- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Re: R80.40 Take 120 & VSX - Full HTTPS Inspection ...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
R80.40 Take 120 & VSX - Full HTTPS Inspection issue
Upgraded two unrelated VSX clusters to R80.40 Take 120 running full HTTPS inspection, and on each I began to notice choppy behaviour on web browsing, along with web-based applications beginning to fail.
When I switched back to the member still on Take 118, it worked directly. Then issues reappeared after going again to the Take 120 system. I refreshed the VS and pushed the policy but it didn't help. I rolled back to Take 118 and everything is peachy again, although I could have used the myriad of fixes introduced in Take 119. 🙂
On one of these clusters, HTTPSi was in evaluation so I can narrow it down to a couple of PC's and work with TAC, an SR is open.
I will post if I get relevant developments, I just wondered if others are using VSX + Take 120 + HTTPSi and having a similar issue.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi 🙂
We are not familiar with this issue , I will appreciate getting the SR number for better understanding.
thanks!
Naama Specktor
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
There was a rare issue discovered with T119 and T120 that sounds similar to what you are describing.
Are you seeing any parser errors in your logs?
Either way, if you have a TAC case open then you’re on the right path.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@mcatanzaro There is a bunch of "F2P outbound processing failed (CPAS)", after a session with TAC they hint at SecureXL but additional debug sessions are planned during an upcoming maintenance window.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Did you find any solution for this problem?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Are you already running a JHF version that includes the following?
PRJ-30818, PRHF-19417 |
SecureXL | In a rare scenario, after an upgrade, HTTPS traffic may be dropped. |
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
No, not yet. Take38 not GA for 81.10. I have seen that bug, but it just day HTTPS traffic not HTTPS Inspected traffic. Maybe a typo from CP?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I left the cluster on R80.40 Take 118 until R81 T44 became recommended and upgraded there and now Take 58, never had any HTTPS Inspection issues since.