CyberDrac Posted September 23, 2014 Posted September 23, 2014 Over the last few months we have become aware of increasing number of laptops, used by staff at home, which are experiencing exceptionally slow Internet access. By exceptionally slow, we're talking about 40 minutes to open a webpage if it doesn't time out during that period and fail completely. These machines have previously been in use for over a year prior to the start of these issues. Our principle browser is Internet Explorer, however the results have been replicated in Google Chrome and Mozilla Firefox. Initial thoughts have been that the proxy settings were affecting it, however only Internet Explorer and Google Chrome use the GPO configured settings, Firefox was free of any GPO influence and suffered the same fate despite having the flexibility to experiment with the proxy settings. The proxy settings are to use a proxy.pac file served up by our smoothwall, my understanding is that in the absence of the file it will simply default to having no proxy settings at home. Temporary respite can occasionally be achieved following a full software rebuild of the operating system and a deletion of the user's profile, however some simply aren't fixed by this and others it is fixed for only a short period of time. Now there is obviously a setting or configuration at fault here, there may be an update being applied having a side effect, it may yet be a proxy related issue, however sixth months down the line I am no closer to identifying the cause. Has anyone had anything similar occur, or feel able to offer some insight into the difficulties we're experiencing? Thanks in advance CD
robjduk Posted September 23, 2014 Posted September 23, 2014 Do you have any VPN/direct access at all as it sounds it is looking for a network resource? Anyway apart from that I suggest uninstalling an antivirus completely and testing it. I once had an issue a little like yours and it was not until I remove the AV over disabling it, the problem was cured. Good luck either way. 1
win Posted September 23, 2014 Posted September 23, 2014 Is it slow at home or on the domain (or both)? Here are a couple of suggestions: 1. the cliche malware/virus 2. change the DNS to google dns 8.8.8.8 (just for testing purposes) 1
CyberDrac Posted September 23, 2014 Author Posted September 23, 2014 Do you have any VPN/direct access at all as it sounds it is looking for a network resource?No VPN nor DirectAccess (although Direct Access look interesting) Anyway apart from that I suggest uninstalling an antivirus completely and testing it. I once had an issue a little like yours and it was not until I remove the AV over disabling it, the problem was cured. Good luck either way.I'll see if I can uninstall it without it automatically trying to re-install the cliche malware/virusI'd like to think that it isn't getting infected that fast, but I'll give them a good sweep change the DNS to google dns 8.8.8.8 (just for testing purposes)The staff profiles are locked down in a fashion that they can't be changed/viewed, I'd hope that their DNS entries are those that are handed out by the DHCP on their home router, but I'll see if there is a way of checking through other routes ... good thoughts keep them coming
win Posted September 23, 2014 Posted September 23, 2014 Perhaps lend them a network cable and tell them to plug it directly into the router (also ask them to reboot it) - could be their wireless. Better yet, ask if you can take one of the laptops home yourself and test it with your own home connection. If it works for you as administrator, you know it's their connection. 1
cpjitservices Posted September 23, 2014 Posted September 23, 2014 If I were you I'd be running the likes of Malwarebytes and Spybot / Combofix through those laptops sounds like they may be infected with something. May even run CCleaner on them see if there is anything stuck in cache. 1
mac_shinobi Posted September 23, 2014 Posted September 23, 2014 (edited) If I were you I'd be running the likes of Malwarebytes and Spybot / Combofix through those laptops sounds like they may be infected with something. May even run CCleaner on them see if there is anything stuck in cache. I would say this but if its across all domain laptops from the school that are using a direct broadband connection at peoples homes then am just curious on the pac file config as maybe need to double check and tweak the pac file to ensure that when the laptops are using a direct connection that the pac file is not trying to communicate with the schools proxy servers ( smoothwall or whatever ) ?? You could possibly as a test stop all the anti virus services to emulate the AV not running and see if that helps ( as above ) Just wondering if you have a spare laptop that you could image freshly and join to your domain with all the group policies etc applied to it and then use a direct connection from the laptop instead of going through your smoothwall and see if its the same, if so then at least that narrows what the issue(s) could be so obviously not going to be malware / viruses etc as it has been freshly imaged Also just curious if there are any errors in event viewer ? Also when you say they are taking them home , how are they connecting the laptop to there broadband router ie wireless or a network cable ? Any other thoughts @Arthur or @SYNACK ?? Edited September 23, 2014 by mac_shinobi
SYNACK Posted September 23, 2014 Posted September 23, 2014 I would look at the AV/firewall and get them to do a route print when at home along with a tracert to some slow sites. May need a couple of tech savey ones but may shed some light. 1
mac_shinobi Posted September 23, 2014 Posted September 23, 2014 I would look at the AV/firewall and get them to do a route print when at home along with a tracert to some slow sites. May need a couple of tech savey ones but may shed some light. Maybe a bat file that outputs the results to a text file which the user can email you ?
