TheSpawn
Neuling
- Mitglied seit
- 11.02.2013
- Beiträge
- 14
Hier ist der Link zu dem Thread den needles meint: T-Home Entertain / IPTV - Sophos User Bulletin Board
Follow along with the video below to see how to install our site as a web app on your home screen.
Anmerkung: this_feature_currently_requires_accessing_site_using_safari
Hast du den Webfilter an? Dann lösche mal den cache (unter advanced)
Ansonsten ist das SQL-Log noch ziemlich groß und die coredumps. Beides geht nur über die CLI zu löschen
Up2Date 9.107033 package description:
Remarks:
System will be rebooted
Configuration will be upgraded
Connected REDs will perform firmware upgrade
Connected Wifi APs will perform firmware upgrade
News:
Update to UTM 9.107
Bugfixes:
Fix [21794]: Support UTM 9 install on ASG 120 Rev4 with 2GB Memory
Fix [22571]: UTM-RED Client with dynamic IP doesn't re-establish the tunnel
Fix [23727]: Wifi: it should not be possible to set the same Mesh name twice
Fix [24059]: Aua fails to handle customized user group attributes
Fix [24430]: Sporadic reboots probably caused from sip helper
Fix [24572]: Automatic Monitoring shows Uplink Interface as ONLINE although it is down
Fix [25219]: If Inline PGP decryption fails the customer is getting an empty mail
Fix [25323]: Obviously wrong traffic counting
Fix [25459]: WiFi Separate Zone: Suddenly it's not possible to process traffic via the AP due to incorrect RED peer address
Fix [25492]: Policy routing not working together with full transparent mode of HTTP proxy
Fix [25572]: Default gateway for DSL interface not set probably in link failover setup
Fix [25657]: Do not imply filename and next-server when specifying DHCP options 66/67
Fix [25910]: [e1000] Reset Adapter after Update to 9.100 and some Intel Interfaces
Fix [25931]: False Positive during WAF Upload
Fix [25940]: Several core dumps in __kernel_vsyscall (/usr/apache/bin/httpd -k restart)
Fix [25980]: DHCP server does not provide IP address if address pools are used
Fix [26077]: WAF real server is switching to error state every 5-10 min without any known reason
Fix [26273]: Improvement of Notification Information in notifier.log
Fix [26388]: RED50 Traffic not possible, red_server reports "Unable to get proc entry"
Fix [26450]: Upon upgrade, "The web filtering URL regular expression object with the name 'Any domain expressions' already exists"
Fix [26656]: RAS Manager is not able to change or create SSL VPN Profiles
Fix [26850]: Default gateway for PPPoE interface not set after reconnect
Fix [26929]: If username contains a '\' SSL VPN config is not stored correctly on the client
Fix [26933]: hotspot doesn't work in an active active cluster environment
Fix [27084]: high cpu load from postgres. Caused from pfilter reporter
Fix [27198]: Not possible to decrypt an email if there are more than one empty lines between header and body
Fix [27253]: Search Engine reports do not work if uppercase domain name is used
Fix [27362]: SAA doesn't work for AD users
Fix [27421]: Disabled RED devices are always able to establish a connection to the UTM
Fix [27455]: Adding an additional interface to PPPoE interface takes it down
Fix [27473]: Visit of ZDF mediathek will cause a display bug in websec reporting.
Fix [27479]: mdw died on UTM100/110 if QoS is enabled without a selector
Fix [27597]: red_server dies after RED reconnect - no further connection possible until UTM reboot
Fix [27685]: New Packetfilter block rules doesn't work for established connections
