Jump to content

Recommended Posts

Posted

Hi there,

 

do any of you Lightspeed users use O365 and are you finding logging into it extremely slow?

 

Thanks

 

 

(Argh sorry about the spelling mistake in the title :()

Posted

Ah ha!

 

After a rather busy day I have finally managed to investigate this issue further.

 

When using IE to browse and use login.microsoftonline.com it's painfully slow. Using Firefox or Chrome works a charm.

 

So looking into the settings for IE, there is one for 'Check for server certificate revocation'. If enabled is what's killing the https connections. When this is disabled access to https sites goes through smoothly on IE.

 

I'm tempted to just disable this via GPO and be done with it but I'd rather ask the Oracle aka Edugeekers about whether there's another way to fix this without compromising things.

 

Thanks

Posted
So what is Lightspeed doing to slow that down?

 

Haven't a clue but when I sent the internet traffic from my PC via the old smart cache it works fine but Lightspeed at the moment aren't convinced that it's a Lightspeed issue.

 

I have added my PC as an exclusion on the Lighyspeed box but the issue is still there.

 

I will plug a laptop directly into the router tomorrow and see what that brings up!

Posted

Does it work if you disable CRL checking but still go through the Lightspeed does it still happen?

 

Likewise, having that enabled but not going through the Lightspeed what happens?

  • Thanks 1
Posted
Does it work if you disable CRL checking but still go through the Lightspeed does it still happen?

 

Likewise, having that enabled but not going through the Lightspeed what happens?

 

Disabling this setting within IE makes iE behave normally.

 

I will setup a laptop tomorrow that will go through to the we without going via the Lightspeed box and see what happens.

 

Prior to having the Lightspeed box in place this wasn't an issue.

Posted

I have just got my laptop accessing the internet directly through our firewall/router and there was no issue what so ever when having 'Check for server certificate revocation' enabled. :(

 

When I set the laptop up to go back through the LS box with this IE setting in place then we get the issues with accessing https stuff again.

 

I have fired this back over to Lightspeed so we shall see what they say.

 

Very odd!

Posted

bodminman,

 

I did get a reply from Lightspeed which was no help what so ever as i am experiencing the same issues at out site;

The connections to Office 365 appears to be to random external IP Addresses on Port 137 when I looked through your Web Activity Report yesterday, if the server was on site it could be added to the Rockets Internal Ignore list. - What a load of rubbish!

 

Still awaiting for an educated answer

  • Thanks 1
Posted
So I assume connecting to Office 365 through Outlook operates normally? We're going live with Lightspeed soon so be interesting to see.
Posted
So I assume connecting to Office 365 through Outlook operates normally? We're going live with Lightspeed soon so be interesting to see.

 

At the moment I can't get my outlook to connect through to O365 although it has worked but it stopped earlier this week. I shall be tackling this tomorrow and I will let you know how I get on.

Posted

Make sure you have P2P turned off on your Lightspeed box, I am now getting the following error when users try and access out o365 SharePoint;

If you retry the SharePoint link again it allows you through.....

 

sharepoint error.JPG

Posted
Make sure you have P2P turned off on your Lightspeed box, I am now getting the following error when users try and access out o365 SharePoint;

If you retry the SharePoint link again it allows you through.....

 

[ATTACH=CONFIG]21439[/ATTACH]

I'm seeing that too actually if I use mail.ourdomain.com. If I go to the proper login page it works.
Posted
Is lightspeed blocking access to the CRLs you need? That could slow things down as IE will look to see if the cert has been revoked and have to wait $timeout seconds to find out that it can't...would hope lightspeed have a CRL category you can allow?
Posted
Is lightspeed blocking access to the CRLs you need? That could slow things down as IE will look to see if the cert has been revoked and have to wait $timeout seconds to find out that it can't...would hope lightspeed have a CRL category you can allow?

This was happening at home for me.

  • 1 month later...
Posted
@bodminman Do you use Office 365 with Outlook and are you using HTTPS decryption on the Rocket? I.e Is the Rocket acting as a proxy server?

@Edu-IT - As a school we don't use Outlook although I do have it configured on my machine.

 

The Rocket is not acting as a proxy server but we do have the 'Decode SSL Certs' option enabled under Web Filter/General.

Posted
Do you have any problems with Outlook on it, such as Mailtips not working? I suspect not if you aren't using it as a proxy as I don't think it decrypts SSL in non proxy mode which is where I think the issue is.
Posted
Do you have any problems with Outlook on it, such as Mailtips not working? I suspect not if you aren't using it as a proxy as I don't think it decrypts SSL in non proxy mode which is where I think the issue is.

 

Nah, outlook works fine tbh but during our trial when we did have it setup as a proxy I couldn't get outlook to connect at all. However I was assured that all would be fine when it's inline.

  • 5 weeks later...
Posted

Sorry to drag this up again but I want to update you where I'm up to!

 

Basically I have found the cause and would like some advice on implementing the cure!

 

When I run 'netsh winhttp show proxy' the result shows our old proxy server/port. This info is visible within IE but not enabled.

 

When I run 'netsh winhttp reset proxy' (settin git to 'Direct Access')browsing the web works as normal and we have now issues at all, even with 'Check for server certificate revocation' enabled.

 

How can I set the machines to do the 'netsh winhttp reset proxy' without me having to go around them all manually? Startup script?

 

Thanks

Posted
If the info shows in IE but is not enabled, do you know what's populating it? Something GPO based? Could you do a GPP with the info cleared (or set to new proxy server/port) and disabled maybe rather than script?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...