DMcCoy Posted September 23, 2014 Posted September 23, 2014 (edited) Is an automatic configuration script specified in Group Policy? Edit: I see it is, page loading with IE and Chrome will be very slow while it times out on the autoconfig for each page requrest. Edited September 23, 2014 by DMcCoy 1
CyberDrac Posted September 24, 2014 Author Posted September 24, 2014 Perhaps lend them a network cable and tell them to plug it directly into the router (also ask them to reboot it) - could be their wireless. Better yet, ask if you can take one of the laptops home yourself and test it with your own home connection. If it works for you as administrator, you know it's their connection.I tested last night with a admin account, and two staff accounts, in each case I was able to reproduce the issue, it can be consistently reproduced in Internet Explorer and Google Chrome on my home connection with 152mbit/20mbit. Typically google.co.uk takes in excess of ten minutes to appear and other more complicated pages take up to forty minute. I believe that I had tried it with a network cable on previous attempts, but I will try that again tonight if I can. If I were you I'd be running the likes of Malwarebytes and Spybot / Combofix through those laptops sounds like they may be infected with something. May even run CCleaner on them see if there is anything stuck in cache.Sophos says that they're clean, but I'll run them through another anti-Virus/ant-iMalware suite, and maybe throw CCleaner in for good measure. This has happened also on freshly re-built machines on their first evening home and so I'm hopeful that they aren't getting infected that quickly, but I won't rule anything out. I would say this but if its across all domain laptops from the school that are using a direct broadband connection at peoples homes then am just curious on the pac file config as maybe need to double check and tweak the pac file to ensure that when the laptops are using a direct connection that the pac file is not trying to communicate with the schools proxy servers ( smoothwall or whatever ) ?? You could possibly as a test stop all the anti virus services to emulate the AV not running and see if that helps ( as above ) Just wondering if you have a spare laptop that you could image freshly and join to your domain with all the group policies etc applied to it and then use a direct connection from the laptop instead of going through your smoothwall and see if its the same, if so then at least that narrows what the issue(s) could be so obviously not going to be malware / viruses etc as it has been freshly imaged Also just curious if there are any errors in event viewer ? Also when you say they are taking them home , how are they connecting the laptop to there broadband router ie wireless or a network cable ?Tried to uninstall Sophos last night but it wouldn't let me due to a lack of membership to 'Sophos Administrators' on any of the credential cached on the machine. My understanding of the automatic configuration option through proxy.pac is that if it can't find it, it will default to 'no proxy'. With the Mozilla Firefox installation I have the option to use fixed proxy settings (which I know won't work off site), system settings (so it should behave the same as Google Chrome and Internet Explorer, and it does), and no proxy (which doesn't improve matters). Bizarely my workplace's portal/vle is accessible at close to normal speeds and a Citrix Desktop session behaves beautifully. Most users connect via wireless, however I believe that we've sent a few home with cables before as well with no improvement, however as I said earlier, I plan to double check that again tonight. Is an automatic configuration script specified in Group Policy? Edit: I see it is, page loading with IE and Chrome will be very slow while it times out on the autoconfig for each page requrest.But would it do it for every page? or just the first time?
win Posted September 24, 2014 Posted September 24, 2014 This is a mystery. Other things to try: - Run a browser from a usb stick (e.g. chrome from portable apps) - Disable windows firewall - Try using tor - uninstall flash - install a virtual PC (or vmware) this will help determine hardware/software problem
mac_shinobi Posted September 24, 2014 Posted September 24, 2014 (edited) From services stop all the Sophos Services from running and try again Control Panel --> administrative tools --> Services or from a command prompt running as administrator ( right click on command prompt --> run as administrator ) or run or where it states search programs and files type services.msc and press enter / return and scroll down to Sophos and right click and stop all of the Sophos Services. Close down all instances of web browsers so IE / Chrome / Firefox etc and re launch and try again on a wired connection and a wireless connection Screen Grab from machine : If you need to get sophos started again just restart windows and the services should auto start again so you don't have to start them in any specific order with error messages etc Edited September 24, 2014 by mac_shinobi 1
sparkeh Posted September 24, 2014 Posted September 24, 2014 Bizarely my workplace's portal/vle is accessible at close to normal speeds and a Citrix Desktop session behaves beautifully. ^ This is what I find interesting. How is your VLE hosted? Just wondering if services hosted in school are working ok, which could lead me to suspect that something is trying to connect to a school hosted resource when the laptops are off network. 2
CyberDrac Posted September 24, 2014 Author Posted September 24, 2014 Mac_Shinobi ... I've cut through to the chase and simply uninstalled Sophos, so I'll test again tonight. How is your VLE hosted?We have an internally hosted SharePoint server a TMG Server to direct traffic to it, and internal DNS entries to ensure that during the working day on site the traffic is kept local, whereas off site regular DNS applies.
