{"id":22327,"date":"2018-03-14T12:00:00","date_gmt":"2018-03-14T11:00:00","guid":{"rendered":"https:\/\/www.avanet.com\/kb\/sophos-firewall-and-the-quic-protocol\/"},"modified":"2022-06-16T19:43:05","modified_gmt":"2022-06-16T18:43:05","slug":"sophos-firewall-and-the-quic-protocol","status":"publish","type":"kb","link":"https:\/\/www.avanet.com\/en\/kb\/sophos-firewall-and-the-quic-protocol\/","title":{"rendered":"Sophos Firewall and the QUIC protocol"},"content":{"rendered":"\n<p>In this article we will explain what the QUIC protocol is and why you should disable it for security reasons, at least for now.<\/p>\n\n<h2 class=\"wp-block-heading\" id=\"h-was-genau-ist-das-quic-protokoll\">What exactly is the QUIC protocol?<\/h2>\n\n<p>QUIC stands for &#8220;Quick UDP Internet Connections&#8221; and was developed by Google to make the Internet faster.<\/p>\n\n<p>Let&#8217;s take a well-tried protocol, such as HTTP (Hyper Text Transfer Protocol). This already exists in a second version &#8211; HTTP\/2. The transport protocol that HTTP relies on is TCP. This has proven to be reliable, but it is also not exactly fast. The connection takes a long time to establish and if the page is then also encrypted with SSL, i.e. HTTPS, it takes even longer. This is exactly where Google came in and created QUIC, a protocol that is not only secure, but also enables fast connections.<\/p>\n\n<p>QUIC does not use TCP, but UDP, which is faster but also less reliable. Because of its speed, the protocol is therefore also often used for video or audio streaming. With QUIC, Google has managed to compensate for the unreliability of UDP and thus develop a fast, stable and secure protocol.<\/p>\n\n<p>The web server running this website here already supports QUIC. HTTP\/2 is used as the protocol by default. However, if you are using Google Chrome, QUIC is used. On the following screenshot you can see how the whole thing works. Massively less packet turnaround time (Round Trip Time &gt; RTT).<\/p>\n\n<figure class=\"wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-1 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/www.avanet.com\/assets\/sophos-firewall-tcp-tcp-tls-quic.jpg\"><img loading=\"lazy\" decoding=\"async\" width=\"997\" height=\"567\" data-id=\"21724\" src=\"https:\/\/www.avanet.com\/assets\/sophos-firewall-tcp-tcp-tls-quic.jpg\" alt=\"QUIC: Connection establishment without packet turnaround time\" class=\"wp-image-21724\" srcset=\"https:\/\/www.avanet.com\/assets\/sophos-firewall-tcp-tcp-tls-quic.jpg 997w, https:\/\/www.avanet.com\/assets\/sophos-firewall-tcp-tcp-tls-quic-64x36.jpg 64w, https:\/\/www.avanet.com\/assets\/sophos-firewall-tcp-tcp-tls-quic-300x171.jpg 300w, https:\/\/www.avanet.com\/assets\/sophos-firewall-tcp-tcp-tls-quic-600x341.jpg 600w, https:\/\/www.avanet.com\/assets\/sophos-firewall-tcp-tcp-tls-quic-768x437.jpg 768w, https:\/\/www.avanet.com\/assets\/sophos-firewall-tcp-tcp-tls-quic-18x10.jpg 18w\" sizes=\"auto, (max-width: 997px) 100vw, 997px\" \/><\/a><figcaption><small><strong>Image source<\/strong>: Chromium Blog<\/small><\/figcaption><\/figure>\n<\/figure>\n\n<p>But QUIC can do more, such as maintaining the connection to the web server. You are probably familiar with the behavior that when you visit a website at home and then want to view it again later on the road via 4G or in the office via the WLAN, the page is reloaded. This behavior is triggered because your IP address has changed, causing you to disconnect from the web server. With QUIC this won&#8217;t happen to you, because it works with browser detection and the connection can be easily re-established.<\/p>\n\n<h2 class=\"wp-block-heading\">QUIC &#8211; Uncontrollable with Sophos at the moment<\/h2>\n\n<p>Google has definitely developed something great with QUIC and with almost 60% market share of the Google Chrome browser (source: statista), they definitely have the power to spread this protocol.