Link to home
Start Free TrialLog in
Avatar of Fletch_r21
Fletch_r21Flag for United Kingdom of Great Britain and Northern Ireland

asked on

Netscaler VPN clients unable to connect to HTTPS websites via a Bluecoat Web Proxy server on port 80 (but it works on 8080)

Hi Guys

Our Netscaler VPN clients are able to connect to the network and  reach the Bluecoate Proxy on the network layer (port 80), but when we try to browse to HTTPS Internet websites, the connections seem to get dropped. Internet sites on HTTP work fine.

Our Bluecoat Proxy (hosted in a managed network that we have no access to) also listens on port 8080. if we configure the Netscalers to use the web proxy on port 8080, the issue is resolved. i.e. both HTTP and HTTPS work fine.

Unfortunately, we have a particular business requirement to get this working on port 80. Port 8080 can not be used at present.

Could anyone point me in the right direction?

Thanks

Mihail
Avatar of arnold
arnold
Flag of United States of America image

port 80 is an unsecured port, check whether your Netscreen detects and rejects the encrypted data within port 80 a rule that does not apply to 8080.

i.e. presumably the same business requirement requires the configuration on port 80 that causes your issue.

You are mixing two distinct technologies into the same channel.
https uses port 443 not port 80
Avatar of VRTX
VRTX

Thanks for your comment, Arnold.

We have tried to trace the traffic as it is leaving the netscaler for the BlueCoat webproxy and the conclusion was that no traffic was leaving the netscaler when we attempted to connect to HTTPS websites (it worked for http sites fine).

so I cant t "check whether the Netscreen detects and rejects the encrypted data within port 80" as it doesn't appear to be sending it out on port 80. Where would this rule be configured on the netscaler? Can we override it?

Many thanks

m
Also, the business requirement is for a Netscaler VPN client to be able to connect Outlook to their Office 365 mailbox via another Bluecoat web proxy that does not have port 8080 open. so we have to get it working for port 80...
Often deep inspection detects encrypted data going through port 80 as a concern......

Please check your logs whether you can locate event that sheds light on your situation.
Check with the vendor.
Avatar of Fletch_r21

ASKER

Arnold, do you mean check the logs on the BlueCoat proxy? we don't have access to these logs so it a bit problematic.

Last time we performed these assessment it was concluded that HTTPS traffic was not leaving the netscaler.  i.e. nothing was reaching the proxy when HTTP requests were made from the client.

If you were referring to the Netscaler (v11) logs, coudl you please clarify which ones?
p.s. the follwoing VRTX comments are mine:

Thanks for your comment, Arnold.

We have tried to trace the traffic as it is leaving the netscaler for the BlueCoat webproxy and the conclusion was that no traffic was leaving the netscaler when we attempted to connect to HTTPS websites (it worked for http sites fine).

so I cant t "check whether the Netscreen detects and rejects the encrypted data within port 80" as it doesn't appear to be sending it out on port 80. Where would this rule be configured on the netscaler? Can we override it?

Many thanks

----

Also, the business requirement is for a Netscaler VPN client to be able to connect Outlook to their Office 365 mailbox via another Bluecoat web proxy that does not have port 8080 open. so we have to get it working for port 80...
Can you check whether you are diverting port 443 traffic to a proxy via port 80?
Redirecting encrypted traffic is not possible as there is no way to access what the request is.
Usually, a proxy handler for secure communication merely establishes a tunnel/connection through which the client then negotiates the session with the end ..
Do you mean "are we diverting port 443 traffic to a proxy via port 80" using the Nescaler functionality? How can i check this?
How are proxy settings deployed in your environment? Are you using transparent mode diverting requests on port 80 to the proxy? If so what do you do for port 443 destined requests.  If you push proxy settings or publish them using DNS/DHCP
When you reference port 8080 is that an instance of net scalar that you configure to listen on that port ?often port 8080 is a tomcat unsecured port so it is unclear what you are comparing. As commonly both port 80 and 8080 are unencrypted data streams.

