Cable Forum

Cable Forum (https://www.cableforum.uk/board/index.php)
-   Virgin Media Internet Service (https://www.cableforum.uk/board/forumdisplay.php?f=12)
-   -   screwed ACL on guildford proxy (https://www.cableforum.uk/board/showthread.php?t=4715)

Frank 29-11-2003 18:47

screwed ACL on guildford proxy
 
I access webmail via https on port 2096.

Using the cache cache3-glfd.server.ntli.net I get the error:
Quote:

Forbidden

You were denied access because:
Access denied by access control list.


Any ideas as to why? This webmail works fine using another cache.

Paul 29-11-2003 18:51

Re: screwed ACL on guildford proxy
 
Oops edit time;

I just noticed its https - remove the proxy server from https in your settings, you only need it for http.

Frank 29-11-2003 18:59

Re: screwed ACL on guildford proxy
 
Quote:

Originally Posted by pem
I just noticed its https - remove the proxy server from https in your settings, you only need it for http.

Well yeah I take your point.

BUT... The cache should not be intercepting requests on port 2096 anyway. This behaviour is displayed on all guildford caches too, but not other ntl caches.

Also, the fact that the cache should not be intercepting this https traffic is proven by other caches working without needing to implement the suggestion above (you are right by the way for normal ssl traffic, but cos it's on port 2096 this shouldn't be needed).

Which leads me to believe it is broken. I've also been using this cache for the last month or so and it has only broken today - nothing has changed on my PC grrr

Frank 29-11-2003 19:08

Re: screwed ACL on guildford proxy
 
Sorry, let me add Bristol to the list of screwed caches.
Quote:

Tunnel or SSL Forbidden

Description: 2096 is not an allowed port for Tunnel or SSL connections


Some consistent failures please ntl? :)

Paul 29-11-2003 19:32

Re: screwed ACL on guildford proxy
 
Quote:

Originally Posted by Keyser
Well yeah I take your point.

BUT... The cache should not be intercepting requests on port 2096 anyway. This behaviour is displayed on all guildford caches too, but not other ntl caches.

Also, the fact that the cache should not be intercepting this https traffic is proven by other caches working without needing to implement the suggestion above (you are right by the way for normal ssl traffic, but cos it's on port 2096 this shouldn't be needed).

Which leads me to believe it is broken. I've also been using this cache for the last month or so and it has only broken today - nothing has changed on my PC grrr

If you are manually setting your proxy and have it set for https as well as http then it is not a case of the cache intercepting it - you are forcing your https traffic to use the cache - and it is responding exactly as I would expect it to (on a port other than 443).

If it worked before then TBH I would say that was a fault or very poor security setting which they seem to have corrected.

Proxy servers will not normally respond to http or https requests on non standard ports - to prevent them being abused (like by spammers for instance).

MetaWraith 29-11-2003 19:52

Re: screwed ACL on guildford proxy
 
Quote:

Originally Posted by Keyser
Sorry, let me add Bristol to the list of screwed caches.
[/b][/font]

Some consistent failures please ntl? :)

ssssssshhhhhhhh dont give them ideas.


All times are GMT. The time now is 19:23.

Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2026, vBulletin Solutions Inc.
All Posts and Content are © Cable Forum