This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Please explain this odd diagnostic tool behaviour.

Hi folks,

I have another thread which the  issue has been resolved about accessing coles.com.au.

I can now access that site without any issues. I was using the policy tester during my investigations and received some strange answers which did not help with the resolution.

Policy tester results. The first is with the SSL/TLS in the selection process. The second is just the web proxy with the web policy used the access rules.

Why does the SSL/TLS cause the site to show blocked in the testing when in practice it is not blocked?

Ian



This thread was automatically locked due to age.

Top Replies

  • First of all: TLS/SSL Scanning is not involved in this situation. 
    The policy tester simply says, your IP has no matching firewall rule for WAN (This particular WAN IP).

    If you browse from this IP to the particular WAN IP, do you see a logviewer entry? Can you show us this logviewer entry? 

    Jump to answer
Parents Reply Children
  • they also have other IP today than in your log:

    your log:

    url="">www.coles.com.au/favicon.ico" content_type="text/xml" override_token="" src_ip="2403:5814:8482:3201:100::4" dst_ip="2620:1ec:4e:1::32"

    Web server IPv6 connectivity
    Trying to get hxxps:||www.coles.com.au from 2620:1ec:4f:1:0:0:0:64...
    307 Temporary Redirect
    Trying to get hxxps:||www.coles.com.au from 2620:1ec:4e:1:0:0:0:64...
    307 Temporary Redirect



    Secure web server IPv6 connectivity
    Trying to get hxxps:||www.coles.com.au from 2620:1ec:4f:1:0:0:0:64...
    200 OK
    Trying to get hxxps:||www.coles.com.au from 2620:1ec:4e:1:0:0:0:64...
    200 OK