If you have a Linux/UNIX system, or instal, OpenSSL on a Windows system
From the command line in either run, openssl s_client -connect anysecureurl:443
And see what happens. Are you connected destination and can make request
HEAD HTTPS://www.theurl.com HTTP/1.1
HOst:
REferrer:
Hi There,

Found these two links.

http://docplayer.net/6624924-Blue-coat-security-first-steps-solution-for-controlling-https.html
http://discussions.citrix.com/topic/350825-netscaler-gateway-access-intermittent-access-problem/ (Check for bluecoat specifically).

Kindly confirm if the bluecoat device is deployed in transparent/explicit mode.
Arnold

Please see the results below of the OpenSSL Test you have asked us to run:

Internal LAN

OpenSSL> s_client -host www.google.co.uk -port 443
Loading 'screen' into random state - done
CONNECTED(00000168)
depth=2 /C=US/O=GeoTrust Inc./CN=GeoTrust Global CA
verify error:num=20:unable to get local issuer certificate
verify return:0
---
Certificate chain
 0 s:/C=US/ST=California/L=Mountain View/O=Google Inc/CN=google.com
   i:/C=US/O=Google Inc/CN=Google Internet Authority G2
 1 s:/C=US/O=Google Inc/CN=Google Internet Authority G2
   i:/C=US/O=GeoTrust Inc./CN=GeoTrust Global CA
 2 s:/C=US/O=GeoTrust Inc./CN=GeoTrust Global CA
   i:/C=US/O=Equifax/OU=Equifax Secure Certificate Authority
---
Server certificate
-----BEGIN CERTIFICATE-----
MIIgHDCCHwSgAwIBAgIIN7KozYlEyWEwDQYJKoZIhvcNAQELBQAwSTELMAkGA1UE
BhMCVVMxEzARBgNVBAoTCkdvb2dsZSBJbmMxJTAjBgNVBAMTHEdvb2dsZSBJbnRl
cm5ldCBBdXRob3JpdHkgRzIwHhcNMTYwNTA0MDkzMTAzWhcNMTYwNzI3MDgzOTAw
WjBkMQswCQYDVQQGEwJVUzETMBEGA1UECAwKQ2FsaWZvcm5pYTEWMBQGA1UEBwwN
TW91bnRhaW4gVmlldzETMBEGA1UECgwKR29vZ2xlIEluYzETMBEGA1UEAwwKZ29v
Z2xlLmNvbTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAMHfFzeHfak7
LBcmg8UXFIEnSNC/HW8UdX0A1PT8Gp/f49qOaNFlUOhKyeMc+D7dVpv6YiHvN3Fx
sgJHL0qKVvMF9h7fhO6UUlf2hLLBUKxnpdI5eIUsIw2XnISgGxxexa0iocznVw69
yad0fL3iS7y0atkiT1h6YNdqq1RFlOHH/L3UX9AOEliDSM9TKAjFXnSAasQ0cmuw
