Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
JasMan
Contributor

Delay when visiting sites hosted at Cloudflare

Hi all,

I noticed that some of the websites that I visit daily need a very long time until the first content shows up in the browser. I run a tcpdump on my client, the LAN and the WAN site of our perimeter firewall to analyze the cause of the delay.

The SYN packet from my client hits the LAN interface of the firewall after 1-3ms. But the outgoing SYN on the WAN site of our firewall appears 5-6 seconds later.
The logs in the SmartConsole draws a different picture: the incoming and outgoing SYN appear in the log at the same second, which is exactly the time where the outgoing SYN appears in the packet capture on the WAN interface.

This happens for all tested sites

  • which are located at Cloudflare
  • which are not excluded from HTTPS inspection
  • which haven't been visited in the last hour

The CA list on the gatewway is up to date and complete.

Any thoughts what or which blade could cause the delay?

Could a WSTLSD daemon debug help?

Jas Man

0 Kudos
3 Replies
Timothy_Hall
Legend Legend
Legend

If still no joy, please post the output of enabled_blades run from the gateway along with your code and JHFA level.

Gaia 4.18 (R82) Immersion Tips, Tricks, & Best Practices Video Course
Now Available at https://shadowpeak.com/gaia4-18-immersion-course
the_rock
Legend
Legend

Is it same on every browser? If so, you can always try use secure DNS setting, see if it makes any difference. I believe in every browser, there are few options, ie google dns, cloud flare, etc.

Andy

0 Kudos
the_rock
Legend
Legend

I did more checking into this and saw case I had with customer and what I attached turned out to tbe the issue, it was on hold and when we changed to background, all worked well. Might be worth checking.

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events