| CPUG | |
| The Check Point User Group | |
| A Resource For The Check Point Community. Fast. Useful. Independent. | |
|
| |||||||
![]() |
| | LinkBack | Thread Tools | Display Modes |
| |||
| We are currently having problems accessing a certain HTTPS website: https://geas.multiasistenciaeuropea....onExplotacion/ When accessing the website outside of our firewall (for example via ADSL at home) there are no problems. When accessing the site at our office behind our Checkpoint firewall, we receive the "cannot display the webpage" error. We have tried with Vista + IE7, XP + IE6, Vista + Firefox 3.0.5. All to no avail. When looking at the traffic from the client (at the office) in wireshark, I can see that the client is sending SYN packets, but not receiving any SYN ACK at all. The TCP session is not starting as if the Checkpoint firewall is not allowing it to be established. When looking in Tracker, I can see the HTTPS traffic allowed to the destination, but no rejected or blocked traffic. My theory is that the usual suspect, SmartDefense, is causing the problem but I'm not sure where to look. We are running SPLAT R65 HFA40 in a failover cluster. Does anybody have any ideas? Thanks! |
| |||
| If its Smart Defense blocking you, there should be an entry in SmartTracker in the relevant section. Doesn't sound like an SD issue though - what is the actual reason code behind the "cannot display the webpage" error you get (normally some more detailed info available) Things to check: - Is your DNS server responding to the host name correctly - Are you using a proxy server - and if so, check the logs (or try bypassing it) - If you have an openssl installation somewhere try: openssl s_client -connect servername:443 -showcerts This will verify the communications for you. (As an aside Firefox 3.0.5 is quite old - 3.0.10 has been out for a while, and as reliable as any FF3 installations can be) Last edited by fwwidgit; 2009-06-10 at 08:46. |
| |||
| Given that it's HTTPS, there isn't a whole lot that SmartDefense can inspect. I tried your link and I can get to the login page but it wants me to install an ActiveX control. Are you blocking ActiveX controls somehow? Ray |
![]() |
| Thread Tools | |
| Display Modes | |
| |