Jump to content

Machines Cannot get Web but network access is fine.


Recommended Posts

Posted

Hello,

 

We have a small outreach centre a couple of miles away from our main campus. it has a Read-Only DC. Network traffic comes back to the main site. Web traffic goes through a PFsense box.

 

yesterday everything worked fine. This morning, users have come in to find that although they are still getting the network (emails, shared drives, printing, etc) they cannot browse the web.

 

I've connected into the local DC and run a tracert to google. This works fine.

 

Proxy settings are disabled by default and I've asked one of the staff to double check they are indeed, switched off. I've gone through the GPOs that I believe are affecting the machines and they are set to allow automatic configuration.

 

Any ideas?

 

Thanks in advance.

Posted
Points to an issue with the Router on the remote site to me, I guess the clients have their default gateway set to the Remote site router and their DNS points to the Domain Controller?
Posted
Thanks for the replies guys. We've ended up diverting the WAN gateway straight through the existing LAN connection which has got the users back on their feet.
Posted
Thanks for the replies guys. We've ended up diverting the WAN gateway straight through the existing LAN connection which has got the users back on their feet.

 

Youve done what now ? Care to elaborate ?

  • Thanks 1
Posted (edited)

Well, we didn't really 'fix' the issue per se.

 

As I said in my original post the outreach centre had a bit of an odd set up. No idea why, it may have been that the previous techies were given five minutes notice to get a working solution up and running (par for the course at our place.)

 

Bear in mind there is a single router at the remote site. It has connections back to our firewall on the main campus.

 

Traffic to our network (emails, printers, share drives, etc) comes straight back to our main site. This was working. This was labeled as LAN.

 

Web traffic e.g. Facebook, education sites...anything else was going straight out to the web. This wasn't working. Browser would cogitate for a while then issue a connection error warning. This was labeled as WAN (again, I don't know why) Tracert would work fine, annoyingly.

 

We have a second outreach centre elsewhere and they had the exact same issue, it turns out. Possibly something got changed in our FW rules... I know somebody has been working on them.

 

The centre runs a lot of online tests each week. We were looking at the staff having to give up their Saturday's to keep up with client demand. They had already been out of action for a day and a half at this point. Also, we became concerned that web traffic wasn't being filtered so changing things to work this way seemed the right thing to do anyway.

 

So we simply pointed the web traffic down the same VPN route to the network as the other network traffic.

Edited by Zoatibix
Posted (edited)

Possible someone changed or removed a rule without knowing. While it's fresh in your mind it would be a good idea to document it ;) .

 

Our Firewall was externally managed up till recently so just got access to it, there is a lot of cleaning up to be done and may well break something we don't know about yet if it's not labeled appropriately and we can't see what it is for, old email servers etc. :peep: .

Edited by Davit2005
Posted
yeah, ours has lot of potentially useless stuff on it. Quite possible that something important wasn't labeled as it should have been and got chopped. I mean last week I found an entire Server 2012 backup server running DPM that I didn't even know we had sitting in a server room labeled as whatever it had been in a previous 'life' :D

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...