6dsnTjH6kozz1+nrQooyUEwTNyuMRaEEWdWf1FCg9pptIEMOo5+7ivX/7+zqK9dP
XXANjK0nM+WRs9xIyrvW3pGe5Iml+aOp4lnGLofGGp2j7M+CwNfq//6U60w1oaro
sijYat7zAW0CAwEAAaOCHOswghznMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEF
BQcDAjCCG7cGA1UdEQSCG64wghuqggpnb29nbGUuY29tggoqLjJtZG4ubmV0gg0q
LmFuZHJvaWQuY29tghYqLmFwcGVuZ2luZS5nb29nbGUuY29tghQqLmF1LmRvdWJs
ZWNsaWNrLm5ldIILKi5jYy1kdC5jb22CEiouY2xvdWQuZ29vZ2xlLmNvbYIUKi5k
ZS5kb3VibGVjbGljay5uZXSCESouZG91YmxlY2xpY2suY29tghEqLmRvdWJsZWNs
aWNrLm5ldIIVKi5mbHMuZG91YmxlY2xpY2submV0ghQqLmZyLmRvdWJsZWNsaWNr
Lm5ldIIWKi5nb29nbGUtYW5hbHl0aWNzLmNvbYILKi5nb29nbGUuYWOCCyouZ29v
Z2xlLmFkggsqLmdvb2dsZS5hZYILKi5nb29nbGUuYWaCCyouZ29vZ2xlLmFnggsq
Lmdvb2dsZS5hbIILKi5nb29nbGUuYW2CCyouZ29vZ2xlLmFzggsqLmdvb2dsZS5h
dIILKi5nb29nbGUuYXqCCyouZ29vZ2xlLmJhggsqLmdvb2dsZS5iZYILKi5nb29n
bGUuYmaCCyouZ29vZ2xlLmJnggsqLmdvb2dsZS5iaYILKi5nb29nbGUuYmqCCyou
Z29vZ2xlLmJzggsqLmdvb2dsZS5idIILKi5nb29nbGUuYnmCCyouZ29vZ2xlLmNh
ggwqLmdvb2dsZS5jYXSCCyouZ29vZ2xlLmNjggsqLmdvb2dsZS5jZIILKi5nb29n
bGUuY2aCCyouZ29vZ2xlLmNnggsqLmdvb2dsZS5jaIILKi5nb29nbGUuY2mCCyou
Z29vZ2xlLmNsggsqLmdvb2dsZS5jbYILKi5nb29nbGUuY26CDiouZ29vZ2xlLmNv
LmFvgg4qLmdvb2dsZS5jby5id4IOKi5nb29nbGUuY28uY2uCDiouZ29vZ2xlLmNv
LmNygg4qLmdvb2dsZS5jby5odYIOKi5nb29nbGUuY28uaWSCDiouZ29vZ2xlLmNv
Lmlsgg4qLmdvb2dsZS5jby5pbYIOKi5nb29nbGUuY28uaW6CDiouZ29vZ2xlLmNv
Lmplgg4qLmdvb2dsZS5jby5qcIIOKi5nb29nbGUuY28ua2WCDiouZ29vZ2xlLmNv
Lmtygg4qLmdvb2dsZS5jby5sc4IOKi5nb29nbGUuY28ubWGCDiouZ29vZ2xlLmNv
Lm16gg4qLmdvb2dsZS5jby5ueoIOKi5nb29nbGUuY28udGiCDiouZ29vZ2xlLmNv
LnR6gg4qLmdvb2dsZS5jby51Z4IOKi5nb29nbGUuY28udWuCDiouZ29vZ2xlLmNv
LnV6gg4qLmdvb2dsZS5jby52ZYIOKi5nb29nbGUuY28udmmCDiouZ29vZ2xlLmNv
Lnphgg4qLmdvb2dsZS5jby56bYIOKi5nb29nbGUuY28ueneCDCouZ29vZ2xlLmNv
bYIPKi5nb29nbGUuY29tLmFmgg8qLmdvb2dsZS5jb20uYWeCDyouZ29vZ2xlLmNv
bS5haYIPKi5nb29nbGUuY29tLmFygg8qLmdvb2dsZS5jb20uYXWCDyouZ29vZ2xl
LmNvbS5iZIIPKi5nb29nbGUuY29tLmJogg8qLmdvb2dsZS5jb20uYm6CDyouZ29v
Z2xlLmNvbS5ib4IPKi5nb29nbGUuY29tLmJygg8qLmdvb2dsZS5jb20uYnmCDyou
Z29vZ2xlLmNvbS5ieoIPKi5nb29nbGUuY29tLmNugg8qLmdvb2dsZS5jb20uY2+C
