kennysarmy Posted July 24, 2020 Author Posted July 24, 2020 Ah yes, I saw that issue too.. was a bit baffling. Are you able to rule out the smoothwall by bypassing it? I've brought a pc home and can't replicate the issue. On first turn on it briefly showed the globe icon but that quicky turned to the normal network icon. Currently trying to see if I can break it to replicate the issues I see at work If not the next call might be too RM / SWGFL to see if they can set up a port on our router with no filtering or firewall rules. I don't think the smoothwall is the issue, as the normal proxy is only set by a user group policy. I'm still unsure though what effect the winhttp proxy setting has with respect to the globe or network icon showing machine has internet or not. Sometimes very frustrating not to come from a background in networking....
kennysarmy Posted July 24, 2020 Author Posted July 24, 2020 When this PC was still at work and I had the "globe" issue at the logon screen I logged on and it remained in the sys tray instead of the normal network icon. I tried to do a trace route and this was the result... I could still PING though ! And I had internet via the browser. Seconds later the globe turned in to the normal network icon.
DGardiner Posted July 25, 2020 Posted July 25, 2020 (edited) found a few threads online saying its probing http://www.msftncsi.com to check connectivity and whitelisting should resolve this? also https://mspoweruser.com/windows-10-kb4535996-limited-internet-bug/ ? Edited July 25, 2020 by DGardiner 1
Michael Posted July 25, 2020 Posted July 25, 2020 I can try but without a proxy entry of either the smoothwall or the swgfl proxy I won't have any internet access through the browser. Also, the issue is affecting the PC's before anyone is even logged on. This is very frustrating. I'm going to re-image a PC on Monday and see if we can recreate the behaviour before we do any of our post image tasks or install any software or move the PC to the correct OU. In that case, may I suggest you install the latest July 2020 patch for Windows? Even if devices cannot connect to the internet, they can still connect to WSUS.
free780 Posted July 25, 2020 Posted July 25, 2020 (edited) Allow http://www.msftncsi.com and http://www.msftconnecttest.com unauthenticated and with no SSL interception. It needs to be accessible at machine level. Years ago I heard of people putting a DNS entry for the domain in their environment and putting the text file on a webserver as a test on a network with no outbound Internet access. http://www.msftncsi.com/ncsi.txt http://www.msftconnecttest.com/connecttest.txt Edited July 25, 2020 by free780
patpat22 Posted July 25, 2020 Posted July 25, 2020 There was an issue a few months ago. The easiest/quickest fix was to remove the explicit proxy so you connect in transparent mode. I was about to say exactly that. This should work out for you.
kennysarmy Posted July 25, 2020 Author Posted July 25, 2020 found a few threads online saying its probing http://www.msftncsi.com to check connectivity and whitelisting should resolve this? also https://mspoweruser.com/windows-10-kb4535996-limited-internet-bug/ ? Hey just checking in on the thread over the weekend. I'll add the whitelist to our smoothwall, my first thought though is if this is blocked why is it ok some of the time? Also I'm still confused as to how this can be a smoothwall filtering issue if it's showing a globe stating no internet at the login screen before our user GPO sets the proxy.
LeMarchand Posted July 25, 2020 Posted July 25, 2020 Also I'm still confused as to how this can be a smoothwall filtering issue if it's showing a globe stating no internet at the login screen before our user GPO sets the proxy. IIRC the "can I get to t'internet" check is done at system level, hence the suggestions above about the winhttp settings.
kennysarmy Posted July 26, 2020 Author Posted July 26, 2020 I had a thought this morning to shutdown the smoothwall and see if this affects all the windows 10 newly images PC's, thus proving if the smoothwall could be the source of the blockage.
