Jump to content

Recommended Posts

Posted (edited)

Good afternoon,

 

I'm noticing on a couple of PC's, Sophos (Cloud) isn't updating and started to investigate why. Before summer, our firewall rules were restructured from allowing everything unless it was block, to blocking everything unless it was allowed.

 

Checking our firewall logs, I'm seeing a lot of HTTPS requests getting blocked by our default firewall rule. These are going to numerous IP's for example 52.19.226.19 and 34.248.21.115. These are from different internal ports but are exiting over 443.

 

Not being fully in the know with firewalls. Is there a reason why these request are not being sent over the proxy and are instead showing up as blocked in the firewall? I'm guessing that enabling 443 as a firewall rule isn't really a solution as could we be opening ourselves up for undesirable traffic leaving the network over 443.

 

Thanks

Edited by ZeroHour
Posted

So...do these troublesome PCs have a smoothwall https certificate installers?

 

You would need authentication exceptions to sophos cloud or to whatever else is getting blocked...because updates and the like will run as service account not as a user account.

Posted (edited)

Sophos did introduce some real time telemetry that used AWS that isn't proxy aware on the client a few years ago. It would be best to allow it through an intercepting proxy if you have this configured.

 

https://community.sophos.com/products/endpoint-security-control/f/sophos-endpoint-software/2434/sophos-anti-virus-making-1000-s-of-internet-requests-causing-very-slow-internet-speeds

Edited by free780
Posted

Thanks for the replies.

 

In answer to the questions, the affected PC's do have the Smoothwall SSL certs on them and we have auth exceptions for the websites used by Sophos. We're just in the process of setting up a Caching server, which should solve the issue with PC's trying to connect to Sophos directly.

 

However, I don't understand why traffic over port 443 is going through the firewall and not the proxy (transparent or fixed)

Posted
How are you setting the proxy? If you are setting a browser proxy - possibly with a GPO - that isn't necessarily picked up by anything else (JAVA is a case in point - which has its own separate configuration). Setting it via DHCP with an option pointing to WPAD (if you have a webserver somewhere to host this...) tends to be more successful with dome devices and applications.
Posted
However, I don't understand why traffic over port 443 is going through the firewall and not the proxy (transparent or fixed)

 

If it's direct IP traffic it won't go out via proxy, we get this with some parts of Office 365 and had to make a dynamic rule to allow it out directly.

Posted
If it's direct IP traffic it won't go out via proxy, we get this with some parts of Office 365 and had to make a dynamic rule to allow it out directly.

 

Thanks, did you use any tools to understand what application or service is creating the traffic? Some of the IP's just go to AWS etc, so knowing what's creating the traffic can be difficult.

Posted
Thanks, did you use any tools to understand what application or service is creating the traffic? Some of the IP's just go to AWS etc, so knowing what's creating the traffic can be difficult.

 

Our firewall recognises application traffic so we can tell which one it's from. Also the destination IP often matches up to Microsoft's list at https://docs.microsoft.com/en-gb/office365/enterprise/urls-and-ip-address-ranges?redirectSourcePath=%252farticle%252fOffice-365-URLs-and-IP-address-ranges-8548a211-3fe7-47cb-abb1-355ea5aa88a2

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...