- CheckMates
- :
- Products
- :
- General Topics
- :
- Re: cannot access www.yahho.com access
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
cannot access www.yahho.com access
Hello Mates. I have just configured my checkpoint R80.10 and has not blocked any sites. I am able to access all the other pages except www.yahoo.com which times out when in checks TSL configurations. I have tried different computers and browsers but nothing has changed. has any of you guys ever had this problem.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
What do you see in the logs when you attempt to access www.yahoo.com?
What does your rule look like to allow access to www.yahoo.com?
Have you done a tcpdump to validate traffic is flowing correctly or used something like fw ctl zdebug + drop?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I have the log for the command that you specified. For the internet access I have the below policy,
source: internal network destination : any service application: Http/Https action Accept.
I allowed everything on HTTP and HTTPS. I have the log but am having some problems to attach it
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I'm not sure how many of the errors in the debug output relate to the specific issue, but I see a few things you should probably fix:
- ;[cpu_3];[fw4_0];fw_log_drop_ex: Packet proto=1 41.217.216.18:1281 -> 41.75.1.100:9672 dropped by fw_icmp_stateless_checks Reason: ICMP redirect packets are not allowed;
- Since we ignore ICMP redirect packets, this can potentially create connectivity issues. You should fix whatever issue is causing ICMP redirects to be issued.
- ;[cpu_3];[fw4_0];fw_log_drop_ex: Packet proto=6 172.16.0.200:62578 -> 87.248.98.7:443 dropped by fw_first_packet_state_checks Reason: First packet isn't SYN;
- This usually points to an asymmetric routing issue, meaning outbound packets are taking one path and inbound packets are taking another. Based on the destination IP address being associated with Yahoo, this is probably your issue.
- ;[cpu_3];[fw4_0];fw_log_drop_ex: Packet proto=1 172.16.20.1:2048 -> 172.16.9.1:20866 dropped by fw_local_anti_spoofing Reason: local interface spoof;
- Most likely something is misconfigured in your gateway anti-spoofing settings.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
When I try to browse am getting this error on the browser, The site can’t provide a secure connection. uses an unsupported protocol. The client and server don’t support a common SSL protocol version or cipher suite. This is likely to be caused when the server needs RC4, which is no longer considered secure.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
But it does prove you've moved past your previous issue.
