Hallo all out there,
I really hope, that anyone on this great world can help me - respectively my organisation.
Did anyone of you tried to open the URL above? And did you have no problems to open this site with all of the included objects without any problems?
So - we have problems ... until about 3 weeks ago!
But then -suddenly and without any omen- we get some problems, which are not very easy to explain. We will open a ticket with our support-level, but perhaps some of you gets a good idea.
Now, here it goes:
Our normal Proxy-sytem is a cluster containing two appliances(debian) which are called over one adress. All clients are connected through a proxy.pac-file.
"github.com" can only be opened correctly with Firefox, or the latest version of InternetExplorer. In the further text I only will talk about Firefox FrontMotion or the normal FireFox Browser in its latest version.
As a subject to compare the behavior or for testing new rules or settings we have an exact clone of those appliances running as a VMWare. The only difference is the web cache, which does not exist on the WebGateway-VM, and of course, the "ground-system"- VMWare is installed on a windows platform. All other settings, rules and configuration is exactly the same as on the originals.
So far the basics, now the specials:
The normal way open the site "https://github.com" with FireFox should look like this:
, but using our proxy-systems over the proxy.pac-file it looks that way:
With this result I nearly tried everything on the system - beginning with the rule sets, settings and even in the configuaration. Global Whitelisting was equally useless as tunneling all certificates, which you get with a trace or logging the session.
Next step was our test-system - as I told this is the exact clone of the real systems >> and there everything works and looks like it has to look, without any change in the rules or something like that.
Next step was an entry in the proxy.pac-file, that " *github* " should connect directly without the proxy-systems >> of course this works fine!
Next step was an entry in the proxy.pac-file, that all requests, which has anything to do with " *github* " will redirect on the test-system >> and it works fine.
Next step was the same entry, but now "hard" on one of the clustered appliances >> fail
Now my thought was, that the only difference is the web-cache (as I told above). So I deactivated it on the real system, tried again without any entry in the proxy.pac-file >> and failed.
And now I am at the end of my ideas. The state now is, that this one and only URL got an entry in the proxy.pac-file with a redirect on the test-system, so at least all filters are active. But this cannot be the final solution, because it is only a test-system.
And that is the reason, why I beg your help and your ideas. We cannot imagine, that our organisation here in Germany is the onliest place in the universe, which got this problem.
...and already yet a big ThankYou for your answers!