Skip to main content
Contributor III
May 18, 2010
Question

Not able to access HTTPS websites

  • May 18, 2010
  • 15 replies
  • 44822 views
I am having problems accessing certain(not all) SSL websites behind a FortiGate 110c running 4.0 MR2. Sites I cannot access include gmail.com and a local banking website. It is quite odd because last week I was unable to access gmail.com and Firefox would give the error: " Connection Interrupted" . Today in the morning I was able to access the sites for a few hours, however, within an hour from the last successful access I could no longer access the sites and Firefox would give the error: " The connection was reset." During this time-frame no changes were made to the FortiGate - which is weird why all of the sudden the sites would go from not working, to working, then back to not working. Anyone have any idea what could be causing this or where to start troubleshooting?

    15 replies

    ibm_ioman
    New Member
    October 6, 2010
    just to understand correctly, on what interface should I modify the tcp-mss?
    rwpatterson
    New Member
    October 6, 2010
    VPN interface.
    ibm_ioman
    New Member
    October 6, 2010
    I modified mtu to 1428 both on port8 and on vpn interface ... no change.
    ibm_ioman
    New Member
    October 6, 2010
    ping host -l 1400 -f ---> works ping host -l 1401 -f ---> doesn' t work modified mtu on vpn interface, still doesn' t work. I must specify, if I do a VIP to the call recorder (which works on ftp - port 21) and connect through Internet, not VPN, everything works.
    rwpatterson
    New Member
    October 6, 2010
    Change your MTU value to 1400, remove the tcp-mss value. Let us know how that goes.
    ibm_ioman
    New Member
    October 6, 2010
    changed mtu value to 1400 on vpn interface and unset tcp-mss - no result
    rwpatterson
    New Member
    October 6, 2010
    What does the sniffer indicate?
    ibm_ioman
    New Member
    October 6, 2010
    exactly the same: unreachable - need to frag (mtu 1428) again, this sniffer is run on port8, in which the recorder is directly connected. my way is: vpn (on wan1) -> port8
    Maik
    New Member
    October 6, 2010
    Hi Mike From your posts I read that you are using: Internet Explorer 6 and HTTPS Deep Scan Option In case you have no problems to access those websites with other browser (IE7,IE8), then change the following settings: config firewall ssl setting set ssl-send-empty-frags disable end regards Maik
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.