?
Solved

Certain HTTPS sites will not load - no errors - company wide

Posted on 2014-01-17
5
Medium Priority
?
333 Views
Last Modified: 2014-01-22
Environment:
Servers: Windows 2008 R2 Enterprise, Hyper-V, one virtual machine is office domain controller, another slice is Exchange.

Back Story:
On Monday, on of our techs performed a driver update on the Hyper-V's NICs.  Starting then, mail would not flow inbound.  About the same time (not entirely sure), IE stopped working properly.  Tuesday evening, we found that, if we modified the MTU on the network to 1464, we could get mail flowing.  The change was made on the firewall, not the server.

Wed/Thu: IE was working except for some HTTPS sites (ex: https://orders.dominos.com).  Others worked fine (https://secure.experts-exchange.com).  Lots of stuff was done to fix this - including replacing the firewall - EXCEPT removing the updated NIC driver.

Friday:  Still happening on all systems on the network (not just the servers).

Does anyone have a clue?  Could it be the NIC driver on the Hyper-V?  How would that cause other workstations to fail?  I am going to look into removing the driver update but I am not yet convinced it is the problem (not this one anyway).

The NIC is an HP NC382i and the driver is 7.8.21.0.

Help?
0
Comment
Question by:crapshooter
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
5 Comments
 

Author Comment

by:crapshooter
ID: 39789733
FYI: I just rolled back to the previous driver.  No change in behavior.
0
 
LVL 47

Accepted Solution

by:
Craig Beck earned 2000 total points
ID: 39790421
Can you try setting the MTU back to 1500 on the firewall, then see what you get when you use the following command on the mail server...

ping www.google.com -f -l 1472
0
 

Author Comment

by:crapshooter
ID: 39791315
OK, it seems to have worked.  Still waiting for confirmation from the client.  Why did you choose that specific packet size?
0
 
LVL 47

Expert Comment

by:Craig Beck
ID: 39791330
1472 is the maximum packet size which will pass through a standard Ethernet port (before overheads are applied)

If you can pass a packet with a size of 1472 bytes at the ping command it will tell you that MTU is fine across the network.

Now that you've set the MTU back to 1500 are you still seeing the problem?
0
 

Author Comment

by:crapshooter
ID: 39795317
Nope.  At 1500, all is well.  I wonder if the systems were trying to send SSL packets that were larger than what the firewall would handle and the firewall dropped them.  Still, it only happened for some SSL sites.  And it was consistent across all systems on the network.  So it is still pretty weird.
0

Featured Post

Veeam Disaster Recovery in Microsoft Azure

Veeam PN for Microsoft Azure is a FREE solution designed to simplify and automate the setup of a DR site in Microsoft Azure using lightweight software-defined networking. It reduces the complexity of VPN deployments and is designed for businesses of ALL sizes.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I was supporting a handful of Windows 2008 (non-R2) 2 node clusters with shared quorum disks. Some had SQL 2008 installed and some were just a vendor application that we supported. For the purposes of this article it doesn’t really matter which so w…
You might have come across a situation when you have Exchange 2013 server in two different sites (Production and DR). After adding the Database copy in ECP console it displays Database copy status unknown for the DR exchange server. Issue is strange…
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This tutorial will walk an individual through setting the global and backup job media overwrite and protection periods in Backup Exec 2012. Log onto the Backup Exec Central Administration Server. Examine the services. If all or most of them are stop…

719 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question