Jump to content

Recommended Posts

Posted
8 minutes ago, toffee_paul said:

Following a call with Smoothwall they believe it to be an issue with DNS. Upon changing the DNS forwarders to Google's (8.8.8.8 / 8.8.4.4) on our on-prem appliance, access to Arbor is now working fine.

 

May be worth changing yours temporarily and see if it makes a difference.  @5nowman you mentioned you're on BT Fibre so maybe your issue is different as you mentioned slowness rather than an out-and-out inability the resource itself.

 

Thanks to Alan @ Smoothwall for highlighting this.

Thank you for your reply. 

 

8.8.8.8 tested already.

Is 8.8.4.4 another google DNS?

Infact smoothwall redirects to that.

 

 

Posted

There's nothing we have particularly changed.

One of our 3rd line support engineers suggests there's an issue with virgin's DNS (he referenced this thread, I presume he's working on that ticket, I have been in meetings all aft and not looked jsut yet).

I also have a whatsapp from one of our more technically adept partners who suggest that they had a similar issue, and that was down to using cloudflare's DNS over google's. 

 

Posted

@5nowman Smoothwall doesnt redirect to anything - it will use the DNS resolvers you tell it to use. 8.8.4.4 is the secondary to 8.8.8.8. You can also try quad9s (9.9.9.9) as an alternative, although that's a PDNS so will sometimes block stuff

 

Edit - if you have a ticket # I can ask one of our engineers to take a look at yours in the same way as Alan did for @toffee_paul

Posted

FWIW I get a minimum 5 second delay getting to gb6.behaviourwatch.co.uk - this is through a non-smoothwall connection, and consistent over multiple runs
image.thumb.png.e25a3c95f62344571e101a0ec5ae621e.png

Posted
13 minutes ago, tom_newton said:

There's nothing we have particularly changed.

One of our 3rd line support engineers suggests there's an issue with virgin's DNS (he referenced this thread, I presume he's working on that ticket, I have been in meetings all aft and not looked jsut yet).

I also have a whatsapp from one of our more technically adept partners who suggest that they had a similar issue, and that was down to using cloudflare's DNS over google's. 

 

see i have a ticket open currently about this issue referencing this thread in the ticket.

 

is there a fix for it yet?

Posted

@SeeFights there isn't a Smoothwall problem in this thread as I see it so far: happy for you to DM me your ticket number.
 

The arbor/raven issue is 100% DNS. 

The behaviourwatch issue is, to my mind, a behaviourwatch problem.  I am seeing ~15 seconds to download a tiny gif from their site.

Posted
Just now, tom_newton said:

@SeeFights there isn't a Smoothwall problem in this thread as I see it so far: happy for you to DM me your ticket number.
 

The arbor/raven issue is 100% DNS. 

The behaviourwatch issue is, to my mind, a behaviourwatch problem.  I am seeing ~15 seconds to download a tiny gif from their site.

with it being a dns issue it sounds like its my bosses issue *insert devious smile*

 

im fine waiting for whoever at smoothwall gets to me its eod for us now :D

Posted

OK, I find from different ISPs behaviourwatch has no issue. 

My home Andrews and Arnold is horror, from one of our boxes in google cloud, no worries.

Suspect they have routing issues

Posted (edited)
4 minutes ago, tom_newton said:

If you could lay out your exact issue here  @SeeFights or DM me a ticket I might take a stab at working out the issue

So its pretty much the same issue as the start. Arbor on some machines tries to contact https://cdn.ravenjs.com/3.16.1/raven.min.js - Fails then returns a 403.

 

I have tried forcing a chrome refresh, i have reinstalled windows and that wont work, i have tried it on a different wifi (one that bypasses smoothwall) and that doesnt work, i have tried it with the proxy off and that doesnt work. even uninstalling chrome and reinstalling doesnt work. Edge also doesnt work, im not permitted to try firefox so not sure with that.

 

oh and not to mention, it only affects a handful of people - if it was dns it would affect everyone no?

