06-13-2012 01:38 AM
Hi,
we recently ran into a problem accessing the page www.infas-geodaten.de (or the corresponding IP) through our IronPort S160.
Even a policy trace ends up with a failure.
Any help on how to narrow down this problem or how to solve it is welcome.
Kind regards,
Thomas
Bei der Verarbeitung der Anfrage zur Seite ( http://www.infas-geodaten.de/ ) ist ein interner Systemfehler aufgetreten.
Bitte wiederholen Sie diese Anfrage.
Wenn der Fehler weiterbesteht, kontaktieren Sie bitte Ihren ServiceDesk und geben den unten genannten Code an.
Meldungs-Codes: | (1, INTERNAL_ERROR, http://www.infas-geodaten.de/) |
Bei der Verarbeitung der Anfrage zur Seite ( http://195.227.221.196/ ) ist ein interner Systemfehler aufgetreten.
Bitte wiederholen Sie diese Anfrage.
Wenn der Fehler weiterbesteht, kontaktieren Sie bitte Ihren ServiceDesk (Tel.: 9800) ( servicedesk@kvwl.de ) und geben den unten genannten Code an.
Meldungs-Codes: | (1, INTERNAL_ERROR, http://195.227.221.196/) |
Solved! Go to Solution.
06-18-2012 12:28 AM
Hi Thomas,
Thanks for the accesslog details. When we now look at the timing (150113ms, which is ~2x 75sec, the WSA TCP timeout on SYN connect) together with 502 (gateway timeout) would mean that the WSA was not able to establish a TCP session to the destination server for some reason.
You could mimic a TCP connect test on the CLI of the WSA to the host via the telnet command:
> telnet www.infas-geodaten.de 80
to see if something on the routing/firewall is missing here.
Hope I could help you a bit further.
-Stephan
06-14-2012 01:42 PM
Hi Thomas,
you are sure this error was generated on your S160? Of these request, could you lookup this request in the aclogs? The according log line should englighten more what might have caused it.
Thanks,
Stephan
06-17-2012 11:11 PM
Hi Stephan,
the message is generated by our S160 indeed.
I looked up the request in the accesslog:
1339999212.554 150113 172.22.20.13 NONE/502 1855 GET http://www.infas-geodaten.de/ "DOM\user@DS.DOM.KVWL.DE" DIRECT/www.infas-geodaten.de - OTHER-NONE-KVWL_User-NONE-NONE-NONE-DefaultGroup
Any hint in there?
Thanks a lot,
Thomas
06-18-2012 12:28 AM
Hi Thomas,
Thanks for the accesslog details. When we now look at the timing (150113ms, which is ~2x 75sec, the WSA TCP timeout on SYN connect) together with 502 (gateway timeout) would mean that the WSA was not able to establish a TCP session to the destination server for some reason.
You could mimic a TCP connect test on the CLI of the WSA to the host via the telnet command:
> telnet www.infas-geodaten.de 80
to see if something on the routing/firewall is missing here.
Hope I could help you a bit further.
-Stephan
06-19-2012 03:38 AM
Hi Stephan,
shame on me I didn't telnet the host directly from the S160 right away... As you supposed the TCP SYN times out.
Routing and firewall are fine over here. I double checked that and also tried to telnet www.infas-geodaten.de from our most outer system without success.
So no problem regarding the S160.
Contacted the operater. Seems as if their routing is buggy or they are blocking our ip-range as none of the services residing in their ip-range is responding.
Regards
Thomas
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide