Solved

Certain web sites will not load or load very slowly

Posted on 2003-12-05
11
433 Views
Last Modified: 2013-11-13
We have a LAN of about 100 machines mainly PCs with 5 Macs running OS 10.2. The LAN is connected to the internet via a router using NAT and a hardware firewall.
The Macs cannot load www.google.ie but can load www.google.com, they cannot load www.apple.com but can load www.yahoo.com. I can ping the "problem" sites from the Macs without any problems. I've looked at the akadns (akamei) link because both google and apple provide localised services and yahoo doesn't appear to.
I connected one Mac directly to the internet via dialup and it can connect to the "problem" sites without problems.
Has anyone seen this before and know any solution?
0
Comment
Question by:gcousins
  • 4
  • 3
  • 2
11 Comments
 
LVL 30

Expert Comment

by:weed
ID: 9883049
Probably doesnt make a difference but what browser are you using? Can you ftp to apple.com?
0
 

Author Comment

by:gcousins
ID: 9883145
IE 5.2 and Safari. The applets in OS X such as the help system (Sherlock? - Forgive me, I'm a PC admin) that draw down from apple.com don't work as well.
FTP works fast with the problem sites.
0
 
LVL 30

Expert Comment

by:weed
ID: 9883437
Almost like some sort of filter is in effect. Certain sites, and only HTTP traffic. No local firewall turned on for the OS X machines? No LittleSnitch installed?
0
 

Author Comment

by:gcousins
ID: 9883490
That's the strange thing, there's no local firewalls on the Macs and no-one here knows what LittleSnitch is.
I wonder if the localised "problem" sites are sending data on ports other than 80 just to Macs. Perhaps they're using UDP to send data once the page request has been made and our gateway firewall doesn't like it. The only problem with this thesis is why doesn't it effect the PCs.
0
Superior storage. Superior surveillance.

WD Purple drives are built for 24/7, always-on, high-definition security systems. With support for up to 8 hard drives and 32 cameras, WD Purple drives are optimized for surveillance.

 
LVL 4

Expert Comment

by:rogier
ID: 9891671
This looks really unusual. Perhaps your provider's MTU is exceeded loading these sites, I'm just thinking out loud. This is a known issue in 10.2, and you should update to 10.2.5 or later to solve it.

Also, try to connect to http://17.254.0.91/ and tell me if this works. This is apple.com but connecting this way you bypass the dns server... just to exclude that one from your list of possible errors... It is known that OS X responds slow or not at all when you don't have a dns server set in the network control panel.

good luck,
rogier.

p.s. little snitch is an application supervisor that avoids apps to phone home.
0
 

Author Comment

by:gcousins
ID: 9895629
Hi Rogier,

I did a bit of research on Saturday that pointed me towards the 10.2.5 update and how it promised to fix the DNS/UDP packet size error. We're applying the patch now on a clean machine and I'll let you know how we get on. We had applied an "all in" 10.2.2 to 10.2.8 patch to another machine but the problem remains so maybe we have to go to .5 first and then to .8.
We also found that if we use the sites IP addresses (bypassing the DNS) in the web browser, there's no problem. We run a windows 2000 DNS server with BIND secondaries on our network and have tried leaving the local search domain in and out, tried a local ISPs domain, tried with BIND secondaries and without and still no joy.
We may use local hosts files but I feel that a dynamic provider like akamai might not work well.
I'll keep you informed.
0
 
LVL 4

Expert Comment

by:rogier
ID: 9906431
As all works when bypassing the DNS I think we have localized the problem. I read you have tried to leave in and out the search domain, so I do suppose you have set the DNS server address as an IP no. But just in case not:

system preferences >>> show: build-in ethernet >>> TCP/IP tab.

good luck,
Rogier.
0
 

Author Comment

by:gcousins
ID: 9929453
Update: google.ie now loads but not apple.com. I found out the the UDP DNS packet has to be less than 500 bytes and if it's not the web page will hang while trying to load. The DNS server address is always set as an IP on our network.
Perhaps I'll never find an explanation or cure for this.
0
 
LVL 4

Accepted Solution

by:
rogier earned 500 total points
ID: 9932251
perhaps it's the built in firewall in OSX? try to reconfigure using sunshield:

http://homepage.mac.com/opalliere/shield_man.html

goodluck,
Rogier
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Short answer to this question: there is no effective WiFi manager in iOS devices as seen in Windows WiFi or Macbook OSx WiFi management, but this article will try and provide some amicable solutions to better suite your needs.
In this article we will discuss some EI Capitan Mail app issues and provide some manual process to resolve them.
This Micro Tutorial demonstrates using Microsoft Excel pivot tables, how to reverse engineer competitors' marketing strategies through backlinks.
With the power of JIRA, there's an unlimited number of ways you can customize it, use it and benefit from it. With that in mind, there's bound to be things that I wasn't able to cover in this course. With this summary we'll look at some places to go…

861 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

25 Experts available now in Live!

Get 1:1 Help Now