I will preface this by saying I had a UTM120 for three years with the UTM9 OS and right now thinking boy I miss those days. I was told that my appliance was nearing end-of-life so to renew licensing I went with the XG115. I had configured UTM9 on my own and generated help desk cases if issues arose. This appliance is quite a bit different. Firmware XG115 (SFOS 17.0.0 GA) so on the latest firmware.
What I am trying to resolve right now is that any type of web surfing is extremely painful. I have an on-premise Exchange server so port 443 is being forwarded to it but I also have the default network rule of WAN to LAN all ports and all services are open. I have a similar network rule that WAN to LAN port 443 is open thinking of other workstations that initiate SSL traffic it will find its way back to the device that initiated the traffic. Let's face it. Most web sites are https. I am constantly being warned that the certificate cannot be verified and I have to click to still access the site or create an exception for the site depending on the browser. I cannot log in using an account to any web site. Some sites I can't even create the exception in Firefox. I can't use the StartPage search engine. Amazon looks like crap. No pictures and just a bunch of links.
A little bit on the network. Uverse gateway goes to a Cisco ASA appliance that I consider my perimeter (and why not have another layer of defense !). The XG is in bridge mode. For a time I would go to my OWA site for my on-premise exchange server and would get certificate errors there to (not up for renewal for another two weeks yet). The ASA is listed as the Gateway for the XG in the WAN port. The Lan port on the XG was plugged into my SG300 Cisco Switch. I don't go too crazy with the security on the switch. Just the default VLAN1 with port security tied to the MAC address of the device using the port. This configuration worked well with UTM9.
I get the feeling that some of the traffic is getting recognized as DDOS or TCP Flooding and discarded judging by what I see in the logs. I did click on the setting for allowing dynamic routing on the WAN port. I also made the XG the default gateway for the network.
Windows update appears to work. I have slimmed down security until I figure out the issue. Not using IPS on any of the firewall rules yet. I can connect to my network via RDP, SSH, FTP, my IP Cameras, and other things which use Business Application rules.
Under Web > General Settings I deselected "Block Invalid Certificates" and then was able to use ADSM to get to my ASA Appliance otherwise that was a problem too. HTTPS Scanning Certificate Authority is on the default SecurityAppliance_SSL_CA. I know I had issues with this option on the UTM9.
Most logs are empty but Firewall and IPS have a lot in them. Attached are from IPS logs. I see blocks for cloudflare but willing to bet part happens when I go to the Amazon Web Site. Notice lots of TCP Floods and the number of packets dropped.
”The time we save is the biggest benefit of E-E to our team. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange.
-Mike Kapnisakis, Warner Bros
With your subscription - you'll gain access to our exclusive IT community of thousands of IT pros. You'll also be able to connect with highly specified Experts to get personalized solutions to your troubleshooting & research questions. It’s like crowd-sourced consulting.
We can't always guarantee that the perfect solution to your specific problem will be waiting for you. If you ask your own question - our Certified Experts will team up with you to help you get the answers you need.
Our certified Experts are CTOs, CISOs, and Technical Architects who answer questions, write articles, and produce videos on Experts Exchange. 99% of them have full time tech jobs - they volunteer their time to help other people in the technology industry learn and succeed.
We can't guarantee quick solutions - Experts Exchange isn't a help desk. We're a community of IT professionals committed to sharing knowledge. Our experts volunteer their time to help other people in the technology industry learn and succeed.
Our community of experts have been thoroughly vetted for their expertise and industry experience.