Jump to content

Recommended Posts

Posted (edited)

On our smoothwall we gets sites that just don't render correctly - as if their css file was missing. When this happens checking the web log shows nothing being blocked and the site isn't specifically mentioned in our rules

 

In fact, the live web log view shows 'ok' for the url as the user views it - except the site is rendered messily (i.e menus don't work, image aligned incorrectly etc)

 

If I put a top level allow rule for this site it generally works, but why? How can I tell what is being blocked by the smoothwall box when nothing is showing in the logs?

 

I've also noticed that some sites webcam streams fail in the same way - the webcam times out but nothing is showing as being blocked?

Edited by Sheridan
Posted

I had a similar issue with sites not loading properly which was very frustrating for my ICT department when they were teaching about web design! I found that it was a content security policy that was restricting it... I would remove all content security on a test login and slowly re-instate each security category of that polciy until you find the offending one... I just cheated and switched off most of it and i haven't had any issues...

 

Very frustrating that the logs don't show the site being blocked by that policy...

 

Hope it helps...

  • Thanks 1
Posted (edited)

I'll check that out - I've got the default set of security rules enabled.

 

Problem with the webcam seems to be its bypassing Smoothwall (ie. using a seperate protocol), but I can see any failed access on the firewall.

 

Edit: Its an odd one this. It seems like the webcam uses Adobe Flash (which I believe is RTMP on port 1935), now I have a rule on our ISA box to allow RMTP out directly but it doesn't appear to be blocked by smoothwall, nor hitting the isa box. I can't tell what IE is trying to do with the stream?

Edited by Sheridan
Posted

One to watch - the log viewer has an "ignore filter" - most of the time you don't want to see the reams of css and javascript. Turn off the ignore filter, and add another one (eg. domain filter) to keep the results manageable, and you should see the things you're blocking.

 

As for webcams.. could be RTSP.. or RTMP 554 and 1492 i think

Posted

It seems it was the security rules that caused the 'mangling' - the CSS cross scripting rule seems to be the culprit.

 

As for the webcams, I can't see anything hitting the firewall that is RTMP (1935) or RSTP (554) at all, very odd. Channel4 OD uses RTMP and that works fine.

Posted
I've had to admit defeat on this webcam problem. The webcam stream is an Adobe Flash Player one. The smoothwall box isn't blocking anything that I can and nothing is hitting the firewall when the client is trying to connect. The smoothwall box shows lots of traffic to the webcam site but nothing being denied whereas the firewall shows nothing so I'm guessing its using port 80/443.
Posted

Sheridan is tired!

 

I ran Wireshark and it simply shows a lot of access to the smoothwall proxy - and nothing else to an external ip as far as I can see.

Posted

Maybe we'll let you off, you were only conceding defeat in front of your fellow 'geek - so no harm done to the collective rep ;)

 

Email me the packet dump if you like, see if I can make any sense of it.

Posted
I tried the site in question at home and the webcams do work fine, using the Media Player extension plugin. I'll get Wireshark back onto the case again!
Posted

Have you tried a different browser?

 

Thought I had a similar one recently.. nothing getting logged in smoothwall anywhere. Turns out it was a bug in IE (or a recent IE update) that broke rendering on some websites

Posted (edited)

It does the same thing in firefox as well - the webcam plugin just sits there saying 'loading'. Externally I've tested with IE, firefox and seamonkey and they all work OK.

 

All I can see in wireshark is access to the smoothwall box as a proxy.

 

Actually, since we installed the smoothwall box google maps has never worked either. We always get the 'Still loading' message whatever browser we use - even when maps.google.com is given a top level 'Allow'

 

I've now tried on a seperate smoothwall box - which has no Deny rules at all. Same result. Nothing logged either.

Edited by Sheridan
Posted

Sheridan, I think you were on the right track earlier in-thread when you mentioned content modification rules.

 

Turn off the ignore filter in the log viewer and check for any lines with MODIFIED, particularly on JavaScript, and see what you see.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...