Skip to main content
Jirka1
Explorer II
January 28, 2022
Question

7.0.4 - break Proxy inspection

  • January 28, 2022
  • 21 replies
  • 36100 views

Hello,

 

yesterday I upgraded FG200E to version 7.0.4.

In the previous version 7.0.1 I used proxy inspection + SSL deep inspection (certificate signed from AD). After the update (7.0.1 -> 7.0.3 -> 7.0.4) all policies in Proxy mode stopped working. Each browser returned an "err_ssl_protocol_error" error, but eg IMAPS, SMTPS worked well.
Once I've adjusted the Policy to flow (and all UTMs), everything works.

 

There wasn't much time to find out why it behaves like this, I'll continue this weekend.

 

Has anyone tried to deploy 7.0.4?

 

Jirka

21 replies

Jirka1
Jirka1Author
Explorer II
January 28, 2022

I did some more tests:

 

- the problem only appears when applying an APP or IPS profile on Proxy policy
- I tried to create a new Policy - no change
- I tried to change Deep Inspection to Certification Inspection - no change
- everything is functional only with AV and WEB filtering

Jirka

 

Hmichel
Visitor III
January 29, 2022

Hi,

same here with 601E. Workaround was to change ssl-inspection Form Deep-inspection to certificate inspection. Weird is, that i Patched yesterday 17:00 But it stopped working today 13:00. No difference with flow of proxy based policys. No difference if i disable webfilter, AC, AV … My Only Chance was to disable Deep inspection



EDIT: deep inspection works in Flow-based Mode 

 

Hagen

Jirka1
Jirka1Author
Explorer II
January 29, 2022

Hi Hagen,

 

that's exactly how it worked for me. After the update everything worked but over time the Proxy Policy stopped working. So certification inspection doesn't work for me either.
Last night I tried the box format installing 7.0.4 and restoring the configuration. It worked again for a while and this morning I'm getting "ERR_CONNECTION_CLOSED" from browsers (chrome, edge, firefox).
I have create ticket also on TAC and waiting for response.

Jirka

CorreyAnderson
New Member
January 30, 2022

No idea about it so far. But I would like to learn more. Thank you so much!

Kangming
Staff
Staff
January 31, 2022

Hi Jirka1,

Found a similar scene, do you match this issue environment?

=========

Traffic is blocked when AV profiled enabled in proxy inspection mode + IPSec scenario with NPU offloading enabled
Workaround: disable NPU offload in affected firewall policy

=========

 

Jirka1
Jirka1Author
Explorer II
January 31, 2022

Hi Kangming,

no, this workaround doesn't work for me.

Proxy policy paradoxically only works with my AV profile for me. If I add APP or IPS - I end up with a browser error "ERR_CONNECTION_CLOSED". And it doesn't matter if I use deep inspection or certification inspection.

Likewise, disabling offload has no effect.

Jirka

Kangming
Staff
Staff
January 31, 2022

Hi Jirka,

OK, I am reproducing this issue in my FGT401E environment, can you share with me the configuration of your proxy policy?

 

 

DVarouxis
New Member
February 2, 2022

Hello ,

 

same issue for my 100E on 7.0.4 . Had to change to Flow Mode to start Browsing .I had created from scratch other Utm Profiles  in Proxy which are worked for a couple of hours and then the same err_ssl_protocol_error.  This is very important for us who are using deep inspection and hope to release soon the fix . By moving to Flow is just a temporary solution but breaks the security  . Come on Support.. you fix smt  and always you break smt that it works  in the  last 2 years updates .

itserv
New Member
February 2, 2022

Hi,

 

just to add my info on 7.0.4 FG300E

 

I get an error on every policy in proxy mode where application control is enabled.

I had to or disable application control or switch to flow mode.

Changing ssl inspection didn't help. 

 

By.

ClaudioPersico
New Member
February 3, 2022

We have the same issue and we had to switch to flow mode. We urgently need to switch back to proxy mode. Thanks

dclabs
Visitor III
February 3, 2022

Same issue for us too.

We either had to switch to flow-mode or worse disable SSL inspection to get it  back to work.

notrixx
New Member
February 3, 2022

Same problem here. FG600E running 7.0.4

Have to disable app and ips inspection on policies using proxy mode to be able to browse the web.

dtesarik
Visitor III
February 3, 2022

We have same problems on FG1000D. Rolback to 7.0.3