LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 02-10-2004, 08:54 AM   #1
mschna
LQ Newbie
 
Registered: Feb 2004
Posts: 4

Rep: Reputation: 0
Problem with https connections - iptables Suse9.0


Hello,

I've a strange problem with an internet connection over https with using ip_tables on an Suse 9.0 Linux system.
The client PC's are set up to use a squid-proxy server on machine A, were a SuSE Linux 7.3 system is running on.
The squid server on machine A is not directly connected to the internet.
The internet connection is established with an nat-rule on machine B which is used as firewall. The system running on machine B is SuSE 9.0 with kernel 2.4.21 an ip-tables version v1.2.8.

The problem is, whenever an client PC uses an https connection (with machine A as Proxy), the browser needs a lot of time for showing a result and much more time until an complete site is shown. With non-https connection there is no problem.

Are there any problems with SuSE9.0's iptables and https connections over https?

Thanx for any help!
 
Old 02-10-2004, 01:37 PM   #2
ricstirato
Member
 
Registered: Jan 2004
Location: Gießen, Germany
Distribution: Xubuntu 12.04, Mythbuntu, Ubuntu Server 12.04
Posts: 174

Rep: Reputation: 24
What kind of clients do you have?

MSIE has big (!) problems with https, and except for MSIE 6, https over proxies is practically impossible when keepalive is on.

There is a MS knowledge base article about this, search for "Internet Explorer keepalive"
 
Old 02-12-2004, 01:54 AM   #3
mschna
LQ Newbie
 
Registered: Feb 2004
Posts: 4

Original Poster
Rep: Reputation: 0
The Clients uses Internet Explorer and Netscape, the Problem is the same.
Are there any modules which should be loaded for ssl over nat except of: iptable_mangle
ipt_MASQUERADE
ipt_state
iptable_filter
ip_gre
ip_nat_ftp
iptable_nat
ip_tables
ip_conntrack_ftp
ip_conntrack

The nat rule uses MASQUERADE:
iptables -t nat -A POSTROUTING -o $INTERNAL_NET -j MASQUERADE

Do I have to load additional modules or is there an fault in the rule?

Many thanks for help!
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Some https connections time out. Likosin Linux - Networking 0 04-26-2005 07:48 PM
Squid problem with https connections thermoponch Linux - Networking 0 11-03-2004 04:41 AM
Iptables not allowing outbound https john8675309 Linux - Software 3 09-13-2004 10:41 PM
Iptables and https sturla69 Linux - Security 6 09-16-2003 10:13 PM
password rejected on https connections JCQ78 Linux - Networking 1 09-07-2003 05:36 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 07:29 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration