Solved

Unable to access browser-based app from outside the firewall

Posted on 2014-03-04
4
262 Views
Last Modified: 2014-03-22
I cannot access/launch a browser-based app (Silverlight) from outside the router (i.e. Internet).  I am getting "This page can’t be displayed" error.
•I updated our external DNS record to point to the internal server FQDN.  When I ping the FQDN, it returns the external IP address of the router.
•On the router, I have port 443 forwarding to the IP address of the correct server.
•I turned off the server software firewalls, but still no joy.
•I installed a wildcard SSL certificate.

Again, everything works fine from within the router (without using lmhost file).  I think the problem may be DNS related, but other than what I've already done, what else might need to be changed?

Error:

This page can’t be displayed

•Make sure the web address https://server.domain.com is correct.
•Look for the page with your search engine.
•Refresh the page in a few minutes.
0
Comment
Question by:CPA_MCSE
  • 3
4 Comments
 
LVL 57

Expert Comment

by:Cliff Galiher
ID: 39904889
If it works within the network but not outside, two possibilities come to mind:

1) Silverlight, being an application framework, can open additional ports. You may need to forward more that 443. Whoever wrote your silverlight app should be able to provide more details.

2) Your router is not properly forwarding port 443. See if any traffic is hitting your server. Wireshark, netmon, or even IIS logs would be helpful here. In some cases, routers (and even some UTM devices) use 443 for management, and improperly configured, will not forward 443 at all because it assumes it is for management, and those rules supercede the port forwarding rules set up by users. Each router is different in this regard, so I can't get more specific.
0
 

Author Comment

by:CPA_MCSE
ID: 39905823
Thanks for the feedback.

1.  It is a default and by-the-book install of a Microsoft web app.  Documentation states only port 443 need be forwarded.

2.  Based on your feedback, I moved the server to a different subnet with a different physical router, set port-forwarding to the new internal IP address, and updated/tested the external DNS record for that server to point to the external IP address of that router.  I also turned off all software firewalls on the server.  Still no joy...

As the server is joined to a pristine W2012 R2 test domain with default settings, might there be something there I would need to change?  Grasping at straws here...
0
 

Accepted Solution

by:
CPA_MCSE earned 0 total points
ID: 39935480
ISP is blocking port 443.
0
 

Author Closing Comment

by:CPA_MCSE
ID: 39947226
My testing determined ISP is blocking port 443.
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

What to do when Windows Update is not working correctly? What tools can I use to detect the cause of the malfunction problem? What does this numeric error code mean? These and other questions that you have been asking in the past are answered here (…
These days, all we hear about hacktivists took down so and so websites and retrieved thousands of user’s data. One of the techniques to get unauthorized access to database is by performing SQL injection. This article is quite lengthy which gives bas…
In this Micro Tutorial viewers will learn how to use Windows Server Backup to create full image of their system. Tutorial shows how to install Windows Server Backup Feature on Windows 2012R2 and how to configure scheduled Bare Metal Recovery backup.…
This tutorial will walk an individual through the process of installing the necessary services and then configuring a Windows Server 2012 system as an iSCSI target. To install the necessary roles, go to Server Manager, and select Add Roles and Featu…

773 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question