Koozali.org: home of the SME Server

https blocked

Offline jugglingphil

  • *
  • 5
  • +0/-0
https blocked
« on: November 03, 2010, 11:43:04 AM »
Hi, long time user of SME, 1st time poster.
Recently upgraded SME server to 7.5.1. This was a fresh install on new hardware. Since moving to 7.5.1 https sites can not be accessed, while http sites can. If I go out via another gateway, https and http work ok.
I can not see what is blocking this access. An pointers and help, greatly appreciated.
 
I have installed the dmc-mitel-portopening contrib, ports 80 and 443 are open. Squid.conf also lists port 443 as safe

Thanks in advance, Phil

Offline janet

  • *****
  • 4,812
  • +0/-0
Re: https blocked
« Reply #1 on: November 03, 2010, 02:39:02 PM »
jugglingphil
 
Quote
I have installed the dmc-mitel-portopening contrib

That is a very old contrib for sme5. You should uninstall it immediately.

SME server has a built in port opening and forwarding panel since sme6 I think.

While you might be a long time user, you have certainly not kept track of development.

In normal default use you do not need to open or forward any ports.
Remove the rpm and see if you still have problems.
If so, please explain more precisely what access from where to where that you have problems with.
Please search before asking, an answer may already exist.
The Search & other links to useful information are at top of Forum.

Offline CharlieBrady

  • *
  • 6,918
  • +3/-0
Re: https blocked
« Reply #2 on: November 03, 2010, 03:31:55 PM »
SME server has a built in port opening and forwarding panel since sme6 I think.

Port forwarding, yes, since before sme6. Port opening is implicit in service enabling/disabling.

OP however seems to be reporting a problem with outbound access. SME server blocks no outbound accesses. I suspect that OP's problem might be default gateway configuration and/or proxy configuration on client machines.

If this command on the server shows content, then https is not being blocked outbound from the server:

lynx -dump https://www.contribs.org/

Offline jugglingphil

  • *
  • 5
  • +0/-0
Re: https blocked
« Reply #3 on: November 03, 2010, 03:45:08 PM »
I have removed port-opening.
still can not access https sites.
I know that this isn't normal, and I doubt it's a bug as there are no other reports (as I can see) to this happening for anyone else.

From a PC on the network, with DNS and Default gateway pointing to SME server (server and gateway) can access http but not https.
http proxy is enable on SME server but not on PC.

If http proxy disabled can not access http or https, same if proxy set on PC (internet options)
PC config did not change from old SME server runnning 7.0

From SME server, lynx -dump command shows plenty of content.

Offline Igi2003

  • *****
  • 226
  • +0/-0
Re: https blocked
« Reply #4 on: November 03, 2010, 10:19:17 PM »
I had this Problem too when my WAN Connection is enabled in the configuration db. After Update I must disable WAN, because my SME connects via ppp0.
Code: [Select]
db configuration setprop wan status disabled signal-event....post....and reboot... don“t forget
Only if your WAN Connection is setup via adsl-setup, not console...

Igi

Offline CharlieBrady

  • *
  • 6,918
  • +3/-0
Re: https blocked
« Reply #5 on: November 03, 2010, 11:50:14 PM »
Only if your WAN Connection is setup via adsl-setup, not console...

Why are you using adsl-setup and not the console?

Offline Igi2003

  • *****
  • 226
  • +0/-0
Re: https blocked
« Reply #6 on: November 04, 2010, 12:10:45 AM »
Because my connection was not established automatically when using PPPoE Setup over console. Then I tried over adsl-setup, and then the PPPoE connection comes up after bootup SME. Even when WAN Connection (wan status enabled in config db) is enabled too, I have Problems with https (SSL) Sites. My Provider drop the first connection wenn the second comes up. So the two connections kicks one the other permanently till I disable wan connection.

