SonicWALL TZ 300 and Filtering

It seems that my TZ300 is blocking my being able to log into to The login to Sophos works fine until I get redirected to This then hangs. If I bypass the firewall I can log in fine. I have added to the allowed section in:-

Security Services/Content Filter/Configure/Custom List/Allowed URI

... but it makes no difference. I can't see anything on the TZ300 log. I have also filtered packet filtering for my machine and can't see anything that would help me resolve what's going on.
Who is Participating?
cescentmanConnect With a Mentor Author Commented:
I’ve resolved this. The MTU setting on the firewall was 1500, putting it at 1492 sorted it.

Thanks for your help
J SpoorTMECommented:
Sophos is a direct competitor of SonicWALL. Your unit probably doesn't like you going to the competition.

Just a joke :)

Can you explain the exact behavior you are seeing? Any error message?
Not sure what this okta is?

Can you ping the domain that is not working to capture the IP address.
Then run a packet capture on that IP address and see if there are dropped packets.
if so, please copy paste the dropcode and module ID..

View example configurations and the SonicWALL webui and features on or
cescentmanAuthor Commented:
Thanks for the speedy reply. Although I couched it as my network it's actually my son's business network so gathering data takes a little time as I need to remotely connect..

OK so redirects to on any number of machines I have tried outside his network. Also any machines bypassing the TZ300 connect without problem too.

The IP address changes so they clearly use balancing.

On his network through the firewall there is no error it just says fails to reach the site. There are no dropped packets showing when I refresh the browser and the packet capture screen

PingConfigureing packet captureAccessing sophos.okta.comNothing showing
Simple Misconfiguration =Network Vulnerability

In this technical webinar, AlgoSec will present several examples of common misconfigurations; including a basic device change, business application connectivity changes, and data center migrations. Learn best practices to protect your business from attack.

J SpoorTMECommented:
can you do the following, when capturing set Ethernet protocol to IP

you only caught switch packets

anyways the browser says it's a time out, if it would have been the SonicWALL dropping the packet you would see a different error.

from your pc open acommand promt


gimme the out put please
cescentmanAuthor Commented:
OK no sign of dropped packets on the TZ300 the tracert output:-

Tracing route to []
over a maximum of 30 hops:

  1     7 ms     6 ms     7 ms
  2     7 ms     7 ms     7 ms
  3    12 ms     7 ms     8 ms []
  4    95 ms   210 ms   210 ms []
  5    88 ms    98 ms    88 ms []
  6     *        *        *     Request timed out.
  7     *        *        *     Request timed out.
  8    94 ms    92 ms    99 ms
  9    89 ms    89 ms    89 ms
 10    88 ms    89 ms    89 ms
 11     *        *        *     Request timed out.
 12     *        *        *     Request timed out.
 13     *        *        *     Request timed out.
 14     *        *        *     Request timed out.
 15     *        *        *     Request timed out.
 16   110 ms   107 ms   105 ms
 17     *        *        *     Request timed out.
 18     *        *
J SpoorTMECommented:
I'm also getting a lot of timed outs, hoped this would show a routing issue.

I can access the link from behind my own Sonic.

Unfortunately I'm at a loss without having the ability to advanced debug your SonicWALL...

cescentmanAuthor Commented:
Is advanced debugging something we could organise via a remote session?
J SpoorTMECommented:
I would first run it by your son.
And / or contact SonicWALL support.
cescentmanAuthor Commented:
I'm not sure what to do in this case as I resolved it but it seems unfair you get no points for all the effort you put in.
J SpoorConnect With a Mentor TMECommented:
seems you have fragmentation issues then....
cescentmanAuthor Commented:
The problem was resolved by me but on the way jspoor was very helpful.
Blue Street TechLast KnightsCommented:
Regarding your fragmenting issue this article will show you how to dial in your MTU settings precisely so that you can maximize your efficiency:

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.