Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

Another weird filter issue

2 views
Skip to first unread message

Stevo

unread,
May 12, 2009, 2:05:10 PM5/12/09
to
Been hearing rumblings that people here can't get to part of a site
that's using port 8080 in the link.

Already have a stateful excpetion for port 8080 outbound, but that does
not seem to work for this site.

Site they're trying to go to is http://www.wyonewspapers.org , then
clicking on the browse by city or browse by county links, neither of
which work unless I unload filters.

Any suggestions as to what I can do here?

TIA,

Steve

Craig Johnson

unread,
May 13, 2009, 6:16:06 PM5/13/09
to
In article <qTiOl.8220$s8....@kovat.provo.novell.com>, Stevo wrote:
> Any suggestions as to what I can do here?
>
Your exceptions are wrong if the site works simply by unloading
filters.

Could possibly be that a java applet loads that tries to connect
directly to the site via NAT? In which case you'd need to open port
8080 from private to public interfaces, stateful.

PKTSCAN or filter debug work would tell you what was going on, and from
there it should be easy to fix the filters.

Craig Johnson
Novell Support Connection SysOp
*** For a current patch list, tips, handy files and books on
BorderManager, go to http://www.craigjconsulting.com ***


Stevo

unread,
May 13, 2009, 6:27:41 PM5/13/09
to
Craig Johnson blathered something to the effect:

> Your exceptions are wrong if the site works simply by unloading
> filters.

Well that's definitely a possibility, filter excpetions have been
kicking my *** lately.


> Could possibly be that a java applet loads that tries to connect
> directly to the site via NAT? In which case you'd need to open port
> 8080 from private to public interfaces, stateful.

I already have a stateful exception from private to public for 8080

Craig Johnson

unread,
May 18, 2009, 2:22:39 PM5/18/09
to
In article <xPHOl.16$rb5...@kovat.provo.novell.com>, Stevo wrote:
> > Could possibly be that a java applet loads that tries to connect
> > directly to the site via NAT? In which case you'd need to open port
> > 8080 from private to public interfaces, stateful.
>
> I already have a stateful exception from private to public for 8080
>
Have you tried filter debug or pktscan or wireshark to see just what
packets are going where?
0 new messages