kennysarmy Posted July 27, 2020 Author Posted July 27, 2020 OK so I came in this morning and did the following: Disconnected the smoothwall filtering device from the LAN It appeared to make no difference, on reboot some imaged PC's showed the globe and some the network icon (with internet) By logon all showed the LAN icon with "internet access" - I could n't at that time get any to show the globe issue (annoyingly intermittent) I also (with the smoothwall disconnected) changed the WinHTTP to a dummy address using: netsh winhttp set proxy proxy-server="http=dummy.co.uk:8080;https=dummy.co.uk:8080" Once logged on the LAN icon again showed with "internet access" Does this prove the device's routing is straight to the SWGfL router, bypassing the smoothwall and ignoring the winhttp proxy? Is this something to do with the DNS settings and routing on my core switch?
kennysarmy Posted July 27, 2020 Author Posted July 27, 2020 IIRC the "can I get to t'internet" check is done at system level, hence the suggestions above about the winhttp settings. Do you know if this is done on every restart?
Steve21 Posted July 27, 2020 Posted July 27, 2020 Kenny I did mention it a few pages back but you aren’t supposed to be using http/https settings anymore, that was the old legacy proxy settings for clients, not for system access Try setting the proxy-server direct to the sslfilter etc Or post a screenshot of the current winhttp settings as it’ll show what it’s using Steve
LeMarchand Posted July 27, 2020 Posted July 27, 2020 Do you know if this is done on every restart? I thought so, but... Kenny I did mention it a few pages back but you aren’t supposed to be using http/https settings anymore, that was the old legacy proxy settings for clients, not for system access ...I'm probably wrong!
kennysarmy Posted July 27, 2020 Author Posted July 27, 2020 Kenny I did mention it a few pages back but you aren’t supposed to be using http/https settings anymore, that was the old legacy proxy settings for clients, not for system access Try setting the proxy-server direct to the sslfilter etc Or post a screenshot of the current winhttp settings as it’ll show what it’s using Steve Hi, Sorry if I missed or misunderstood your message, I'll get there I've just turned on a freshly imaged PC from last week and it's showing the globe (so the device cannot get on the internet) I've logged on as an admin and here are the results for winhttp: C:\windows\system32>netsh winhttp show proxy Current WinHTTP proxy settings: Proxy Server(s) : http=rubbish:8080;https=rubbish:8080 Bypass List : (none) Once I'm logged on I get the standard LAN connected icon (with internet)! (As part of the user group policies applied, one sets the proxy for IE etc to our smoothwall address) On another PC that seems to be showing the LAN connected with internet access at logon screen reliably I logged in and changed the winhttp proxy to a dummy address, after each reboot the LAN icon with internet access was showing...
kennysarmy Posted July 27, 2020 Author Posted July 27, 2020 On the telephone with RM... Call time currently 1hr 28. He's working on filtering and firewall rules. He can see the issue first hand so.... Everything crossed currently!
Steve21 Posted July 27, 2020 Posted July 27, 2020 (edited) To rephrase my last post as was on phone so tried to do it shorter, basically it works in 3 steps DNS query against - http://www.msftconnecttest.com HTTP Get against - http://www.msftconnecttest.com/connecttest.txt DNS query against - dns.msftncsi.com All 3 of these need to pass for it to get a successful connection, so by default you should have the below two in your filtering/bypasses *.msftncsi.com *.msftconnecttest.com However, in regards to my comment about WINHTTP, my point was that the way you're setting http/https separately was for user based proxies in previous OS's, for Win10 you should only need a single proxy set on the client e.g. proxy-server="sslfilter.swgfl.org.uk:8080" Doing it the legacy way, splitting HTTP/HTTPS/FTP/SOCK5 etc doesn't work in WinHTTP anymore (afaik, if anyone wants to clarify?), I've always just used the single proxy setting, which then will bypass the Smoothie and only be affected by RM/SWGFL filtering which should have both of those whitelisted anyway (Now as a last point, but I assume this was checked earlier in your comments, unless you've disabled activeprobing etc via GPO for any reason? ) Steve Edited July 27, 2020 by Steve21 1