DyouZ29vZ2xlLmNvbS5jdYIPKi5nb29nbGUuY29tLmN5gg8qLmdvb2dsZS5jb20u
ZG+CDyouZ29vZ2xlLmNvbS5lY4IPKi5nb29nbGUuY29tLmVngg8qLmdvb2dsZS5j
b20uZXSCDyouZ29vZ2xlLmNvbS5maoIPKi5nb29nbGUuY29tLmdlgg8qLmdvb2ds
ZS5jb20uZ2iCDyouZ29vZ2xlLmNvbS5naYIPKi5nb29nbGUuY29tLmdygg8qLmdv
b2dsZS5jb20uZ3SCDyouZ29vZ2xlLmNvbS5oa4IPKi5nb29nbGUuY29tLmlxgg8q
Lmdvb2dsZS5jb20uam2CDyouZ29vZ2xlLmNvbS5qb4IPKi5nb29nbGUuY29tLmto
gg8qLmdvb2dsZS5jb20ua3eCDyouZ29vZ2xlLmNvbS5sYoIPKi5nb29nbGUuY29t
Lmx5gg8qLmdvb2dsZS5jb20ubW2CDyouZ29vZ2xlLmNvbS5tdIIPKi5nb29nbGUu
Y29tLm14gg8qLmdvb2dsZS5jb20ubXmCDyouZ29vZ2xlLmNvbS5uYYIPKi5nb29n
bGUuY29tLm5mgg8qLmdvb2dsZS5jb20ubmeCDyouZ29vZ2xlLmNvbS5uaYIPKi5n
b29nbGUuY29tLm5wgg8qLmdvb2dsZS5jb20ubnKCDyouZ29vZ2xlLmNvbS5vbYIP
Ki5nb29nbGUuY29tLnBhgg8qLmdvb2dsZS5jb20ucGWCDyouZ29vZ2xlLmNvbS5w
Z4IPKi5nb29nbGUuY29tLnBogg8qLmdvb2dsZS5jb20ucGuCDyouZ29vZ2xlLmNv
bS5wbIIPKi5nb29nbGUuY29tLnBygg8qLmdvb2dsZS5jb20ucHmCDyouZ29vZ2xl
LmNvbS5xYYIPKi5nb29nbGUuY29tLnJ1gg8qLmdvb2dsZS5jb20uc2GCDyouZ29v
Z2xlLmNvbS5zYoIPKi5nb29nbGUuY29tLnNngg8qLmdvb2dsZS5jb20uc2yCDyou
Z29vZ2xlLmNvbS5zdoIPKi5nb29nbGUuY29tLnRqgg8qLmdvb2dsZS5jb20udG6C
DyouZ29vZ2xlLmNvbS50coIPKi5nb29nbGUuY29tLnR3gg8qLmdvb2dsZS5jb20u
dWGCDyouZ29vZ2xlLmNvbS51eYIPKi5nb29nbGUuY29tLnZjgg8qLmdvb2dsZS5j
b20udmWCDyouZ29vZ2xlLmNvbS52boILKi5nb29nbGUuY3aCCyouZ29vZ2xlLmN6
ggsqLmdvb2dsZS5kZYILKi5nb29nbGUuZGqCCyouZ29vZ2xlLmRrggsqLmdvb2ds
ZS5kbYILKi5nb29nbGUuZHqCCyouZ29vZ2xlLmVlggsqLmdvb2dsZS5lc4IMKi5n
b29nbGUuZXVzggsqLmdvb2dsZS5maYILKi5nb29nbGUuZm2CCyouZ29vZ2xlLmZy
ggwqLmdvb2dsZS5mcmyCCyouZ29vZ2xlLmdhggwqLmdvb2dsZS5nYWyCCyouZ29v
Z2xlLmdlggsqLmdvb2dsZS5nZ4ILKi5nb29nbGUuZ2yCCyouZ29vZ2xlLmdtggsq
Lmdvb2dsZS5ncIILKi5nb29nbGUuZ3KCCyouZ29vZ2xlLmd5ggsqLmdvb2dsZS5o
a4ILKi5nb29nbGUuaG6CCyouZ29vZ2xlLmhyggsqLmdvb2dsZS5odIILKi5nb29n
bGUuaHWCCyouZ29vZ2xlLmllggsqLmdvb2dsZS5pbYILKi5nb29nbGUuaW6CDSou
Z29vZ2xlLmluZm+CCyouZ29vZ2xlLmlxggsqLmdvb2dsZS5pcoILKi5nb29nbGUu
aXOCCyouZ29vZ2xlLml0gg4qLmdvb2dsZS5pdC5hb4ILKi5nb29nbGUuamWCCyou
Z29vZ2xlLmpvgg0qLmdvb2dsZS5qb2JzggsqLmdvb2dsZS5qcIILKi5nb29nbGUu
