Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted

Hi all

 

Does anyone who uses Sophos Firewall have the issue where the Outlook client just plain crashes increasingly regularly at random intervals? Googling this it appears to have been a known issue for many but I cannot see an resolution...

 

Cheers in advance...

Posted
Had issues like that at a previous school. After we first installed there were issues of Outlook showing as offline regularly. This turned out to be an idle time out in the XG user authorisation. Other times when there was slowness in Outlook I would check the M365 endpoints and make sure any new IPs weren't being inspected.
Posted
We have already added the web exceptions for O365 using the import feature that is available. I will look into the idle timeout next as suggested above. Thankyou for your replies...
Posted (edited)
We have already added the web exceptions for O365 using the import feature that is available. I will look into the idle timeout next as suggested above. Thankyou for your replies...

 

Try creating a new Web->Exception list, called something like Office Endpoints or so, and enter the RegEx's from that article into it, rather than using the Import feature. We've found that not only creates a lot of unnecessary Web Exceptions when you can have a single list, but it may also cause issues.

 

Also, as others have said, if you're using STAS then check Authentication->STAS and 'Restrict client traffic during identity probe'.

 

Once you've got the RegEx's imported to a single Exception list, you can remove the other ones which were automatically created by the Import method and see if that's any better. Include the more general RegEx's too, specifically for office.com (from the article, linked in the chat):

 

https://support.sophos.com/support/s/article/KB-000038173?language=en_US

Edited by Wave9_Lee
Posted
Thankyou Lee, I have added in all the Regex's and removed all the ones I imported. 'Restrict client traffic during identity probe' is already set to YES. I am going to monitor for a while now and see if it has made any difference...
Posted
We currently have the STAS "Identity probe time-out" set to 120, any recommendations on this?

 

If you have identity probe timeout set to 120, but have 'Restrict client traffic during identity probe" set to 'no', then it shouldn't matter. But if you have the latter set to yes, then you'll probably get issues every hour for 2mins (120secs). See the STAS article here and search for 'Restrict client traffic': https://community.sophos.com/sophos-xg-firewall/f/recommended-reads/125318/sophos-firewall-best-practice-for-stas

Posted (edited)
Thankyou Lee, I did indeed have it set to be 120 & YES but I have now set to 120 & No and so far so good... Edited by aac
Posted

If you have the list of exceptions in - Skipping HTTPS decryption, Malware & Policy checks - and they're showing up in the Log Viewer->Web Filter log as having those applied (EG "domain="outlook.office365.com", exception="av,https,policy,zero-day protection,validation"), then you should be good on that side of things.

 

If you create an 'allow all' firewall rule on the XG for your test machine (LAN->SourceIPAddress, WAN->Any, no web policy attached = no filtering), that should give you an idea on whether there's a problem on the firewall or not.

 

And, I'm sure you've already tried it, but there's an Outlook Connectivity Assistant tool here from Microsoft which may help identify any client-side / connetivity issues: http://tinyurl.com/mrxzwd6f

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...