Re: Need https,portscan help

From: Colonel Flagg (colonel_flagg_at_NOSOUPFORJ00internetwarzone.org)
Date: 06/18/03


Date: Wed, 18 Jun 2003 15:54:29 -0400

In article <0w1Ia.36032$rb4.2103501@twister.austin.rr.com>,
randall@tnr.cc says...
> Colonel Flagg wrote:
> > In article <0eRHa.30415$1w1.2233906@twister.austin.rr.com>,
> > randall@tnr.cc says...
> >
> >>In the company I work for, I have a web server (apache on redhat 7.2).
> >>The IT dept gave me an external IP and http requests to that ip (port
> >>80) are successful. I need SSL (on 443) to encrypt authentication info
> >>and was told (by IT) that I should already be able to use it; that 443
> >>was open. But ssl request to the external ip fail. https://mysite.xxx
> >>and http://mysite.xxx:443 fail giving me a connection refused error in
> >>mozilla. I have NO TROUBLE using https within the internal network,
> >>just fron outside the firewall.
> >>
> >>When trying to connect from outside, I check my logs for attempts to
> >>connect. I can't see any records of connection attempts in my logs.
> >>
> >>I try to portscan the ip, but all I get is filtered ports. I can't even
> >>scan 80 (which I know works). This is likely due to my ignorance of
> >>networking.
> >
> >
> >
> >>I suspect that the port is closed, but I would like to know for sure
> >>before I tell IT they're wrong. I welcome any suggestions.
> >>
> >>Randall
> >>
> >>
> >
> >
> >
> > on the web server, the port is open or you wouldn't be getting there
> > from the internal network.
> >
> > chances are, the firewall sitting in front of the webserver doesn't know
> > to filter the request over to the server handling that IP/domain. can
> > you access the domain through standard http from outside the network? if
> > not, chances are, the administrator of the firewall hasn't modified the
> > firewall for this particular ip/domain.
> >
> >
> >
> yes, http works from outside, but not https
>
> Randall
>
>

probably not filtering/routing the https request through the firewall
properly. contact the firewall admin with your IP and the need for https
(port 443). if he said "he did that", ask him to look over the syntax
and make sure it's correct. advise him that you can get to it from
behind the firewall on the local net and not from outside the local net.

-- 
Colonel Flagg
http://www.internetwarzone.org/
Privacy at a click:
http://www.cotse.net 
Wanna ask a question in Usenet?
http://www.tuxedo.org/~esr/faqs/smart-questions.html
Everything about Usenet answered:
http://www.internetwarzone.org/answers.html
America WILL NOT forget 9-11-01


Relevant Pages

  • Re: SOHO firewall dropping incoming 443 connections - incorrect state
    ... The only incoming connection that I allow is an HTTPS port ... Occasionally the firewall seem to just start denying HTTPS ... I started a case with WatchGuard too, ...
    (comp.security.firewalls)
  • Re: Cant access web on local network server
    ... For correct DNS resolution you have also open port 69. ... Basically with a firewall to the external world you should be fine. ... Basically the port 80 is for http, sometimes 8080, https uses port ... Standard server and now my pcs can not access the web ...
    (microsoft.public.windows.server.general)
  • Re: Wrapping TCP communications in HTTP
    ... That sounds like we might be able to get away with going through port 80 by ... simply wrapping all of our messages in HTTP GETs or POSTs, ... but I still don't think that going through HTTPS is going to ... >> firewall and be able to connect to our components. ...
    (microsoft.public.win32.programmer.networks)
  • Re: Wrapping TCP communications in HTTP
    ... Use port 443 (HTTPS) instead. ... Microsoft MVP, MCSD ... > firewall and be able to connect to our components. ...
    (microsoft.public.win32.programmer.networks)
  • Re: keeping ports open
    ... If a port is open, it means that 1) a software or service is running on your ... and 2) you're not using a firewall or your firewall isn't ... Use firewall software and hardware and antivirus software that is ... Follow the instructions for hardening Windows and IIS at ...
    (microsoft.public.security)