Edited by SeeFights
Posted

Additionally different people use different DNS servers (most folk just use their ISP) and you get to a different DNS server based on your location due to the anycast nature of their IPs (8.8.8.8 for me is not the same endpoint as it is for you).

 

I would strongly suggest going to 8.8.8.8 in your Smoothwall's DNS page, see if that sorts it. Or it might be upstream DNS in your AD if you are AD and transparent proxy.

Posted
1 minute ago, tom_newton said:

Additionally different people use different DNS servers (most folk just use their ISP) and you get to a different DNS server based on your location due to the anycast nature of their IPs (8.8.8.8 for me is not the same endpoint as it is for you).

 

I would strongly suggest going to 8.8.8.8 in your Smoothwall's DNS page, see if that sorts it. Or it might be upstream DNS in your AD if you are AD and transparent proxy.

sorry guys so much of that made no sense to me. im not trained in network troubleshooting 

Posted
1 minute ago, tom_newton said:

OK, we are almost certainly at that level - is there someone who is a DNS wrangler in your school?

my network manager (my boss) just walked in and is going to change the dns to googles.

  • Like 1
Posted (edited)
12 minutes ago, tom_newton said:

OK, we are almost certainly at that level - is there someone who is a DNS wrangler in your school?

its dns. it makes no sense but it works.
Good old Sysadmin joke

Edited by SeeFights
  • Like 1
Posted
1 hour ago, tom_newton said:

FWIW I get a minimum 5 second delay getting to gb6.behaviourwatch.co.uk - this is through a non-smoothwall connection, and consistent over multiple runs
image.thumb.png.e25a3c95f62344571e101a0ec5ae621e.png

5 seconds?!?

 

That is long! The page has loads of objects and if there js a 5 second delay that could be it!

 

What isp are you testing it from?

Posted

OK, it is devinitely a DNS issue for me with behaviourwatch, although whatever I tell curl to use doesnt help, if I do the resolution manually it is lightening fast

 

image.thumb.png.6308a1e61397b411d3101bdeab1aebf0.png

Posted

This isn't just for Arbor, we saw this last week with Instagram when unblocking, and changing DNS on the box resolved it for us as well. However, we changed it to 1.1.1.1 - from Googles, and then it worked. 

Posted
3 hours ago, tom_newton said:

@5nowman Smoothwall doesnt redirect to anything - it will use the DNS resolvers you tell it to use. 8.8.4.4 is the secondary to 8.8.8.8. You can also try quad9s (9.9.9.9) as an alternative, although that's a PDNS so will sometimes block stuff

 

Edit - if you have a ticket # I can ask one of our engineers to take a look at yours in the same way as Alan did for @toffee_paul

thank you . will DM you the ticket number. Are we saying different ISPS are having different delay times?

Posted
42 minutes ago, 5nowman said:

thank you . will DM you the ticket number. Are we saying different ISPS are having different delay times?

It's not your ISP, it's your chosen DNS. Although, it doesn't really make sense, as I have seen it work on Google DNS one minute, and then not on Cloudflare, and then vice versa. Almost like changing the DNS in SW refreshes some cache or something 

Posted (edited)
4 hours ago, ConceroEdu_Matt said:

It's not your ISP, it's your chosen DNS. Although, it doesn't really make sense, as I have seen it work on Google DNS one minute, and then not on Cloudflare, and then vice versa. Almost like changing the DNS in SW refreshes some cache or something 

Have had such a horrible time with this all week with behavourwatch smoothwall etc.

Support has been decent from the ISP and behaviourwatch however neither could find the fault. Escalted to smoothwall direct today. I checked on our smoothwall 

5 hours ago, ConceroEdu_Matt said:

This isn't just for Arbor, we saw this last week with Instagram when unblocking, and changing DNS on the box resolved it for us as well. However, we changed it to 1.1.1.1 - from Googles, and then it worked. 

our smoothwall is set to: 1.1.1.1, 8.8.8.8, 9.9.9.9   which seems ok right....

Edited by 5nowman

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...