pete Posted April 3, 2019 Posted April 3, 2019 (edited) Would people using Smoothwall mind testing https://my.dynamic-learning.co.uk and posting results, because this is odd. On a phone using 4G, https://my.dynamic-learning.co.uk works correctly Via Smoothwall (filtered or unfiltered, HTTPS interception or no HTTPS interception) it doesn't. The policy tester in SW falls over with a generic "internal error during SSL handshake" error. Downforeveryoneorjustme.com says the site's down. Google's page speed test can talk to it without any issues. Their server config looks correct (via SSLLabs) and they're not using HSTS. The error message we get internally appears to relate to HTTPS (secure connection failed), but testing clients here (https://www.ssllabs.com/ssltest/viewMyClient.html) we're clean. Internal DNS returns the same IP address for the server as external DNS does, so we're hitting the same load-balancer/server. Results are similar across all browsers Edited April 3, 2019 by pete
pete Posted April 4, 2019 Author Posted April 4, 2019 OK, via another Smoothwall on the same RBC it's accessible, so it's something on our end (as opposed to RBC/SW) and a direct (no proxy whatsoever) connection works.
AndrewYoward Posted April 5, 2019 Posted April 5, 2019 OK, via another Smoothwall on the same RBC it's accessible, so it's something on our end (as opposed to RBC/SW) and a direct (no proxy whatsoever) connection works. Hi Pete, I have had the guys check it here. It works here with SSL inspection on as well. If you need to log it, just send an email to [email protected] and we will be able to help you out further. You can also use our Live Chat function by clicking on the Help bubble at https://smoothwall.com/support/ Let me know if you need anything further.
pete Posted April 5, 2019 Author Posted April 5, 2019 ^ I'll probably give you guys a shout if I can't get SW to spit out a decent reason why. I'm leaning towards "Squid's doing something daft" at the moment (given unfiltered + https interception off also can't access the site). According to the users, it was working a couple of weeks ago and I haven't altered the configuration beyond blocking a couple of unrelated sites since then.
ibpalle Posted April 8, 2019 Posted April 8, 2019 This could be a load balancer issue - see this thread. http://www.edugeek.net/forums/smoothwall-direct-support/197149-tls-handshake-server-failed.html
pete Posted April 15, 2019 Author Posted April 15, 2019 This could be a load balancer issue - see this thread. http://www.edugeek.net/forums/smoothwall-direct-support/197149-tls-handshake-server-failed.html Sorry, had the week off. I read through that and I'll try clearing the cert cache (already not caching or intercepting the domain). Does SW/Squid still do funky thinks with certs if HTTPS Interception/checking is turned off for a domain?
ibpalle Posted April 15, 2019 Posted April 15, 2019 (edited) Hi Pete The cert error could be on the server side, not the Smoothwall side. Result is the same though. As mentioned in the thread, remove https inspection for the domain and a restart of the proxy with cleared cache may also be needed after that as well. Ups, forgot to add - No, when HTTPS inspection is turned off, the proxy does not check certs. Edited April 15, 2019 by ibpalle
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now