kennysarmy Posted July 27, 2020 Author Posted July 27, 2020 To rephrase my last post as was on phone so tried to do it shorter, basically it works in 3 steps DNS query against - http://www.msftconnecttest.com HTTP Get against - http://www.msftconnecttest.com/connecttest.txt DNS query against - dns.msftncsi.com All 3 of these need to pass for it to get a successful connection, so by default you should have the below two in your filtering/bypasses *.msftncsi.com *.msftconnecttest.com However, in regards to my comment about WINHTTP, my point was that the way you're setting http/https separately was for user based proxies in previous OS's, for Win10 you should only need a single proxy set on the client e.g. proxy-server="sslfilter.swgfl.org.uk:8080" Doing it the legacy way, splitting HTTP/HTTPS/FTP/SOCK5 etc doesn't work in WinHTTP anymore (afaik, if anyone wants to clarify?), I've always just used the single proxy setting, which then will bypass the Smoothie and only be affected by RM/SWGFL filtering which should have both of those whitelisted anyway (Now as a last point, but I assume this was checked earlier in your comments, unless you've disabled activeprobing etc via GPO for any reason? ) Steve That could be very useful information for the RM engineer looking in to this. I'll pass on your post information.
paulellam Posted July 27, 2020 Posted July 27, 2020 The only time this happens to me is when a new user logs in, they have to open IE first and that then sets the proxy for the other browsers, its random thing so does not affect every user and is more frequent in W10, probably due the proxy gpo not kicking.
kennysarmy Posted July 27, 2020 Author Posted July 27, 2020 The only time this happens to me is when a new user logs in, they have to open IE first and that then sets the proxy for the other browsers, its random thing so does not affect every user and is more frequent in W10, probably due the proxy gpo not kicking. So do you have a LAN connected or GLOBE icon before a user logs on?
kennysarmy Posted July 27, 2020 Author Posted July 27, 2020 So RM are scratching their heads a bit. I've just turned on 11 PC's imaged last week and ten are fine and 1 is showing the globe at the logon screen. I know when we hit the SWGfL proxies it's pot luck which one you hit so I do suspect some kind of upstream filtering or proxy issue as that would explain why it appears to be random at our side...
Boredguy Posted July 27, 2020 Posted July 27, 2020 Well if its any help @kennysarmy I don't have msftconnecttest.com in our SWGfL Safetynet list and the only time we ever get the globe icon is when the network cable is disconnected on the station. All our stations pick up the transparent proxy at SWGfL by default, and the users get the userbased sslfiltered proxy assigned once they log on. We don't use smoothwall. 1
kennysarmy Posted July 27, 2020 Author Posted July 27, 2020 Issue continues. So frustrating. Machines that would not shake off the globe last Friday are now fine. Machines that would not shake off the globe this morning now appear fine. Two identical machines imaged on Friday and booted up today; both have a globe at logon screen, one keeps the globe after logon and the other gives the correct LAN icon after logon.
kennysarmy Posted July 28, 2020 Author Posted July 28, 2020 Contacted Microsoft and arranged a call back for later in the week...in the meantime RM still looking in to it. May take another PC home tonight that's playing up to again prove the issue is not with the device... Can't think of anything else to try at this stage.
Michael Posted July 28, 2020 Posted July 28, 2020 Contacted Microsoft and arranged a call back for later in the week...in the meantime RM still looking in to it. May take another PC home tonight that's playing up to again prove the issue is not with the device... Can't think of anything else to try at this stage. On a problematic machine, can you manually install the July 2020 patch?
kennysarmy Posted July 28, 2020 Author Posted July 28, 2020 On a problematic machine, can you manually install the July 2020 patch? Just to be sure, you mean this one? https://answers.microsoft.com/en-us/windows/forum/all/cumulative-updates-july-14th-2020/efd89faa-cb15-4a15-9692-960866afeb94
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now