 2013 will no longer allow you to save files (file is opened write protected)
 Fix [30478]: System & UTM Backups ignore backup limits [9.1]
 Fix [30509]: Uploads via reverse proxy are limited to 128 MB when profile with 'XSS Filter' or 'SQL Injection Filter' enabled is in use [9.1]

RPM packages contained:
 libaviraglue-9.10-5.g5ff1659.i686.rpm           
 libopenssl1_0_0-1.0.1g-1.1.3.g85a91e6.i686.rpm   
 libopenssl1_0_0_httpproxy-1.0.1g-1.1.3.g85a91e6.i686.rpm
 libsaviglue-9.10-6.g510f560.i686.rpm             
 libudev0-147-0.65.1.1090.g17b9ff4.i686.rpm       
 freerdp-1.0.2-2.g2cd7ee9.rb3.i686.rpm           
 modproxymsrpc-9.10-62.g2866ca3.i686.rpm         
 openssl-1.0.1g-1.1.3.g85a91e6.i686.rpm           
 perf-tools-3.8.13.15-27.ge4e9011.i686.rpm       
 perl-IO-Socket-INET6-2.72-1.0.g8ae5623.rb1.noarch.rpm
 postgresql92-9.2.7-0.158345409.g0b33a45.i686.rpm 
 red-firmware2-2035-0.g9f5ac11.noarch.rpm         
 udev-147-0.65.1.1090.g17b9ff4.i686.rpm           
 wireless-firmware-ath9k-4028-0.166542980.g492ce03.i586.rpm
 wireless-firmware-rt2x00-3030-0.166542649.g29abda4.i586.rpm
 ep-reporting-9.10-16.g2b6a2b6.rb1.i686.rpm       
 ep-reporting-resources-9.10-16.g2b6a2b6.rb1.i686.rpm
 ep-confd-9.10-274.g9ed4aa7.i686.rpm             
 ep-endpoint-0.5-0.166185016.gbe3a6ec.i686.rpm   
 ep-ha-daemon-9.10-2.g6329eab.i686.rpm           
 ep-hardware-9.10-20.g86aad0c.i686.rpm           
 ep-libs-9.10-13.gf563a69.i686.rpm               
 ep-mdw-9.10-182.gaaa0071.i686.rpm               
 ep-notifier-9.10-8.g66358b8.i686.rpm             
 ep-raidtools-9.10-59.g40c11ca.i686.rpm           
 ep-red-9.10-87.gfd54bc6.i686.rpm                 
 ep-saa-mac-1.0.0-0.155153976.gc764d50.rb1.i686.rpm
 ep-samba-9.10-7.g9fd0b41.noarch.rpm             
 ep-screenmgr-9.10-0.gfa1fd0b.rb59.i686.rpm       
 ep-webadmin-9.10-210.g7bb6436.i686.rpm           
 ep-webadmin-contentmanager-9.10-13.g231466b.rb1.i686.rpm
 ep-chroot-dhcps-9.10-2.g2cf1614.rb1.noarch.rpm   
 ep-chroot-ntp-9.10-2.g9eb2b2e.rb1.noarch.rpm     
 ep-chroot-smtp-9.10-29.g3b64a83.i686.rpm         
 chroot-clientlessvpn-9.10-7.g8c9493d.i686.rpm   
 chroot-ipsec-9.10-7.g93cfeb0.i686.rpm           
 chroot-reverseproxy-2.4.4-111.g85b7382.i686.rpm 
 ep-chroot-pop3-9.10-42.g5b45454.i686.rpm         
 ep-httpproxy-9.10-122.g78f3998.i686.rpm         
 kernel-smp-3.8.13.15-27.ge4e9011.i686.rpm       
 kernel-smp64-3.8.13.15-27.ge4e9011.x86_64.rpm   
 ep-release-9.112-12.noarch.rpm


EDIT:

and now u2d-sys-9.112012-113001.tgz.gpg appeared... (on http://download.astaro.de/UTM/v9/up2date/)

that at least has a KB Article:
http://www.sophos.com/en-us/support/...se/121108.aspx

Transparent Proxy Session Idle Timeout

$
0
0
Hello,

I want to run Transparent Proxy with AD SSO. Everything work good but I don't have any idea how can I change transparent proxy session idle timeout. After circa 5 minutes users are somehow deauthenticated and they fall into "Default Block Filter". I need to restart web browser an then everything is OK until next deauthentication. I have changed Web Protection > Filtering Options > Misc > Authentication timeout to 3600 but it doesn't help( I assume it is applicable only to Standard Proxy). We are running 9.201-23 on 2xASG425 in active-standby HA. Web browser: Internet Explorer 11.

Honeywell NetAXS123 and opening ports

$
0
0
Trying to configure Sophos UTM/ASG320 so that building security company can get to and access their device which I've assigned a static ip to.
They requested that a port forward be opened on port 20029.
I've spoken with Luis Fonseca at Sophos support on this and done a tcpdump, and gotten a pcap file to look at in wireshark and it appears that there's traffic. But the security company tech support don't appear to have full knowledge of the Honeywell device, and while I can log into a web interface on it, telneting to check the connection doesn't appear to be available.
Have a DNAT rule and an SNAT rule and Luis confirms that it all appears correct.
How would I configure the UTM to respond to port scans of that port to show as 'open' rather than 'closed' or 'stealth' - the building security company responds to nearly all calls to them with a web based portscan - Subnetonline, MxToolbox or other and say that the port is closed so there's nothing for them to address. Mind you when I attempt a GRC shieldsup test it also shows as closed, so I've got to think there's something I can do to change that status and still be securely configured.

At this point I’m just guessing that some other rule or configuration is conflicting

Let me know if you've any further ways to troubleshoot this. Or if I need to put this in a different group.
Viewing all 14361 articles
Browse latest View live