Koozali.org: home of the SME Server

Cannot access https from outside the lan just on the inside.

Offline kingjm

  • ***
  • 55
  • +0/-0
    • www.iking.ca
for some reason after upgrading to 7.1.3 I cannot access https from outside of the lan. I can access https inside of the lan

I also cannot access imaps (not sure if this is related) from inside the lan but I can from outside.

I have installed snort and oinkmaster. There is no proxy in use.

Where should I start looking.  I have looked at the iptables but don't understand much of what is going on there. Can someone please help?

I have found other forums on ssl issues, but they are for accessing https from within the lan.

Offline mmccarn

  • *
  • 2,657
  • +10/-0
Cannot access https from outside the lan just on the inside.
« Reply #1 on: July 15, 2007, 04:26:47 PM »
Are you running the latest smeserver-snort from 5/25/07?
http://www.vanhees.cc/index.php?name=CmodsDownload&file=index&req=viewsdownload&sid=52&orderby=dateD

Is there anything interesting in your httpd, imaps, or snort log files when you try to connect from off-site?

Does the problem persist if you uninstall snort?

Offline kingjm

  • ***
  • 55
  • +0/-0
    • www.iking.ca
Versions of snort and oink
« Reply #2 on: July 15, 2007, 06:21:20 PM »
I had snort 2.44 and oink 1.2.

I have unistalled and deleted the databases, ran the yum update, and rebooted.

I can now access the https://mydomain.com/index.html from a proxy server. however I cannot access https://mydomain.com/index.php through a proxy.  Not sure if the proxy will not allow it for me to check if the php sites are working.

I was trying http://keepanon.com, and http://freeproxy.ca

Offline kingjm

  • ***
  • 55
  • +0/-0
    • www.iking.ca
Cannot access https from outside the lan just on the inside.
« Reply #3 on: August 04, 2007, 09:05:16 PM »
Well tried to access from three different computers with three different os's, outside of the lan. I still cannot access https. I have been scratching my head thinking of what else it could be.

The only other thing that I can think of is that I am using a cert from cacert.org and am using this thread http://forums.contribs.org/index.php?topic=34624.0