Link to home
Start Free TrialLog in
Avatar of BrianRB
BrianRBFlag for United States of America

asked on

Sophos Windows Firewall and TeamViewer

What do I need to do to get this damn thing to work?  I'm having one hell of a time.  Works fine when I stop the service, but I'm unable to connect to it from my mobile, or any other device, when enabled.
Avatar of BrianRB
BrianRB
Flag of United States of America image

ASKER

FYI, I do have outbound stateful tcp 5938 enabled as well.  can browse the net just fine.

http://www.teamviewer.com/en/help/334-Which-ports-are-used-by-TeamViewer.aspx
Avatar of btan
btan

hope it is not the application control policy blocking it
http://www.sophos.com/en-us/threat-center/threat-analyses/controlled-applications/TeamViewer.aspx

also good to chek the Firewall Live Log and Web Filtering Live Log, if they surface any error for TV. Saw another track stating to use various HTTP/HTTPS scanning mode.
https://www.astaro.org/gateway-products/network-protection-firewall-nat-qos-ips/23675-teamviewer-blocking-3.html
In "Transparent" modes, the Proxy handles only HTTP (and HTTPS if scanning is selected). That's why it can't manage Teamviewer unless HTTPS scanning is enabled.

In "Standard" modes, the proxy handles all of the services listed in 'Allowed target services' on the 'Advanced' tab. In these modes, your browser sends the unencrypted HTTPS URL to the Proxy, thus allowing it to do URL filtering as well as
i think BrianRB uses a local software at his PC/Server like Sophos Enpoint Security ...

check the logfile seen at the following link, or do you have this problem also:
http://community.sophos.com/sophos/board/crawl_message?board.id=ESDP&message.id=16644
useful tips
http://www.sophos.com/en-us/support/knowledgebase/63997.aspx
Creating rules

Run as many applications as possible, that you know are used on computers on your network including web browsers. Details of these applications are recorded in the firewall logs.
Create a set of rules to allow these applications and then create a policy based on these rules.
Export this policy to Enterprise Console. This will provide the foundation upon which you can build other policies.

Rolling out the policy

Set the policy to 'Monitor mode' and roll it out to one or more groups on the network. This will now send reports back to the firewall log. Based on what is reported in the firewall logs, you can then update your policy to block or allow specified traffic.
Once you have run this for a while and are satisfied that you have designed policies to suit your network, reset the firewall to Block by default. Once you have done this it will block all traffic that is not specified in your policies.
Avatar of BrianRB

ASKER

D, you are correct.  Sorry I've been incognito guys.  None of this worked.  :(
have to see check the Intrusion Prevention, Application Control and Firewall logs to determine what is blocking then...if FW is turn off, can it work - should be (trying to ascertain it is default working). in forum there is also to the extend of allowing country to get it working per se

https://www.astaro.org/gateway-products/network-protection-firewall-nat-qos-ips/47474-teamviewer-country-blocking.html

although this is pertaining to UTM, there is specific version in Sophos in itself having conflict and some get it working with some config below

https://www.astaro.org/gateway-products/web-protection-web-filtering-application-visibility-control/48815-9-104-teamviewer-over-http-proxy-sometimes-not-working-2.html
Under Web filtering > Exceptions we have created the following new exception
Teamviewer [Allow Teamviewer Access]
Skipping: Authentication / Caching / Antivirus / Extension blocking / MIME type blocking / URL Filter / Content Removal / SSL scanning / Certificate Trust Check / Certificate Date Check
Matching these URLs: ^https?://([A-Za-z0-9.-]*\.)?teamviewer\.com/

Under firewall we have added a new rule called Teamviewer

Internet > TCP Port (Source: 1:65535) to (Destination: 5938) > Any IP4
Avatar of BrianRB

ASKER

Still nothing
Any error log in event viewer at the workstation, firewall log else this is wild goose chasing. even if sophos is blocking at machine then there should be some form of alert (via Application Control policy) too..
http://www.sophos.com/en-us/threat-center/threat-analyses/controlled-applications/TeamViewer.aspx
 ...also maybe disable Sophos and try windows firewall...same make sure the ports are open up ... after setting those rules try restart your PC. Make sure your changes in Windows Firewall are set for your current profile (Public, Home, Domain) Network.

Windows Firewall Profiles are related to Network Location Awareness (NLA). This allows you to apply a different set of Firewall rules depending on which network you are connected to. Please make sure that the profile you set is associated with the network you connected to.

Network Location Awareness (NLA) and how it relates to Windows Firewall Profiles
http://blogs.technet.com/b/networking/archive/2010/09/08/network-location-awareness-nla-and-how-it-relates-to-windows-firewall-profiles.aspx

Understanding Firewall Profiles
http://technet.microsoft.com/en-us/library/getting-started-wfas-firewall-profiles-ipsec(v=ws.10).aspx
Avatar of BrianRB

ASKER

Hey sorry I've been incognito.  Production has been crazy.  I went through everything you guys suggested and even what Sophos has on their site but still no joy.
ASKER CERTIFIED SOLUTION
Avatar of btan
btan

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of BrianRB

ASKER

yeah it doesn't work :(
looks like better to get the sophos FW uninstalled and confirm it can access and if so, reinstall using latest ver with default setting and try out and then enable the port as mentioned earlier and exception. if all remains, then switch the FW s/w since the support cannot better advice - too much subtle details not surfaced.