[7.902][NOTABUG][CLOSED] Web Proxy doesn't work

Hi,

when i aktivate the Webproxy with transparent setting, i'm not able to surf any website, if i disable him, i can surf again...

I had this problem on 7.901 sporadically. Disable and reenable the Proxy fixed the Problem.
But not on 7.902. I can't surf with enabled proxy.

Which Logfile or or screenshot of the settings is needed?

Regards Robert
  • Astaro Beta Report
    
    --------------------------------
    Version: 7.902
    Type: NOTABUG
    State: CLOSED
    Reporter: Robert Tausend
    Contributor: BrucekConvergent, darrenl, splark
    MantisID: 
    Target version: 
    Fixed in version: 
    --------------------------------
  • Do you see anything in the HTTP logfile?  They have been having troubles (it seems with every beta release the past few weeks, at any rate) with the AV scanner failing... maybe that bug is "back."

    CTO, Convergent Information Security Solutions, LLC

    https://www.convergesecurity.com

    Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries.  Use the advice given at your own risk.

  • Hi,

    in the logs i didn't see much ... I didn't see my requests there ...

    i reaktivated the proxy, tried to surf some pages and deaktivated again ...

    all i see is this:


    2010:04:13-18:31:08 firewall httpproxy[9103]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="epoll_loop" file="epoll.c" line="767" message="starting exit cleanup"
    2010:04:13-18:31:24 firewall httpproxy[9733]: Integrated HTTP-Proxy (c) 2007-2010 Astaro AG, Release 14.g635a676
    2010:04:13-18:31:24 firewall httpproxy[9733]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="main" file="httpproxy.c" line="174" message="reading configuration"
    2010:04:13-18:31:24 firewall httpproxy[9733]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="main" file="httpproxy.c" line="189" message="reading profiles"
    2010:04:13-18:31:24 firewall httpproxy[9733]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="disk_cache_zap" file="diskcache.c" line="430" message="creating cache"
    2010:04:13-18:31:24 firewall httpproxy[9733]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="disk_cache_zap" file="diskcache.c" line="458" message="cache invalid, unlinking in background thread"
    2010:04:13-18:31:24 firewall httpproxy[9733]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="rmdir_recursive_background" file="diskcache.c" line="422" message="unlinking /var/httpcache.001 finished"
    2010:04:13-18:31:24 firewall httpproxy[9733]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="adir_auth_init" file="auth_adir.c" line="221" message="gss_acquire_cred host/firewall.ducktales.net@DUCKTALES.NET: No such file or directory"
    2010:04:13-18:31:25 firewall httpproxy[9733]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="sc_check_servers" file="scr_scanner.c" line="724" message="server 'cffs01.astaro.com' access time: 104ms"
    2010:04:13-18:31:25 firewall httpproxy[9733]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="sc_check_servers" file="scr_scanner.c" line="724" message="server 'cffs02.astaro.com' access time: 217ms"
    2010:04:13-18:31:26 firewall httpproxy[9733]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="sc_check_servers" file="scr_scanner.c" line="724" message="server 'cffs03.astaro.com' access time: 400ms"
    2010:04:13-18:31:28 firewall httpproxy[9733]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="sc_check_servers" file="scr_scanner.c" line="724" message="server 'cffs05.astaro.com' access time: 122ms"
    2010:04:13-18:31:28 firewall httpproxy[9733]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="sc_check_servers" file="scr_scanner.c" line="724" message="server 'cffs06.astaro.com' access time: 344ms"
    2010:04:13-18:31:29 firewall httpproxy[9733]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="sc_check_servers" file="scr_scanner.c" line="724" message="server 'cffs07.astaro.com' access time: 341ms"
    2010:04:13-18:31:29 firewall httpproxy[9733]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="sc_check_servers" file="scr_scanner.c" line="724" message="server 'cffs08.astaro.com' access time: 868ms"
    2010:04:13-18:31:30 firewall httpproxy[9733]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="sc_check_servers" file="scr_scanner.c" line="724" message="server 'cffs09.astaro.com' access time: 197ms"
    2010:04:13-18:31:30 firewall httpproxy[9733]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="sc_check_servers" file="scr_scanner.c" line="724" message="server 'cffs10.astaro.com' access time: 750ms"
    2010:04:13-18:31:32 firewall httpproxy[9733]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="main" file="httpproxy.c" line="217" message="finished startup"
    2010:04:13-18:32:11 firewall httpproxy[9733]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="confd_config_reload_func" file="confd-client.c" line="716" message="reloading config"
    2010:04:13-18:32:11 firewall httpproxy[9733]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="confd_config_reload_func" file="confd-client.c" line="749" message="done"
    2010:04:13-18:32:34 firewall httpproxy[9733]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="confd_config_reload_func" file="confd-client.c" line="716" message="reloading config"
    2010:04:13-18:32:35 firewall httpproxy[9733]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="confd_config_reload_func" file="confd-client.c" line="749" message="done"
    2010:04:13-18:32:46 firewall httpproxy[9733]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="confd_config_reload_func" file="confd-client.c" line="716" message="reloading config"
    2010:04:13-18:32:46 firewall httpproxy[9733]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="epoll_loop" file="epoll.c" line="767" message="starting exit cleanup"
    2010:04:13-18:32:46 firewall httpproxy[9733]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="json_get_string_array" file="confd-client.c" line="393" message="no array given"
    2010:04:13-18:32:46 firewall httpproxy[9733]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="json_get_string_array" file="confd-client.c" line="393" message="no array given"
    2010:04:13-18:32:46 firewall httpproxy[9733]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="confd_config_reload_func" file="confd-client.c" line="749" message="done"
    2010:04:13-18:32:46 firewall httpproxy[9733]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="scan_exit" file="scanner.c" line="376" message="scanner subsystem shutting down"
    2010:04:13-18:32:46 firewall httpproxy[9733]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="scan_exit" file="scanner.c" line="382" message="scanner subsystem shut down"
    2010:04:13-18:32:46 firewall httpproxy[9733]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="epoll_exit" file="epoll.c" line="127" message="epoll subsystem shutting down"
    2010:04:13-18:32:46 firewall httpproxy[9733]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="epoll_exit" file="epoll.c" line="140" message="epoll subsystem shut down"
    2010:04:13-18:32:46 firewall httpproxy[9733]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="disk_cache_exit" file="diskcache.c" line="42" message="writing cache index"
    2010:04:13-18:32:46 firewall httpproxy[9733]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="disk_cache_exit" file="diskcache.c" line="44" message="writing cache index done"
    2010:04:13-18:32:46 firewall httpproxy[9733]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="main" file="httpproxy.c" line="243" message="shutdown finished, exiting"


