Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
jtfinley
Contributor

Akamai sites fail in browser, can ping

I have a strange issue. New customer with (2) DSL connections on WAN1 & WAN2. WAN 1 = /28 block of IP' s WAN 2 = /29 block of IP' s All websites function fine, however, any site that' s hosted on Akamai web site just spins. pb.com, staples.com, officemax.com, microsoft.com Customer made us aware as this is a new installation. Remote control of a PC at the location shows this, however when running a packet sniff, many trans-it exceeded errors during trace routes from the PC. PW Policies work (NAT) (internal->WAN1) (internal -> WAN2) Routes are EQLB Pings & Trace-routes to said sites reply and finish.... Called ISP asking if they were experiencing peering issues.... Perplexed..... customer thinks it' s the firewall since its " new" .
27 REPLIES 27
rwpatterson
Valued Contributor III

ORIGINAL: jtfinley ...Had the customer plug a PC directly into the DSL modem w/ configured IP from routable block and showed same symptoms. This means the ISP lied. Sigh
What a surprise.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
jtfinley

Here' s a twist. My contact at the ISP stated the IP' s assigned may be BOGON; these IP' s were never assigned before? Possibly that' s the issue....more to come.
rwpatterson
Valued Contributor III

Is your ISP slow in updating their ACLs?

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
jtfinley

The ISP' s thinking it' s AKAMAI that' s slow. Since it appears to only affect AKAMAI websites. Again, we can PING the URL sites, just can' t " reach" it via browser, just spins.
emnoc
Esteemed Contributor III

All BOGON, that could be it. Do you have the address range ? You can check the bogons list online. http://www.team-cymru.org/Services/Bogons/bogon-dd.html I bet your ISP didn' t do their job with that new assignment and maybe akamai is filtering you or their service providers. If you find the origin_server of the CDN host website, you can test to the ORIGIN_SERVER directly and then know it' s that. Be advise they might have site shield protecting the Origin server from direct access.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
jtfinley

We' re not exactly sure what it was, but the ISP logged into the DSL modem(s), made changes. They requested our MTU be 1492 which it was and everything started working. Still investigating the config file on this DSL modem.
emnoc
Esteemed Contributor III

A pcap capture would easying tell you the MSS values for yourt tcp traffic and help determine if it' s an MTU issues. If the DSL modem mtu was an issues, than everything should have failed.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Dave_Hall
Honored Contributor

I' m thinking it could still be a MTU-related issue, not with the local ISP but somewhere on the Akamai network. Maybe the MTU value is something like 1452. Alternately (as outlined in Fortinet kb#11731) setting the tcp-mss-sender option in the firewall policy may resolve the browsing issue. Keep in mind that Akamai hosted sites are mirrored around the world, which is geographically determined via DNS. It could be a problem with the local mirror or route to the local mirror (23.60.74.100 for www.uline.com). Using various DNS servers, I was able to find other mirrors at 184.51.146.100, 173.222.186.100, 95.101.46.100.

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors