Sheridan Posted January 18, 2011 Posted January 18, 2011 Has anyone got Channel4 OD working through their filtering system? We're using Smoothwall and it doesn't seem to be blocking anything, yet we get the connection timeout error on everything we try and play. I've searched through the posts here and there seems to be have been issues with 4od through a proxy server but I'm wondering if this had changed?
tom_newton Posted January 18, 2011 Posted January 18, 2011 You may need to open port 1935 (on your firewall, smoothwall or otherwise) as it uses RTMP...
Sheridan Posted January 19, 2011 Author Posted January 19, 2011 Ahh right, sounds like it might be an LEA issue then
Sheridan Posted January 20, 2011 Author Posted January 20, 2011 Can anyone else get 4od working ok in their network? Can't see why it won't work here.
HallX Posted January 20, 2011 Posted January 20, 2011 Can you connect a laptop with a direct feed to the LEA?
HallX Posted January 20, 2011 Posted January 20, 2011 I can confirm with Tom, our ISA has a rule to allow port 1935 for 4oD. Hope this helps. Paul
Sheridan Posted January 20, 2011 Author Posted January 20, 2011 Hmm, all our web traffic hits a Smoothwall box, and everything else hits and ISA. Can't see 1935 being blocked anywhere here!
HallX Posted January 20, 2011 Posted January 20, 2011 Can you connect a laptop with a direct feed to the LEA? This will confirm if it's you or the LEA, I'd try this before doing anything else. Paul edit - I can't remember whether or not we had to get our LEA to unblock this.
Sheridan Posted January 20, 2011 Author Posted January 20, 2011 This will confirm if it's you or the LEA, I'd try this before doing anything else. Paul edit - I can't remember whether or not we had to get our LEA to unblock this. Unfortunately not - all web traffic is only allowed via the Smoothwall box. Everything else (through the ISA) is only for access to LEA local systems (coporate networks)
Sheridan Posted January 20, 2011 Author Posted January 20, 2011 Is there any way of checking if Smoothwall is passing requests out over that port (1935)?
tom_newton Posted January 20, 2011 Posted January 20, 2011 Sounds like you are using smoothwall just as a web proxy - in which case 1935 won't be hitting it - and its either your gateway (I assume ISA) or the LEA...
Sheridan Posted January 21, 2011 Author Posted January 21, 2011 Actually it looks like I'm a bit scuppered on this. All of our clients use a central router as their gateway and have the Smoothwall box as their web proxy. Any non-http traffic that hits the router is forwarded on to the LEA's internal servers (via an ISA box which uses NAT) if it matches a particular IP address/range that relates to an LEA one. Everything else would be dropped by the router. So I can't get Windows clients to use the Smoothwall box for port 1935 access, and I don't think the router will allow me to route based on remote port type, plus the range of IP addresses Channel 4 use is varied so I can't route based on IP address or range! I can't think of anthor way around this unless someone has a better idea?
box_l Posted February 2, 2011 Posted February 2, 2011 sorry to derail to ISA but: @Hallx Could you please provide me with the rule/s you are using in ISA. I have tried many times, with no luck so far. Adverts play but no content. TIA BoX
HallX Posted February 2, 2011 Posted February 2, 2011 @box_l I created a User Defined protocol called 4oD. I've attached a .bmp of the parameters. I then created a rule allowing protocol for all users anytime from internal to external. Hope this helps. 2
box_l Posted February 2, 2011 Posted February 2, 2011 Many thanks for that. I had an identical setup, except for the fact that I tried TCP first and the UDP, not both at the same time. I'll report back after testing. BoX
markberry Posted January 30, 2012 Posted January 30, 2012 (edited) Did you manage to get this working through Smoothwall? I'm currently trying to get it working through our new box and am having a little trouble. I'm getting some URLs denied and can't seem to get them to go through. I've added them to an allowed filter list and also a list to bypass https interception but they are still blocked. I've attached a pic of the blocked URLs. ATTACH=CONFIG]12854[/ATTACH] Edited January 30, 2012 by markberry
markberry Posted January 30, 2012 Posted January 30, 2012 Yes I have. I've added to an allowed content list so it is not checked by content filters. I've also added it to a second list so that it is not checked by the HTTPS inspection policies.
andyrite Posted January 30, 2012 Posted January 30, 2012 Theres a KB on this. https://support.smoothwall.net/index.php?_m=knowledgebase&_a=viewarticle&kbarticleid=382&nav=0,4 I'll install it here and have a look if you are having trouble still. Andy 1
DT2 Posted January 30, 2012 Posted January 30, 2012 Did you manage to get this working through Smoothwall? I'm currently trying to get it working through our new box and am having a little trouble. I'm getting some URLs denied and can't seem to get them to go through. I've added them to an allowed filter list and also a list to bypass https interception but they are still blocked. I've attached a pic of the blocked URLs. ATTACH=CONFIG]12854[/ATTACH] Mark, you're still being blocked by the core blocked content rule as audio and video (http policy 5). you'll need to sort that out first bud. Darren
mwbutler Posted January 30, 2012 Posted January 30, 2012 Theres a KB on this. https://support.smoothwall.net/index.php?_m=knowledgebase&_a=viewarticle&kbarticleid=382&nav=0,4 I'll install it here and have a look if you are having trouble still. Andy Copying and pasting all of those into our SWGFL filtering system fixed the issue for us last year. Don't think we had to make any changes on our Smoothwall box.
markberry Posted January 30, 2012 Posted January 30, 2012 Mark, you're still being blocked by the core blocked content rule as audio and video (http policy 5). you'll need to sort that out first bud. Darren I've disabled the audio/video filtering from the 'Core blocked content'. I am now still getting the 'Forbidden (403)' errors for https://cp53221.edgefcs.net:80 and https://cp53221.edgefcs.net:1935
DT2 Posted January 30, 2012 Posted January 30, 2012 (edited) I've disabled the audio/video filtering from the 'Core blocked content'. I am now still getting the 'Forbidden (403)' errors for https://cp53221.edgefcs.net:80 and https://cp53221.edgefcs.net:1935 On the UTMs or the SWG3600? DT Edited January 30, 2012 by DT2
markberry Posted January 30, 2012 Posted January 30, 2012 On the SWG-3600. We don't use the UTMs at the moment. The SWG connects to the LEA proxies.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now