DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

2862n can't access to https://forum.draytek.co.uk - why?

  • dansorion
  • User
  • User
More
07 Jun 2018 11:49 #7 by dansorion
Have you got any CSM APP enforcement enabled?

I upgraded two 2830s with the latest firmware on Monday and found on Tuesday that many users kept having issues connecting to HTTPS/SSL services (websites, email, and others), and after using the Draytek Syslog server was able to see the CSM log entries indicating that connections were being blocked for the [LINE] rule. Also once a CSM block occurred I then saw a bunch of DOS blocks, looking to be due to the LAN PCs retrying packets to the HTTPS ports and as the connection was already broken from the CSM enforcement. I unticked the LINE protocol under IM Application in the default profile, and so far nobody has complained. Opened a support ticket about it with Draytek but yet to hear back. I suspect that the LINE IM profile was adjusted in a recent firmware and is falsely detecting legitimate HTTPS traffic

Might not be relevant, but I'd start by using the Draytek Syslog server and looking in the firewall logs under CSM Log and Defense Log.

Dan

Please Log in or Create an account to join the conversation.

More
07 Jun 2018 12:19 #8 by akwe-xavante
What is the firmware and ADSL (Modem Code) version of the 2820
What is the ADSL / VDSL modem code version of the 2862
Are they different

Are you on a non STD BT line.

As a general rule all lines regardless of your ISP are BT (Open Reach) Lines, some are not.

Try the non vectoring firmware version and the vector2 version, I would download ALL firmware versions in advance just in case you loose access to the net.

Have you, are you using the RST files to remove any hidden or rogue setting somewhere within the router.

I have the same two routers and i get the "Performing a TLS handshake to whatever" message for less than a second on all https requests using firefox on both routers.

Please Log in or Create an account to join the conversation.

  • dottedquad
  • Topic Author
  • Offline
  • Junior Member
  • Junior Member
More
07 Jun 2018 12:27 #9 by dottedquad

dansorion wrote: Have you got any CSM APP enforcement enabled?

I upgraded two 2830s with the latest firmware on Monday and found on Tuesday that many users kept having issues connecting to HTTPS/SSL services (websites, email, and others), and after using the Draytek Syslog server was able to see the CSM log entries indicating that connections were being blocked for the [LINE] rule. Also once a CSM block occurred I then saw a bunch of DOS blocks, looking to be due to the LAN PCs retrying packets to the HTTPS ports and as the connection was already broken from the CSM enforcement. I unticked the LINE protocol under IM Application in the default profile, and so far nobody has complained. Opened a support ticket about it with Draytek but yet to hear back. I suspect that the LINE IM profile was adjusted in a recent firmware and is falsely detecting legitimate HTTPS traffic

Might not be relevant, but I'd start by using the Draytek Syslog server and looking in the firewall logs under CSM Log and Defense Log.

Dan



I have just checked the CSM section of my 2862n's configuration pages. All seem to be at factory default settings. Certainly, I have not changed anything there. No profiles are activated. Also the 2862n's syslog doesn't have any messages about blocked connections in it.

Please Log in or Create an account to join the conversation.

  • dottedquad
  • Topic Author
  • Offline
  • Junior Member
  • Junior Member
More
07 Jun 2018 12:44 #10 by dottedquad

akwe-xavante wrote: What is the firmware and ADSL (Modem Code) version of the 2820
What is the ADSL / VDSL modem code version of the 2862
Are they different

Are you on a non STD BT line.

As a general rule all lines regardless of your ISP are BT (Open Reach) Lines, some are not.



I'm not using ADSL/VDSL to connect to the internet. Both my 2862n and my 2820n connect via their WAN2 ports and a WiFi ISP.


Try the non vectoring firmware version and the vector2 version, I would download ALL firmware versions in advance just in case you loose access to the net.


I don't understand what you mean here. Is it relevant to non VDSL/ADSL access?


Have you, are you using the RST files to remove any hidden or rogue setting somewhere within the router.


The 2862n was obtained brand new from http://www.broadbandbuyer.co.uk 5 days ago, and came with the 3.8.6_BT firmware. I configured it, tested it, and later upgraded to v3.8.8.2_BT using the ALL file, not the RST file. The MD5 and SHA1 checksums of the downloaded 3882_BT firmware zip file agreed with the checksums on Drayteks UK download site.
Would it be safe to upgrade using the RST file and then restore the config? Or should I apply RST and reconfigure afresh?


I have the same two routers and i get the "Performing a TLS handshake to whatever" message for less than a second on all https requests using firefox on both routers.



So, there's hope yet? I'm encouraged!

Martin

Please Log in or Create an account to join the conversation.

More
07 Jun 2018 12:51 #11 by x64

dottedquad wrote: Update: I have now updated to the latest firmware for the 2862n (3882_BT) and firefox still gets stuck trying to connect to the draytek forums displaying in its status bar the message "Performing a TLS handshake to forum.draytek.co.uk".

Martin


That sounds sickeningly familiar. If you are on WiFi (particularly thinking 5GHz), try using wired, or trying 2.4GHz.

Please Log in or Create an account to join the conversation.

  • dottedquad
  • Topic Author
  • Offline
  • Junior Member
  • Junior Member
More
07 Jun 2018 12:57 #12 by dottedquad

x64 wrote:

dottedquad wrote: Update: I have now updated to the latest firmware for the 2862n (3882_BT) and firefox still gets stuck trying to connect to the draytek forums displaying in its status bar the message "Performing a TLS handshake to forum.draytek.co.uk".

Martin


That sounds sickeningly familiar. If you are on WiFi (particularly thinking 5GHz), try using wired, or trying 2.4GHz.



Perhaps I wasn't clear? My PC is connected by wired ethernet to my 2820n and 2862n - they get internet access by a wifi ISP. Why should the use of a Wifi hop to the internet backbone affect the 2862n but not the 2820n?

Martin

Please Log in or Create an account to join the conversation.