Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Security Center > General Computer Security
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


General Computer Security Get Help With System Security - This forum is not for malware removal assistance. For malware removal assistance, read the sticky topic at the top of the Virus/Trojan/Spyware Help forum, or the "First Steps" link at the top right of each page.

Reply
 
LinkBack Thread Tools
Old 09-29-2005, 11:12 AM   #1 (permalink)
Registered User
 
Join Date: Aug 2005
Posts: 26
OS: Win XP SP2


External HTTPS download times out through Netscreen firewall

I still have not been able to solve this one. We have a client that is trying to download files from our HTTPS server. Everyone in the world can do it except this guy. He has a SonicWall firewall with stateful packet inspection turned on. If he moves his server outside the Sonicwall or turns off SPI, the download works just fine. If not, he gets into the site and starts the download, but it only gets about 20% of the way through and then times out. Sounds like his problem, right? Unfortunately, I can direct him through our backup off-site link and he can get the file just fine. Both our primary site and backup site are using Netscreen 50 firewalls. The one at the primary site is in high availablity mode (active/passive.)

We have confimed that this is an issue with the way our primary firewall is interacting with the SPI on the Sonicwall, but cannot figure out a fix for this. We have eliminated the IIS version, permissions, SSL certificate issues, server builds, and switch types.

If anyone has seen this or anything like this, please let me know.

Thanks!

Jason Carter
SirNtwrk is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here

Old 10-05-2005, 03:56 PM   #2 (permalink)
Registered User
 
Join Date: Aug 2005
Posts: 26
OS: Win XP SP2


In case anyone is interested in the solution here, which we finally found today, here it is:

The SonicWall firewall apparently does not have the ability to turn off stateful packet inspection as the administrator originally stated. Instead, he was turning off TCP Stateful Inspection. This is a very tight protocol that forces each packet to perform a 3 way handshake in order for it to be considered valid. Upon upgrading his firmware, this option became Strict TCP Stateful Inspection. Turning this option off meant that the establishment of the HTTPS connection would follow the 3 way handshake rules, but subsequent packets inside that session would be passed without the handshake. We have turned off the "Strict" option and everything runs well without sacrificing the security.

I still need to determine why the packets are coming in as duplicates or out of order through one firewall and not the other, but this is at least sovled for now if anyone is interested or comes across this in the future.

Thanks to everyone who at least took a look at this for trying to help.
SirNtwrk is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 06:39 AM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85