I may have traced the problem to some of the meeting traffic getting flagged as Proxy and Tunnel (x-vpn and freegate proxy) when it's incoming, and P2P Torrent Clients P2P when it's outgoing. Both are getting blocked by the application filter. IPS is currently disabled while we troubleshoot this.
198.251.234.154 appears to be a Zoom IP, but it's not listed in the zoom exception list. That might be due to this being a training session, so maybe they have some separate or dedicated IP's for that?
Hello FAAC Inc ,
Thank you for reaching out to the community, I would suggest try prioritizing the traffic, for the reference here is the recommended read - Sophos Firewall: How to prioritize the traffic via SD-WAN for the applications
The blocked torrent and VPN events I was seeing in the application log are gone now that I've allowed the traffic, but a user just sent me a message that his audio was dropping on the meeting, so that may not have been part of the problem after all.
Another site has the same firewall, firewall settings, network switches, and the same ISP and is not experiencing the problems. So now I'm not sure it's a firewall issue at all. I have monitoring setup on our switches to measure traffic and while there are some spikes in traffic that matches when meetings are going on, there are just as many instances of the audio problem when traffic is very low.
Can you validate whether the ISP is dropping the VoIP services traffic with the ISP Team ?
Or if you have another ISP configured on the same FW, you can try routing from another ISP and can validate the difference in the audio ?
I am administrator of a public organization and my users use the endpoint security 6.2.2021.2. I have a great problem with freegate application. Some of my users had download this application and so they bypass my web control. Unfortunatelly endpoint could not find this app as threat. What can i do with it? How can i protect my network from this kind of threats?
93ddb68554