Jump to content

Recommended Posts

Posted

Hi All,

 

We've just rolled out a TMG 2010 server, It acts as a transparent proxy and all works fine for both HTTP sites and HTTPS.

 

The problem we are having is with the IPAD2:

 

Youtube App error: 'Cannot connect to YouTube' - Note: the actual YouTube site works fine, through safari

App Store error: 'Cannot connect to iTunes Store'

 

Im pretty sure both errors are related. After trawling the internet the nearest report & solution of this problem i can find is the following:

 

LINK: hxxp://xxw.google.com/support/forum/p/youtube/thread?tid=4cd50231e5fce253&hl=en

 

Which suggest to enable "Allow range requests through unmodified" on Watchguard equipment - Is there an ISA/TMG Equivalent setting?

 

Any help greatly appreciated.

 

Thanks

Posted

Hi Bio, I think this is the entry that relates to the 'Youtube' app failing to connect.

 

Failed Connection Attempt SHS-SR-TMG-01 20/10/2011 09:10:00

Log type: Web Proxy (Forward)

Status: 1790 The network logon failed.

Rule: Allow All

Source: Internal (10.177.55.72:52070)

Destination: Internal (212.219.83.101:8080)

Request: 209.85.229.99:443

Filter information: Req ID: 09ec533e; Compression: client=No, server=No, compress rate=0% decompress rate=0%

Protocol: https-inspect

User: anonymous

Additional information

Object source: Upstream (Object was returned from an upstream proxy cache.)

Cache info: 0x0

Processing time: 0 MIME type:

Posted

Additional to the above with 'HTTPS Inspection' turned off the error changes to this:

 

Closed Connection SHS-SR-TMG-01 20/10/2011 09:39:18

Log type: Firewall service

Status: A connection was closed because no SYN/ACK reply was received from the server.

Rule: Allow All

Source: Internal (10.177.55.72:52124)

Destination: Internal (209.85.229.105:443)

Protocol: BranchCache - Advertise

Additional information

Number of bytes sent: 640 Number of bytes received: 0

Processing time: 129000ms Original Client IP: 10.177.55.72

Posted
More info: If I open the Youtube application directly through the proxy server (i.e. not via the TMG) and do a search, the app works perfectly. Then I switch the networking to go through the TMG server and the APP continues to function perfectly!! So it looks like it is just the initial connection, could it be certificate related? Once the app is closed it fails to connect again.
Posted
Additional to the above with 'HTTPS Inspection' turned off the error changes to this:

 

Closed Connection SHS-SR-TMG-01 20/10/2011 09:39:18

Log type: Firewall service

Status: A connection was closed because no SYN/ACK reply was received from the server.

Rule: Allow All

Source: Internal (10.177.55.72:52124)

Destination: Internal (209.85.229.105:443)

Protocol: BranchCache - Advertise

Additional information

Number of bytes sent: 640 Number of bytes received: 0

Processing time: 129000ms Original Client IP: 10.177.55.72

 

I'm guessing its using a custom nonstandard badly implemented protocol which is confusing TMG. I'd look at the rules though as it is showing it as branchcache traffic which probably has additional inspection to prevent corrupted commands. It also looks a bit dodgey that the source and destination are both on the internal range. Is it a single interface TMG?

Posted

Hi Synack, Thanks for the reply. The only rule I have setup is a rule says 'Allow All' for 'All Users' from 'All Networks' to 'All Networks' is there anymore I can do?

 

Yes it is a single interface TMG.

 

Im unable todo any testing today but have also read changing the 'HTTP Compression Preferences' may help, what do you think?

Posted

Looking at it, I think it could be due to the layout of the TMG and Proxy.

 

If you are using a single nic TMG (and I'd really advise you get another nic put in there) then the traffic is coming in and out of the same interface. As you said the HTTP and HTTPS traffic is fine, I'd check to see if all traffic is being directed from the proxy to the TMG, otherwise this may well be going on:

 

  1. Handshake request from iPad hits the TMG and is passed on to the other proxy.
  2. This proxy sends the request on to the App store
  3. The request comes back and hits the proxy, which then passes it directly onto the iPad as opposed to the TMG
  4. The iPad is expecting the handshake to come back from the TMG and so ignores the one from the proxy.
  5. The TMG sits around for a bit, doesn't get the handshake reply and then closes the connection - giving you the SYN/ACK message

Posted

Aethon, thanks for the reply.

 

The server is virtual so I can add another card, I just wanted to get things working quickly.

 

The proxy we go through is a Squid proxy hosted by the local council so is difficult to get looked into, is this where I would need to "check to see if all traffic is being directed from the proxy to the TMG"

 

What you describe does sound like whats hapening, well especially the "The TMG sits around for a bit, doesn't get the handshake reply and then closes the connection - giving you the SYN/ACK message" bit

 

However if this was the case wouldnt Safari also be having issues?

 

Thanks

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...