a2eCCyouZ29vZ2xlLmtpggsqLmdvb2dsZS5reoILKi5nb29nbGUubGGCCyouZ29v
Z2xlLmxpggsqLmdvb2dsZS5sa4ILKi5nb29nbGUubHSCCyouZ29vZ2xlLmx1ggsq
Lmdvb2dsZS5sdoILKi5nb29nbGUubWSCCyouZ29vZ2xlLm1lggsqLmdvb2dsZS5t
Z4ILKi5nb29nbGUubWuCCyouZ29vZ2xlLm1sggsqLmdvb2dsZS5tboILKi5nb29n
bGUubXOCCyouZ29vZ2xlLm11ggsqLmdvb2dsZS5tdoILKi5nb29nbGUubXeCCyou
Z29vZ2xlLm5lgg4qLmdvb2dsZS5uZS5qcIIMKi5nb29nbGUubmV0ggsqLmdvb2ds
ZS5uZ4ILKi5nb29nbGUubmyCCyouZ29vZ2xlLm5vggsqLmdvb2dsZS5ucoILKi5n
b29nbGUubnWCDyouZ29vZ2xlLm9mZi5haYILKi5nb29nbGUucGuCCyouZ29vZ2xl
LnBsggsqLmdvb2dsZS5wboILKi5nb29nbGUucHOCCyouZ29vZ2xlLnB0ggsqLmdv
b2dsZS5yb4ILKi5nb29nbGUucnOCCyouZ29vZ2xlLnJ1ggsqLmdvb2dsZS5yd4IL
Ki5nb29nbGUuc2OCCyouZ29vZ2xlLnNlggsqLmdvb2dsZS5zaIILKi5nb29nbGUu
c2mCCyouZ29vZ2xlLnNrggsqLmdvb2dsZS5zbYILKi5nb29nbGUuc26CCyouZ29v
Z2xlLnNvggsqLmdvb2dsZS5zcoILKi5nb29nbGUuc3SCCyouZ29vZ2xlLnRkggwq
Lmdvb2dsZS50ZWyCCyouZ29vZ2xlLnRnggsqLmdvb2dsZS50a4ILKi5nb29nbGUu
dGyCCyouZ29vZ2xlLnRtggsqLmdvb2dsZS50boILKi5nb29nbGUudG+CCyouZ29v
Z2xlLnR0ggsqLmdvb2dsZS51YYILKi5nb29nbGUudXOCCyouZ29vZ2xlLnV6ggsq
Lmdvb2dsZS52Z4ILKi5nb29nbGUudnWCCyouZ29vZ2xlLndzghIqLmdvb2dsZWFk
YXBpcy5jb22CFSouZ29vZ2xlYWRzc2VydmluZy5jboIPKi5nb29nbGVhcGlzLmNu
ghQqLmdvb2dsZWNvbW1lcmNlLmNvbYIWKi5nb29nbGV1c2VyY29udGVudC5jboIR
Ki5nb29nbGV2aWRlby5jb22CDCouZ3N0YXRpYy5jboINKi5nc3RhdGljLmNvbYIK
Ki5ndnQxLmNvbYIKKi5ndnQyLmNvbYIUKi5qcC5kb3VibGVjbGljay5uZXSCFCou
bWV0cmljLmdzdGF0aWMuY29tghQqLnVrLmRvdWJsZWNsaWNrLm5ldIIMKi51cmNo
aW4uY29tghAqLnVybC5nb29nbGUuY29tghYqLnlvdXR1YmUtbm9jb29raWUuY29t
gg0qLnlvdXR1YmUuY29tghYqLnlvdXR1YmVlZHVjYXRpb24uY29tggsqLnl0aW1n
LmNvbYIVYWQubW8uZG91YmxlY2xpY2submV0ghphbmRyb2lkLmNsaWVudHMuZ29v
Z2xlLmNvbYILYW5kcm9pZC5jb22CD2RvdWJsZWNsaWNrLm5ldIIEZy5jb4IGZ29v
LmdsghRnb29nbGUtYW5hbHl0aWNzLmNvbYIJZ29vZ2xlLmFjgglnb29nbGUuYWSC
CWdvb2dsZS5hZYIJZ29vZ2xlLmFmgglnb29nbGUuYWeCCWdvb2dsZS5hbIIJZ29v
Z2xlLmFtgglnb29nbGUuYXOCCWdvb2dsZS5hdIIJZ29vZ2xlLmF6gglnb29nbGUu
YmGCCWdvb2dsZS5iZYIJZ29vZ2xlLmJmgglnb29nbGUuYmeCCWdvb2dsZS5iaYIJ