Fix [27777]: WiFi: Radius packets which should be going to a server routed via IPSec goes out on external interface
Fix [27789]: RED status overview not matching real tunnel status
Fix [27862]: User accounts with less then 3 characters in the username are not consider from the reporting
Fix [27865]: Transparent Split mode doesn't resolve names correctly on RED50
Fix [27887]: [e1000e] Reset adapter unexpectedly
Fix [27910]: Unable to configure the HTTP default profile in the global section caused by AP connected via RED
Fix [28053]: swap partition did not get a UUID
Fix [28223]: The websecurity manager is not able to change or create some proxy settings
Fix [28323]: Unable to create or change any additional address at the ASG
Fix [28327]: HTTP Proxy segfault in PCRE match()
Fix [28413]: Multipath is routing packets on wrong interface after one load balanced ipsec connection fails
Fix [29164]: UTM failover although the syncing process is not finished (prefered master option enabled)
Fix [29900]: RED50 freeze after update to 9.107 SR
Fix [29954]: Endpoint: Not working anymore after update to 9.107 SR
RPM packages contained:
libevent-1_4-2-1.4.5-24.21.495.g000604f.rb2.i686.rpm
libevtlog0-0.2.7-4.22.902.ge4b8fa1.rb1.i686.rpm
libnetfilter_conntrack-1.0.2-4.g5cfbcdf.i686.rpm
libtiff3-3.8.2-141.150.1.1008.g61ccc04.rb1.i686.rpm
aaa_base-11-6.75.1.958.gfd2813d.rb1.i686.rpm
binutils-2.21.1-0.7.25.816.g06392a7.rb1.i686.rpm
ctasd-5.00.0042-2.g0346c9a.rb2.i686.rpm
gpg2-2.0.9-25.33.31.1.942.g5fdba77.rb1.i686.rpm
grub-0.97-162.13.12.1.995.g17fe6b2.rb2.i686.rpm
hwinfo-15.46-0.9.1.975.g9aac543.rb1.i686.rpm
modcookie-9.10-45.g5ce7f15.i686.rpm
modsecurity2-2.5.12-630.gaabd4d0.rb2.i686.rpm
modurlhardening-9.10-43.gc5d31f8.i686.rpm
openssh-5.1p1-41.55.1.914.gcd8e721.rb1.i686.rpm
perf-tools-3.8.6-39.g8a65a05.i686.rpm
red-firmware2-2026-0.g6e286d0.noarch.rpm
rrdtool-1.4.7-1.g81b2a2b.rb1.i686.rpm
smartmontools-5.42-1.1.g200796c.rb1.i686.rpm
smartmontools64-5.42-1.1.g200796c.rb1.x86_64.rpm
udev-147-0.65.1.1050.gb2db9fc.i686.rpm
ulogd-2.1.0-47.gb6f30ae.i686.rpm
wireless-firmware-ath9k-4027-1.gef81435.i586.rpm
wireless-firmware-rt2x00-3029-0.148411878.geb8d5b7.rb1.i586.rpm
xorg-x11-7.4-9.47.1.800.g114f0fe.rb1.i686.rpm
xorg-x11-Xvnc-7.4-27.66.1.875.g77c280f.rb3.i686.rpm
xorg-x11-libICE-7.4-1.15.49.gb65ae06.rb2.i686.rpm
xorg-x11-libSM-7.4-1.18.47.gb65ae06.rb2.i686.rpm
xorg-x11-libX11-7.4-5.9.1.722.g338214c.rb2.i686.rpm
xorg-x11-libXau-7.4-1.15.45.gb65ae06.rb2.i686.rpm
xorg-x11-libXdmcp-7.4-1.15.43.gb65ae06.rb2.i686.rpm
xorg-x11-libXext-7.4-1.16.21.484.g0c49caf.rb1.i686.rpm
xorg-x11-libXfixes-7.4-1.14.41.gb65ae06.rb2.i686.rpm
xorg-x11-libXmu-7.4-1.17.39.gb65ae06.rb2.i686.rpm
xorg-x11-libXp-7.4-1.14.38.gb65ae06.rb2.i686.rpm
xorg-x11-libXpm-7.4-1.17.37.gb65ae06.rb2.i686.rpm
xorg-x11-libXprintUtil-7.4-1.17.36.gb65ae06.rb2.i686.rpm
xorg-x11-libXrender-7.4-1.14.35.gb65ae06.rb2.i686.rpm
xorg-x11-libXt-7.4-1.17.34.gb65ae06.rb2.i686.rpm
xorg-x11-libXv-7.4-1.14.33.gb65ae06.rb2.i686.rpm
xorg-x11-libfontenc-7.4-1.15.50.gb65ae06.rb2.i686.rpm
xorg-x11-libs-7.4-8.26.32.1.723.g338214c.rb2.i686.rpm
xorg-x11-libxcb-7.4-1.20.34.485.g0c49caf.rb1.i686.rpm
xorg-x11-libxkbfile-7.4-1.14.40.gb65ae06.rb2.i686.rpm
xorg-x11-xauth-7.4-9.47.1.800.g114f0fe.rb1.i686.rpm
ep-reporting-9.10-15.g26477ef.rb1.i686.rpm
ep-reporting-c-9.10-97.gf73271d.i686.rpm
ep-reporting-resources-9.10-15.g26477ef.rb1.i686.rpm
ep-confd-9.10-216.g2a4de59.i686.rpm
ep-confd-tools-9.10-166.g57b8fee.rb2.i686.rpm
ep-confd-turksat-xml-rpc-proxy-9.10-3.gb15d411.rb2.i686.rpm
ep-epsecd-9.10-43.ga942ccd.i686.rpm