    Regards
    Robert
  • Hmmm... doesn't look the same bug we've been seeing in previous versions; perhaps an Astaro developer will happen along shortly to decipher what's happening.

    CTO, Convergent Information Security Solutions, LLC

    https://www.convergesecurity.com

    Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries.  Use the advice given at your own risk.

  • Curious, I've just updated to 7.902 and my HTTP proxy is working OK in transparent mode.

    I have noticed that the 'Open Live Log' button under Web Security/HTTPS/Global - opens a different log file than going into the Logging/View Log Files / HTTP daemon.  There is no external browsing content in the log when accessing via the view log files content, only the browsing activities of using the WebAdmin.
  • @Robert can you please take a look in your packetfilter log when the proxy is enabled? I'd like to see if they are dropped by some rule.
  • Running 7.902 here (now), in transparent mode as well, with HTTP Proxy... seems to be working fine here.

    CTO, Convergent Information Security Solutions, LLC

    https://www.convergesecurity.com

    Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries.  Use the advice given at your own risk.


  • I have noticed that the 'Open Live Log' button under Web Security/HTTPS/Global - opens a different log file than going into the Logging/View Log Files / HTTP daemon.  


    I think that might be a bit of naming inconsistency between pages. The "HTTP daemon" log I think relates to the http serving of the admin interface. The log you want is the one called "Content Filter (HTTP/S)" which as you say seems to be called "HTTP Access" on the other page.

    There might be a logical reason for that, but maybe we should log a bug.
  • Realy strange ... today i activated http proxy and it worked ... but i'm shure in the afternoon i will get again problems with it, will have a eye on it and report again ...
    Robert