This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Webserver protection fails with 'error reading status line from remote server' in reverseproxy log

Hello,

After changing from a virtual UTM9 to a XG115 appliance, the webservers are unreachable from the internet when we use web server protection. Only https forwarding is working while we search a solution. We have two Windows IIS servers behind one WAN-IPaddress, two different certificates and two different URLs, both servers have the same problem after the change from UTM to XG.

SSH reverseproxylog shows 'error reading status line from remote server'

Browser shows: The proxy server received an invalid response from an upstream server. The proxy server could not handle the request GET /SynergyMobile. Reason: Error reading from remote server   The same applies to /owa or whatever we try to open.

We applied a new protection policy with minimal settings, nothing we tried makes a difference.

Any ideas?

Kind regards, Gerard Timmerman



This thread was automatically locked due to age.
Parents Reply
  • The case is solved; the problem was that XG's reverse proxy failed when a number of older SSL protocols and ciphers were enabled in Windows 2008R2.

    Solution was disabling all protocols but TLS 1.0, 1.1, 1.2 and all ciphers but Triple DES and AES (using a free toool by Nartec).

     

    This behaviour should be improved by XG not tripping over availability of these protocols, but warning the administrator that these webservers could be vulnerable in the LAN

     

    Best regards, Gerard 

Children
No Data