<\/p>\n\n<p>The problem, however, is that QUIC bypasses WebProxy, Sophos Sandstorm, and also malware scanning and content filtering. The reason for this is that currently only HTTP and HTTPS can be scanned by the web filter. So, as with <a href=\"https:\/\/www.avanet.com\/en\/blog\/https-scanning-why-it-should-be-enabled-on-sophos\/\">HTTPS scanning<\/a>, the firewall owner must take action to avoid taking any risks.<\/p>\n\n<h2 class=\"wp-block-heading\">Disable QUIC<\/h2>\n\n<h3 class=\"wp-block-heading\">1st option: Via Google Chrome<\/h3>\n\n<p>The first option would be to disable the QUIC protocol directly in the Google Chrome browser. To do this, simply enter <code>chrome:\/\/flags\/<\/code> in the address bar and deactivate QUIC.<\/p>\n\n<figure class=\"wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-2 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/www.avanet.com\/assets\/google-chrome-disable-quic-protocol.jpg\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"144\" data-id=\"21725\" src=\"https:\/\/www.avanet.com\/assets\/google-chrome-disable-quic-protocol-1024x144.jpg\" alt=\"Disable QUIC in Google Chrome\" class=\"wp-image-21725\" srcset=\"https:\/\/www.avanet.com\/assets\/google-chrome-disable-quic-protocol-1024x144.jpg 1024w, https:\/\/www.avanet.com\/assets\/google-chrome-disable-quic-protocol-64x9.jpg 64w, https:\/\/www.avanet.com\/assets\/google-chrome-disable-quic-protocol-300x42.jpg 300w, https:\/\/www.avanet.com\/assets\/google-chrome-disable-quic-protocol-600x84.jpg 600w, https:\/\/www.avanet.com\/assets\/google-chrome-disable-quic-protocol-768x108.jpg 768w, https:\/\/www.avanet.com\/assets\/google-chrome-disable-quic-protocol-1536x216.jpg 1536w, https:\/\/www.avanet.com\/assets\/google-chrome-disable-quic-protocol-18x3.jpg 18w, https:\/\/www.avanet.com\/assets\/google-chrome-disable-quic-protocol.jpg 1550w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/a><\/figure>\n<\/figure>\n\n<h3 class=\"wp-block-heading\">2nd option: Via Application Control<\/h3>\n\n<p>If you prefer to block QUIC via the firewall, you can control this via Application Control. Simply create a new filter, add the QUIC protocol and finally select the created filter under Application Control.<\/p>\n\n<figure class=\"wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-3 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/www.avanet.com\/assets\/google-chrome-disable-quic-application-control-filter.jpg\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"385\" data-id=\"21726\" src=\"https:\/\/www.avanet.com\/assets\/google-chrome-disable-quic-application-control-filter-1024x385.jpg\" alt=\"Add QUIC protocol to the filter\" class=\"wp-image-21726\" srcset=\"https:\/\/www.avanet.com\/assets\/google-chrome-disable-quic-application-control-filter-1024x385.jpg 1024w, https:\/\/www.avanet.com\/assets\/google-chrome-disable-quic-application-control-filter-64x24.jpg 64w, https:\/\/www.avanet.com\/assets\/google-chrome-disable-quic-application-control-filter-300x113.jpg 300w, https:\/\/www.avanet.com\/assets\/google-chrome-disable-quic-application-control-filter-600x225.jpg 600w, https:\/\/www.avanet.com\/assets\/google-chrome-disable-quic-application-control-filter-768x288.jpg 768w, https:\/\/www.avanet.com\/assets\/google-chrome-disable-quic-application-control-filter-1536x577.jpg 1536w, https:\/\/www.avanet.com\/assets\/google-chrome-disable-quic-application-control-filter-18x7.jpg 18w, https:\/\/www.avanet.com\/assets\/google-chrome-disable-quic-application-control-filter.jpg 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/a><\/figure>\n<\/figure>\n\n<figure class=\"wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-4 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/www.avanet.com\/assets\/google-chrome-disable-quic-application-control-firewall-rule.jpg\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"406\" data-id=\"21727\" src=\"https:\/\/www.avanet.com\/assets\/google-chrome-disable-quic-application-control-firewall-rule-1024x406.jpg\" alt=\"Select QUIC filter under Application Control\" class=\"wp-image-21727\" srcset=\"https:\/\/www.avanet.com\/assets\/google-chrome-disable-quic-application-control-firewall-rule-1024x406.jpg 1024w, https:\/\/www.avanet.com\/assets\/google-chrome-disable-quic-application-control-firewall-rule-64x25.jpg 64w, https:\/\/www.avanet.com\/assets\/google-chrome-disable-quic-application-control-firewall-rule-300x119.jpg 300w, https:\/\/www.avanet.com\/assets\/google-chrome-disable-quic-application-control-firewall-rule-600x238.jpg 600w, https:\/\/www.avanet.com\/assets\/google-chrome-disable-quic-application-control-firewall-rule-768x304.jpg 768w, https:\/\/www.avanet.com\/assets\/google-chrome-disable-quic-application-control-firewall-rule-1536x608.jpg 1536w, https:\/\/www.avanet.com\/assets\/google-chrome-disable-quic-application-control-firewall-rule-18x7.jpg 18w, https:\/\/www.avanet.com\/assets\/google-chrome-disable-quic-application-control-firewall-rule.jpg 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/a><\/figure>\n<\/figure>\n\n<h3 class=\"wp-block-heading\">3rd option: block UDP on the firewall<\/h3>\n\n<p>The third option is to simply block UDP on ports 443 and 80 on the firewall, which will then automatically use HTTP\/HTTPS.<\/p>\n\n<figure class=\"wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-5 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/www.avanet.com\/assets\/sophos-firewall-sfos-block-quic-protocol-services.jpg\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"327\" data-id=\"21728\" src=\"https:\/\/www.avanet.com\/assets\/sophos-firewall-sfos-block-quic-protocol-services-1024x327.jpg\" alt=\"Disable QUIC in Google Chrome\" class=\"wp-image-21728\" srcset=\"https:\/\/www.avanet.com\/assets\/sophos-firewall-sfos-block-quic-protocol-services-1024x327.jpg 1024w, https:\/\/www.avanet.com\/assets\/sophos-firewall-sfos-block-quic-protocol-services-64x20.jpg 64w, https:\/\/www.avanet.com\/assets\/sophos-firewall-sfos-block-quic-protocol-services-300x96.jpg 300w, https:\/\/www.avanet.com\/assets\/sophos-firewall-sfos-block-quic-protocol-services-600x191.jpg 600w, https:\/\/www.avanet.com\/assets\/sophos-firewall-sfos-block-quic-protocol-services-768x245.jpg 768w, https:\/\/www.avanet.com\/assets\/sophos-firewall-sfos-block-quic-protocol-services-1536x490.jpg 1536w, https:\/\/www.avanet.com\/assets\/sophos-firewall-sfos-block-quic-protocol-services-18x6.jpg 18w, https:\/\/www.avanet.com\/assets\/sophos-firewall-sfos-block-quic-protocol-services.jpg 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/a><\/figure>\n<\/figure>\n\n<p><\/p>\n","protected":false},"author":5,"featured_media":0,"parent":0,"template":"","format":"standard","kb_kategorie":[382],"class_list":["post-22327","kb","type-kb","status-publish","format-standard","hentry","kb_kategorie-sophos-firewall"],"blocksy_meta":[],"acf":[],"_links":{"self":[{"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/kb\/22327","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/kb"}],"about":[{"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/types\/kb"}],"author":[{"embeddable":true,"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/users\/5"}],"wp:attachment":[{"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/media?parent=22327"}],"wp:term":[{"taxonomy":"kb_kategorie","embeddable":true,"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/kb_kategorie?post=22327"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}