Problems Accessing SSL pages on an SBS server

mic_y

Expert Member
Joined
Dec 23, 2004
Messages
1,646
Reaction score
10
Location
Slaapstad
Hi guys,

I recently set up a server at one of my clients offices running SBS 2003. By default, the server runs OWA (Outlook Web Access) and RWW (Remote Web Workplace) with SSL encryption. The server is running on a 4mb ADSL line with a WebAfrica shaped account.

Now, the most obvious way to test that these services were working was to phone someone who was at my house, and ask them to try and access the site, which is exactly what I did. And nothing was working. Anything running on port 80 (normal HTTP) would load perfectly, but once you try and access any SSL pages (port 443) it would time out. Initially I blamed Microsoft, and have been in communication with them for about a week. The guy has not yet tested access.

Yesterday, i re-enabled SSL on the above mentioned pages, and attempted to access them from two different iBurst connections, and 3 different computers. Nothing was working. Then I had a free moment at work, and decided to attempt to access the site. All of a sudden everything worked.

I immediatly phoned a friend, who has iBurst, and asked him to try and access the server as well. Lo and behold, it didnt work. I then phoned another person, who is not on iBurst, and asked them to also try and connect, and they did so without a hitch.

Now to me this seems like an iBurst problem.

If you guys have the time, try and access https://sovietaircharter.no-ip.org/exchange from your iBurst connections, and tell me if you can access it. Also, if you have other connections avaliable (ADSL, dial-up, or internet connections at work) please try and access the site, and post results here. This would be greatly appreciated.

PS. When your browser complains about the security certificate, just click continue. The certificate is a self-signed, and therefore browsers dont trust the CA.
 
Cant connect here from iBurst.

I think your findings are about enough. Give iBurst a call and ask about it..
 
hehe, already did so. Just want to make 100 percent sure you know. Like 5 clients from iBurst cant connect, and 5 non-iBurst clients can connect.

Another "suggestion" that I got was changing MTU to 1324. Cant do it now, caus I am at work. Wanna give it a try EHV? I know i can access other SSL protected sites from my iBurst connection (internet banking).
 
Same problem here, after I click to continue when the security certificate window pops up so yes I'd say it's an iburst problem.

Changing the mtu setting to 1324 made no difference as it still times out.
 
Ok well, looks like iBurst will have some work to do ;)

Bleh, I have been stressing about this for weeks on end now, only to find out it is iBurst who is at fault. Probably some new shaping/proxy/way to irritate customers thing.

Well I have phoned Shaun Green, explained to him what the issue is. Will see what he says, and hopefully move on from there.
 
Last edited:
Tested it on ADSL - works, I can see the OWA login screen.

It is fscking irritating, wish they can sort it out...

...and also why Smoothwall doesn't want to play ball with iBurst...
 
Sounds like a firewall or routing problem.

A firewall issue on my side, or iBurst side?

It cant be on my side, caus i am 100% sure that I did not block incoming connections from iBurst IP's. The other thing is that I can see the incoming connections from iBurst IP's in the IIS log on the server. So it is really strange. Shaun promised to send out a techie, to come with me to the office, so hopefully that clears up something...
 
A firewall issue on my side, or iBurst side?

It cant be on my side, caus i am 100% sure that I did not block incoming connections from iBurst IP's. The other thing is that I can see the incoming connections from iBurst IP's in the IIS log on the server. So it is really strange. Shaun promised to send out a techie, to come with me to the office, so hopefully that clears up something...

Do let us know what happened...

Regards

Libs
 
Top
Sign up to the MyBroadband newsletter
X