ep-ha-9.10-2.g20f5384.rb1.i686.rpm
ep-ha-confd-9.10-5.gd319a90.rb1.i686.rpm
ep-ha-daemon-9.10-1.g1384cc9.i686.rpm
ep-hardware-9.10-0.g235b824.rb1.i686.rpm
ep-libs-9.10-11.g05854bd.rb1.i686.rpm
ep-localization-afg-9.10-63.g35c9a2c.rb1.i686.rpm
ep-localization-ang-9.10-63.g35c9a2c.rb1.i686.rpm
ep-localization-asg-9.10-63.g35c9a2c.rb1.i686.rpm
ep-localization-atg-9.10-63.g35c9a2c.rb1.i686.rpm
ep-localization-aug-9.10-63.g35c9a2c.rb1.i686.rpm
ep-logging-9.10-2.g4e26e17.rb2.i686.rpm
ep-mdw-9.10-150.gbb6b850.i686.rpm
ep-notifier-9.10-7.ga3692ac.rb1.i686.rpm
ep-red-9.10-81.g9632739.i686.rpm
ep-red-windows-driver-9.10-0.g6ddfd31.rb1.i686.rpm
ep-red-windows-service-9.10-2.g5d6c534.rb1.i686.rpm
ep-repctl-0.1-0.148996212.g69ce19a.i686.rpm
ep-screenmgr-9.10-0.gfa1fd0b.rb23.i686.rpm
ep-service-monitor-1.0-19.gece67ce.i686.rpm
ep-ulogd-9.10-1.gaa06d05.rb1.noarch.rpm
ep-urid-9.10-2.g23806c4.i686.rpm
ep-webadmin-9.10-158.g2feaa13.i686.rpm
ep-webadmin-contentmanager-9.10-7.g9403139.rb1.i686.rpm
ep-chroot-smtp-9.10-22.g1560209.rb1.i686.rpm
chroot-httpd-mod-fcgid-2.3.7-27.gd79bacd.i686.rpm
chroot-ipsec-9.10-4.g9c0ddf5.i686.rpm
chroot-openvpn-9.10-9.g2ba798f.i686.rpm
chroot-reverseproxy-2.4.4-94.g15e07d7.i686.rpm
dhcp-chroot-client-4.1.2_ESV_R8-2.ge83d069.i686.rpm
dhcp-chroot-server-4.1.2_ESV_R8-2.ge83d069.i686.rpm
ep-httpproxy-9.10-100.g44f0b71.i686.rpm
kernel-smp-3.8.6-39.g8a65a05.i686.rpm
kernel-smp64-3.8.6-39.g8a65a05.x86_64.rpm
ep-release-9.107-33.noarch.rpm
Intrusion Prevention wird in der DMZ Umgebung angewendet, alles andere führt zu Problemen.
mach einmal eine Firewall Regel mit
Source:Internal
Service: Any
Desitination: Any
Setze diese Regel an die unterste Stelle.
mach einmal eine Firewall Regel mit
Source:Internal
Service: Any
Desitination: Any
Setze diese Regel an die unterste Stelle.
Damit öffnest du aber die Tore und setzt die Firewall so gut wie ausser Kraft..
Temporär zum Testen OK, aber keinesfalls immer.
Auch um die UTM performant zuhalten, würde ich die FW Regeln anders anordnen.
Falls VoIP benutz wird, dann an erster Stelle. Web Surfing an zweiter, Email an dritter Stelle usw. Sachen (Dienste) die oft genutzt werden, müssen oben sein.
Es gibt bei der UTM wie auch bei vielen anderen FW first-match. Das hat mit der Geschwindigkeit gar nicht zu tun.
- Falls du mit Webproxy die Webprotection > Webfilter meinst, dann ja das ist an. Ebenso die Application-Control.
Klar - ist nur die Frage wann.Bin ja mal gespannt ob wir den Wagen noch zum fahren kriegen...
Hast du oben nicht geschrieben, dass im IPS-Log nichts kommt, eventl. blockt was anderes.
Schalt mal Webfilter und Applikation-Control ab, dann natürlich die Firewall-Regel Websurfing aktivieren und check dann mal, ob du rauskommst.
Ja im IPS-Log ist kein Einziger Eintrag abgelegt, das Problem tritt nur auf wenn ich unter Network Protection > Intrusion Prevention > Allgemein den Schalter auf "ON" stelle. Ab diesem Zeitpunkt ist das Internet für alle LanClients an allen Diensten tot!!!
Mit dem Schalter auf IPS-Schalter "Off" funktioniert alles wunderbar...
Also mein ich liegts schon irgendwie am IPS, allerdings wohl nicht an den Angriffsmusterregeln(sind ja alle nicht Aktiv!!!) sondern irgendwo tiefer drin...
Den Test ohne Webprotection habe ich wie oben unter Nachtrag beschrieben bereits ohne Erfolg durchgeführt. Irgendwas ist hier "Crazy".
Haste Transparentmodus? Ohne Authentifizierung?Danke für deine Ausführungen zum Webprotect, habe die FiWa-Regel mal deaktiviert und Https-Scanning in WebProt aktiviert.