Z29vZ2xlLmJqgglnb29nbGUuYnOCCWdvb2dsZS5idIIJZ29vZ2xlLmJ5gglnb29n
bGUuY2GCCmdvb2dsZS5jYXSCCWdvb2dsZS5jY4IJZ29vZ2xlLmNkgglnb29nbGUu
Y2aCCWdvb2dsZS5jZ4IJZ29vZ2xlLmNogglnb29nbGUuY2mCCWdvb2dsZS5jbIIJ
Z29vZ2xlLmNtgglnb29nbGUuY26CDGdvb2dsZS5jby5hb4IMZ29vZ2xlLmNvLmJ3
ggxnb29nbGUuY28uY2uCDGdvb2dsZS5jby5jcoIMZ29vZ2xlLmNvLmh1ggxnb29n
bGUuY28uaWSCDGdvb2dsZS5jby5pbIIMZ29vZ2xlLmNvLmltggxnb29nbGUuY28u
aW6CDGdvb2dsZS5jby5qZYIMZ29vZ2xlLmNvLmpwggxnb29nbGUuY28ua2WCDGdv
b2dsZS5jby5rcoIMZ29vZ2xlLmNvLmxzggxnb29nbGUuY28ubWGCDGdvb2dsZS5j
by5teoIMZ29vZ2xlLmNvLm56ggxnb29nbGUuY28udGiCDGdvb2dsZS5jby50eoIM
Z29vZ2xlLmNvLnVnggxnb29nbGUuY28udWuCDGdvb2dsZS5jby51eoIMZ29vZ2xl
LmNvLnZlggxnb29nbGUuY28udmmCDGdvb2dsZS5jby56YYIMZ29vZ2xlLmNvLnpt
ggxnb29nbGUuY28ueneCDWdvb2dsZS5jb20uYWaCDWdvb2dsZS5jb20uYWeCDWdv
b2dsZS5jb20uYWmCDWdvb2dsZS5jb20uYXKCDWdvb2dsZS5jb20uYXWCDWdvb2ds
ZS5jb20uYmSCDWdvb2dsZS5jb20uYmiCDWdvb2dsZS5jb20uYm6CDWdvb2dsZS5j
b20uYm+CDWdvb2dsZS5jb20uYnKCDWdvb2dsZS5jb20uYnmCDWdvb2dsZS5jb20u
YnqCDWdvb2dsZS5jb20uY26CDWdvb2dsZS5jb20uY2+CDWdvb2dsZS5jb20uY3WC
DWdvb2dsZS5jb20uY3mCDWdvb2dsZS5jb20uZG+CDWdvb2dsZS5jb20uZWOCDWdv
b2dsZS5jb20uZWeCDWdvb2dsZS5jb20uZXSCDWdvb2dsZS5jb20uZmqCDWdvb2ds
ZS5jb20uZ2WCDWdvb2dsZS5jb20uZ2iCDWdvb2dsZS5jb20uZ2mCDWdvb2dsZS5j
b20uZ3KCDWdvb2dsZS5jb20uZ3SCDWdvb2dsZS5jb20uaGuCDWdvb2dsZS5jb20u
aXGCDWdvb2dsZS5jb20uam2CDWdvb2dsZS5jb20uam+CDWdvb2dsZS5jb20ua2iC
DWdvb2dsZS5jb20ua3eCDWdvb2dsZS5jb20ubGKCDWdvb2dsZS5jb20ubHmCDWdv
b2dsZS5jb20ubW2CDWdvb2dsZS5jb20ubXSCDWdvb2dsZS5jb20ubXiCDWdvb2ds
ZS5jb20ubXmCDWdvb2dsZS5jb20ubmGCDWdvb2dsZS5jb20ubmaCDWdvb2dsZS5j
b20ubmeCDWdvb2dsZS5jb20ubmmCDWdvb2dsZS5jb20ubnCCDWdvb2dsZS5jb20u
bnKCDWdvb2dsZS5jb20ub22CDWdvb2dsZS5jb20ucGGCDWdvb2dsZS5jb20ucGWC
DWdvb2dsZS5jb20ucGeCDWdvb2dsZS5jb20ucGiCDWdvb2dsZS5jb20ucGuCDWdv
b2dsZS5jb20ucGyCDWdvb2dsZS5jb20ucHKCDWdvb2dsZS5jb20ucHmCDWdvb2ds
ZS5jb20ucWGCDWdvb2dsZS5jb20ucnWCDWdvb2dsZS5jb20uc2GCDWdvb2dsZS5j
b20uc2KCDWdvb2dsZS5jb20uc2eCDWdvb2dsZS5jb20uc2yCDWdvb2dsZS5jb20u
c3aCDWdvb2dsZS5jb20udGqCDWdvb2dsZS5jb20udG6CDWdvb2dsZS5jb20udHKC
