This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

mozilla.org, IPv6 and SSL scanning

Hi,

I have a problem with the mozilla.org website when SSL scanning is enabled.

Log entries in Webfilter log:
2013:10:25-08:40:59 vpn httpproxy[5263]: id="0003" severity="info" sys="SecureWeb" sub="http" request="0x232eb608" function="tunnel_handler_recv_data" file="tunnel.c" line="45" message="epoll_fill_buffer: Network is unreachable"
2013:10:25-08:40:59 vpn httpproxy[5263]: id="0002" severity="info" sys="SecureWeb" sub="http" name="web request blocked" action="block" method="CONNECT" srcip="" dstip="2620:101:8020:5::2:132" user="" statuscode="500" cached="0" profile="REF_HttProInternalde (Internal_Default)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="175" request="0x232eb608" url="addons.mozilla.org/" exceptions="ssl" error="Network is unreachable"
2013:10:25-08:40:59 vpn httpproxy[5263]: id="0003" severity="info" sys="SecureWeb" sub="http" request="0x2c2bacd8" function="tunnel_handler_recv_data" file="tunnel.c" line="45" message="epoll_fill_buffer: Network is unreachable"
2013:10:25-08:40:59 vpn httpproxy[5263]: id="0002" severity="info" sys="SecureWeb" sub="http" name="web request blocked" action="block" method="CONNECT" srcip="" dstip="2620:101:8020:5::2:132" user="" statuscode="500" cached="0" profile="REF_HttProInternalde (Internal_Default)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="175" request="0x2c2bacd8" url="addons.mozilla.org/" exceptions="ssl" error="Network is unreachable"


My Setup:
UTM 9.106 (current) Home License
IPv6 enabled (native connection, no tunnel broker)
Proxy in Standard mode, SSL scanning enabled
SSL scanning exception for "^https://.*\mozilla\org/"

When I disable IPv6 on the UTM, everything works fine...

Any idea, what's wrong here?


This thread was automatically locked due to age.
  • Just tested with disabling my SSL scanning exception for "https://.*\.mozilla\.org/":
    It also works (with IPv6 enabled)!

    I added this exception in the past because the mozilla products couldn't reach its update severs without it.
    Just have to test if that still works with this exception disabled...