Solved

Certain web sites will not load or load very slowly

Posted on 2003-12-05
11
434 Views
Last Modified: 2013-11-13
We have a LAN of about 100 machines mainly PCs with 5 Macs running OS 10.2. The LAN is connected to the internet via a router using NAT and a hardware firewall.
The Macs cannot load www.google.ie but can load www.google.com, they cannot load www.apple.com but can load www.yahoo.com. I can ping the "problem" sites from the Macs without any problems. I've looked at the akadns (akamei) link because both google and apple provide localised services and yahoo doesn't appear to.
I connected one Mac directly to the internet via dialup and it can connect to the "problem" sites without problems.
Has anyone seen this before and know any solution?
0
Comment
Question by:gcousins
  • 4
  • 3
  • 2
11 Comments
 
LVL 30

Expert Comment

by:weed
ID: 9883049
Probably doesnt make a difference but what browser are you using? Can you ftp to apple.com?
0
 

Author Comment

by:gcousins
ID: 9883145
IE 5.2 and Safari. The applets in OS X such as the help system (Sherlock? - Forgive me, I'm a PC admin) that draw down from apple.com don't work as well.
FTP works fast with the problem sites.
0
 
LVL 30

Expert Comment

by:weed
ID: 9883437
Almost like some sort of filter is in effect. Certain sites, and only HTTP traffic. No local firewall turned on for the OS X machines? No LittleSnitch installed?
0
Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

 

Author Comment

by:gcousins
ID: 9883490
That's the strange thing, there's no local firewalls on the Macs and no-one here knows what LittleSnitch is.
I wonder if the localised "problem" sites are sending data on ports other than 80 just to Macs. Perhaps they're using UDP to send data once the page request has been made and our gateway firewall doesn't like it. The only problem with this thesis is why doesn't it effect the PCs.
0
 
LVL 4

Expert Comment

by:rogier
ID: 9891671
This looks really unusual. Perhaps your provider's MTU is exceeded loading these sites, I'm just thinking out loud. This is a known issue in 10.2, and you should update to 10.2.5 or later to solve it.

Also, try to connect to http://17.254.0.91/ and tell me if this works. This is apple.com but connecting this way you bypass the dns server... just to exclude that one from your list of possible errors... It is known that OS X responds slow or not at all when you don't have a dns server set in the network control panel.

good luck,
rogier.

p.s. little snitch is an application supervisor that avoids apps to phone home.
0
 

Author Comment

by:gcousins
ID: 9895629
Hi Rogier,

I did a bit of research on Saturday that pointed me towards the 10.2.5 update and how it promised to fix the DNS/UDP packet size error. We're applying the patch now on a clean machine and I'll let you know how we get on. We had applied an "all in" 10.2.2 to 10.2.8 patch to another machine but the problem remains so maybe we have to go to .5 first and then to .8.
We also found that if we use the sites IP addresses (bypassing the DNS) in the web browser, there's no problem. We run a windows 2000 DNS server with BIND secondaries on our network and have tried leaving the local search domain in and out, tried a local ISPs domain, tried with BIND secondaries and without and still no joy.
We may use local hosts files but I feel that a dynamic provider like akamai might not work well.
I'll keep you informed.
0
 
LVL 4

Expert Comment

by:rogier
ID: 9906431
As all works when bypassing the DNS I think we have localized the problem. I read you have tried to leave in and out the search domain, so I do suppose you have set the DNS server address as an IP no. But just in case not:

system preferences >>> show: build-in ethernet >>> TCP/IP tab.

good luck,
Rogier.
0
 

Author Comment

by:gcousins
ID: 9929453
Update: google.ie now loads but not apple.com. I found out the the UDP DNS packet has to be less than 500 bytes and if it's not the web page will hang while trying to load. The DNS server address is always set as an IP on our network.
Perhaps I'll never find an explanation or cure for this.
0
 
LVL 4

Accepted Solution

by:
rogier earned 500 total points
ID: 9932251
perhaps it's the built in firewall in OSX? try to reconfigure using sunshield:

http://homepage.mac.com/opalliere/shield_man.html

goodluck,
Rogier
0

Featured Post

Is Your AD Toolbox Looking More Like a Toybox?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

SUMMARY Enterprise backup in a heterogeneous network is a subject full of complications and restrictions. Issues such as filename & path structure, attributes and extended metadata always tend to complicate the subject to the extent where either …
Worried about if Apple can protect your documents, photos, and everything else that gets stored in iCloud? Read on to find out what Apple really uses to make things secure.
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.
Finds all prime numbers in a range requested and places them in a public primes() array. I've demostrated a template size of 30 (2 * 3 * 5) but larger templates can be built such 210  (2 * 3 * 5 * 7) or 2310  (2 * 3 * 5 * 7 * 11). The larger templa…

809 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question