mac_shinobi Posted September 24, 2014 Posted September 24, 2014 (edited) Mac_Shinobi ... I've cut through to the chase and simply uninstalled Sophos, so I'll test again tonight. We have an internally hosted SharePoint server a TMG Server to direct traffic to it, and internal DNS entries to ensure that during the working day on site the traffic is kept local, whereas off site regular DNS applies. Is the PAC File hosted internally , if so then wondering if that is the issue ? I thought the pac file had to be hosted externally ?? Think that was what @sparkeh was getting at / saying due to them not being connected to VPN directly back into your school network ? Edited September 24, 2014 by mac_shinobi
CyberDrac Posted September 24, 2014 Author Posted September 24, 2014 The PAC file is hosted on our internal SmoothWall address and is defined through, I believe GPO. I believed that in the event that the specified file wasn't available (i.e. externally) that the default behaviour for a browser, specifically Internet Explorer, was to proceed as if no proxy information is entered.
sparkeh Posted September 24, 2014 Posted September 24, 2014 The PAC file is hosted on our internal SmoothWall address and is defined through, I believe GPO. I believed that in the event that the specified file wasn't available (i.e. externally) that the default behaviour for a browser, specifically Internet Explorer, was to proceed as if no proxy information is entered. If you use the url method then every single request that the the browser makes will attempt to run the script: Auto proxy configuration settings for Internet Explorer 11 Automatic proxy URL (.JS, .JVS, or .PAC file) box: Type the location of your automatic proxy script. This script runs whenever Internet Explorer 11 makes a network request and can include multiple proxy servers for each protocol type. We use the wpad method that doesn't have this problem. 1
mac_shinobi Posted September 24, 2014 Posted September 24, 2014 If you use the url method then every single request that the the browser makes will attempt to run the script: We use the wpad method that doesn't have this problem. How do you setup the wpad pac file method from scratch - I would like to know just out of curiousty from configuring the pac file script and how to implement the wpad method ?
CyberDrac Posted September 24, 2014 Author Posted September 24, 2014 I've been researching through the two links below ... https://techlib.barracuda.com/display/wsflexv41/how+to+configure+proxy+settings+using+pac+files+and+wpad Configure option 252 for a DHCP scope 1
sparkeh Posted September 24, 2014 Posted September 24, 2014 (edited) How do you setup the wpad pac file method from scratch - I would like to know just out of curiousty from configuring the pac file script and how to implement the wpad method ? There's a good guide here: About implementing WPAD But basic steps are to create a wpad file (basically the same as a pac file), put it on a server running IIS, add a DNS entry and DHCP option pointing to the file (some browsers use DNS, some use DHCP and some use both) and configure your browser to automatically detect the wpad file (in IE its the "Automatically detect settings" tick box). The advantage of this is that when you browse the web the browser tries to find the wpad file, if on site then it does and uses those settings, if you are at home it can't find it and carries on with a direct connection. It doesn't suffer the issue of continually trying to connect to the settings file. The only issue I have had with it is that when you alter the wpad file you have to wait for the clients to refresh the locally held copy (it caches it for a certain period you see). Edited September 24, 2014 by sparkeh 1
mac_shinobi Posted September 24, 2014 Posted September 24, 2014 Found this http://static.googleusercontent.com/media/www.google.com/en//support/enterprise/static/postini/docs/help_center/PAC_Guide_V.1.pdf
CyberDrac Posted September 26, 2014 Author Posted September 26, 2014 (edited) A Big Thank You to everyone who has contributed to this thread. If nothing else many of the suggestions made me challenge my pre-conceptions and assumptions about our existing configuration. Assumption 1 - that the WPAD was working, wrong Assumption 2 - that the proxy.pac entry wouldn't be used if the proxy.pac couldn't be seen to be downloaded from the internal network, wrong Resolution 1 - fixed the WPAD by adding the DHCP entries as well as the DNS entries which were already in place Resolution 2 - removed the proxy.pac entry from the GPO for users using the staff laptops (user configuration, setup for loopback, assigned to the machine's OU) The machines are behaving themselves better at home, I suspect that this will now open up a raft of new issues now that staff are working from home more, but thanks to everyone for your contributions. edit : when I'm feeling brave I'll experiment with removing the proxy.pac entry for the entire network and allow WPAD to do the job Edited September 26, 2014 by CyberDrac 1
andyturpie Posted September 26, 2014 Posted September 26, 2014 Give this a blast? http://www.onyxbox.co.uk/software/downloads/ps.htm 1
CyberDrac Posted September 26, 2014 Author Posted September 26, 2014 Give this a blast? http://www.onyxbox.co.uk/software/downloads/ps.htmThank you, our current solution means that this isn't necessary. We actually used that application on our CC3 network before we went vanilla and it did a great job.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now