DWdvb2dsZS5jb20udHeCDWdvb2dsZS5jb20udWGCDWdvb2dsZS5jb20udXmCDWdv
b2dsZS5jb20udmOCDWdvb2dsZS5jb20udmWCDWdvb2dsZS5jb20udm6CCWdvb2ds
ZS5jdoIJZ29vZ2xlLmN6gglnb29nbGUuZGWCCWdvb2dsZS5kaoIJZ29vZ2xlLmRr
gglnb29nbGUuZG2CCWdvb2dsZS5keoIJZ29vZ2xlLmVlgglnb29nbGUuZXOCCmdv
b2dsZS5ldXOCCWdvb2dsZS5maYIJZ29vZ2xlLmZtgglnb29nbGUuZnKCCmdvb2ds
ZS5mcmyCCWdvb2dsZS5nYYIKZ29vZ2xlLmdhbIIJZ29vZ2xlLmdlgglnb29nbGUu
Z2eCCWdvb2dsZS5nbIIJZ29vZ2xlLmdtgglnb29nbGUuZ3CCCWdvb2dsZS5ncoIJ
Z29vZ2xlLmd5gglnb29nbGUuaGuCCWdvb2dsZS5oboIJZ29vZ2xlLmhygglnb29n
bGUuaHSCCWdvb2dsZS5odYIJZ29vZ2xlLmllgglnb29nbGUuaW2CCWdvb2dsZS5p
boILZ29vZ2xlLmluZm+CCWdvb2dsZS5pcYIJZ29vZ2xlLmlygglnb29nbGUuaXOC
CWdvb2dsZS5pdIIMZ29vZ2xlLml0LmFvgglnb29nbGUuamWCCWdvb2dsZS5qb4IL
Z29vZ2xlLmpvYnOCCWdvb2dsZS5qcIIJZ29vZ2xlLmtngglnb29nbGUua2mCCWdv
b2dsZS5reoIJZ29vZ2xlLmxhgglnb29nbGUubGmCCWdvb2dsZS5sa4IJZ29vZ2xl
Lmx0gglnb29nbGUubHWCCWdvb2dsZS5sdoIJZ29vZ2xlLm1kgglnb29nbGUubWWC
CWdvb2dsZS5tZ4IJZ29vZ2xlLm1rgglnb29nbGUubWyCCWdvb2dsZS5tboIJZ29v
Z2xlLm1zgglnb29nbGUubXWCCWdvb2dsZS5tdoIJZ29vZ2xlLm13gglnb29nbGUu
bmWCDGdvb2dsZS5uZS5qcIIKZ29vZ2xlLm5ldIIJZ29vZ2xlLm5ngglnb29nbGUu
bmyCCWdvb2dsZS5ub4IJZ29vZ2xlLm5ygglnb29nbGUubnWCDWdvb2dsZS5vZmYu
YWmCCWdvb2dsZS5wa4IJZ29vZ2xlLnBsgglnb29nbGUucG6CCWdvb2dsZS5wc4IJ
Z29vZ2xlLnB0gglnb29nbGUucm+CCWdvb2dsZS5yc4IJZ29vZ2xlLnJ1gglnb29n
bGUucneCCWdvb2dsZS5zY4IJZ29vZ2xlLnNlgglnb29nbGUuc2iCCWdvb2dsZS5z
aYIJZ29vZ2xlLnNrgglnb29nbGUuc22CCWdvb2dsZS5zboIJZ29vZ2xlLnNvggln
b29nbGUuc3KCCWdvb2dsZS5zdIIJZ29vZ2xlLnRkggpnb29nbGUudGVsgglnb29n
bGUudGeCCWdvb2dsZS50a4IJZ29vZ2xlLnRsgglnb29nbGUudG2CCWdvb2dsZS50
boIJZ29vZ2xlLnRvgglnb29nbGUudHSCCWdvb2dsZS51YYIJZ29vZ2xlLnVzggln
b29nbGUudXqCCWdvb2dsZS52Z4IJZ29vZ2xlLnZ1gglnb29nbGUud3OCEmdvb2ds
ZWNvbW1lcmNlLmNvbYILZ3N0YXRpYy5jb22CCnVyY2hpbi5jb22CCnd3dy5nb28u
Z2yCCHlvdXR1LmJlggt5b3V0dWJlLmNvbYIUeW91dHViZWVkdWNhdGlvbi5jb20w
aAYIKwYBBQUHAQEEXDBaMCsGCCsGAQUFBzAChh9odHRwOi8vcGtpLmdvb2dsZS5j
b20vR0lBRzIuY3J0MCsGCCsGAQUFBzABhh9odHRwOi8vY2xpZW50czEuZ29vZ2xl
LmNvbS9vY3NwMB0GA1UdDgQWBBSphhyVpAksALDLWyZVebWsBUMUQDAMBgNVHRMB