Igi

Offline CharlieBrady

  • *
  • 6,918
  • +3/-0
Re: https blocked
« Reply #7 on: November 04, 2010, 01:51:30 AM »
Because my connection was not established automatically when using PPPoE Setup over console.

You should have reported the problem via the bug tracker, so that whatever the problem was could be diagnosed, and fix in the SME server software if required.

I would expect you will have a variety of problems if you attempt to use server-gateway mode with the WAN service disabled, and custom adsl_setup configuration.

Offline axessit

  • *****
  • 213
  • +0/-0
Re: https blocked
« Reply #8 on: November 04, 2010, 10:49:32 AM »
I have my router setup with DHCP for LAN client, only client is SME, with SME as DHCP client using MAC address as identifier on it's external NIC. I have port forward rule for 443 on my router so I can access my webmail from internet. Maybe the router is blocking or forwarding 443 to another IP as a new server will have a new ethernet MAC address and may not have the same IP as the old hardware. You can see your external IP on the SME server manager "review configuration" screen.

I have also heard of the wrong MTU setting on your router, without getting into a debate, this should be defaulted to 1500 if you can see anywhere to adjust it. It makes SSL sessions break if set wrong, normal browsing is OK. But I wouldn't go here first.

When you say if you use another gateway all is OK, is this using the same adsl router or another?


Offline Igi2003

  • *****
  • 226
  • +0/-0
Re: https blocked
« Reply #9 on: November 04, 2010, 06:14:23 PM »
You should have reported the problem via the bug tracker, so that whatever the problem was could be diagnosed, and fix in the SME server software if required.

I would expect you will have a variety of problems if you attempt to use server-gateway mode with the WAN service disabled, and custom adsl_setup configuration.
My SME works fine since three years with this config. Only afer Update if wan is enabled, he had Problems. And he works in Server and Gateway mode.

Offline Stefano

  • *
  • 10,894
  • +3/-0
Re: https blocked
« Reply #10 on: November 04, 2010, 06:51:17 PM »
My SME works fine since three years with this config. Only afer Update if wan is enabled, he had Problems. And he works in Server and Gateway mode.

fine.. but if something doesn't work out of the box it should be reported in bugzilla..
other people could expreinece this issue
thank you

Offline jugglingphil

  • *
  • 5
  • +0/-0
Re: https blocked
« Reply #11 on: November 05, 2010, 10:12:43 AM »
Gone a bit off topic here, I definitely don't want to disable my WAN side.

The PCs, router and ADSL line has not changed.
The old SME 7.0 server was moved to a new Local IP address, while the new 7.5.1 server given the old local IP of the 7.0 server. Both set the same on the external side. At that point I have started to experience problems with https access.
So problem is either with 7.5.1 (unlikely as on a different company I'm involved with 7.5.1 works no problem), or with the way I set it up. I'm thinking best to wipe the new 7.5.1 server and start again, however I won't be able to physically get to the server to do this until next week.

Offline Stefano

  • *
  • 10,894
  • +3/-0
Re: https blocked
« Reply #12 on: November 05, 2010, 10:48:25 AM »
I'm thinking best to wipe the new 7.5.1 server and start again, however I won't be able to physically get to the server to do this until next week.

worst way to act.. you should discover and understand WHY you have such an issue, then, eventually, open a bug

Offline jugglingphil

  • *
  • 5
  • +0/-0
Re: https blocked
« Reply #13 on: November 05, 2010, 11:07:02 AM »
Stefano, that's what I've been trying all week, unfortunately I'm not getting anywhere.

Offline Stefano

  • *
  • 10,894
  • +3/-0
Re: https blocked
« Reply #14 on: November 05, 2010, 11:18:18 AM »
ok..

you say that
- from SME console you can reach https sites (you can try again with elinks https://a_test_site)
- from internal/lan clients you can't.

is your SME http proxy in transparent mode? did you try to disable (if enabled) squid?
did you try to see from SME console and iptraf and/or tcpdump if there's https traffic?