Af8EAjAAMB8GA1UdIwQYMBaAFErdBhYbvPZotXb1gba7Yhq6WoEvMCEGA1UdIAQa
MBgwDAYKKwYBBAHWeQIFATAIBgZngQwBAgIwMAYDVR0fBCkwJzAloCOgIYYfaHR0
cDovL3BraS5nb29nbGUuY29tL0dJQUcyLmNybDANBgkqhkiG9w0BAQsFAAOCAQEA
SV9bUhHH3s0Nb//cZIkX02UUV0g4JaHNToF0OowCwbyI5E1CNfTslm+D9JNFecRr
j+KgZ7osZutGQem4Nnj1ViP1VcdVxN+6uCXVxRraAswTvyIQ0nsuZu02ptGPMD5j
g/vvP7YYIFAkQMLdhCxfpkY4jFTnhW6uBjZoPVEMVcQ9HupKy5wrJP3+7QR7sQQI
QgaPbmBpztGyayqT/Qf7ABBmUK/ZVaiXvmMrFr4/QET0ZHAXBspgwjxKeUUH3mOl
6eJRrzv4sJGN9y6Y0047I/gfQux7eaOACdOnCOXkJRlC6pAInNzZ5JwawNekvl11
3bZCaJ2MZ1bgPu3wIQ0wbw==
-----END CERTIFICATE-----
subject=/C=US/ST=California/L=Mountain View/O=Google Inc/CN=google.com
issuer=/C=US/O=Google Inc/CN=Google Internet Authority G2
---
No client certificate CA names sent
---
SSL handshake has read 10301 bytes and written 450 bytes
---
New, TLSv1/SSLv3, Cipher is AES128-SHA
Server public key is 2048 bit
Compression: NONE
Expansion: NONE
SSL-Session:
    Protocol  : TLSv1
    Cipher    : AES128-SHA
    Session-ID: 9808F335C451E449F655C77AB3C5A9B6E0B491C9E0A2C42708D76B4EDED0ED47

    Session-ID-ctx:
    Master-Key: 224B42CC4E5BFE1FEC6169B7E2A2B3B073B20BD2E3D7BDD82CC2B69ED6CFCCBC
99896ED725E240A172AE45EEB297058D
    Key-Arg   : None
    Start Time: 1463068023
    Timeout   : 300 (sec)
    Verify return code: 20 (unable to get local issuer certificate)
---
read:errno=0

Over the Netscaler VPN

penSSL> s_client -host www.google.co.uk -port 443
Loading 'screen' into random state - done
connect: Bad file descriptor
connect:errno=10060
error in s_client

Thanks

Rich
I am not sure wheter openssl "detects" the proxy and adjusts or fails..

One option is to try proxytunnel http://proxytunnel.sourceforge.net/intro.php to see whether it
ASKER CERTIFIED SOLUTION
Avatar of Fletch_r21
Fletch_r21
Flag of United Kingdom of Great Britain and Northern Ireland image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Thanks for updating
Solution was found internally, however sharing on here for other users.