Results 1 to 10 of 10
  1. #1
    Master Untangler carboncow's Avatar
    Join Date
    Aug 2011
    Location
    Central Ohio
    Posts
    124

    Default user claims blocking yahoo! mail

    Please look at the screenshot and tell me this is not what I would see if Untangle is blocking a site. I've seen the proxy page that comes up if someone tries to view banned content.

    This user claims he cannot send Yahoo! webmail since the new Firewall went live last week. As you can see form my screenshot I have little blocked in the Web Filter and I"m not even flagging webmail!

    Is there anywhere else I should look in a log or is this clearly a Yahoo! issue of sorts?

    You guys will get a kick out of the request I got from one of my users...

    Subject: Computer Performance Issues Need Fixed!
    Body: Cannot send email

    1. The user sent me an email from this account just fine!
    2. We'll assume he met cannot get the email outside our LAN, which I remote'd into his PC and tested just fine to my personal account, check.
    3. While I remote'd in I saw the error message from his Yahoo! webmail account...so we'll assume this is the issue he's talking about. So I'm not sure what this has todo with "computer performance" as he noted in the subject.

    hahahaha! but I digress...
    Attached Images Attached Images

  2. #2
    some dude hlarsen's Avatar
    Join Date
    Jul 2010
    Location
    sfba
    Posts
    1,323

    Default

    it's probably Intrusion Prevention, look at the Event Log.
    Attention: Support on the Untangle Forums is provided by volunteers and community members.
    If you need official Untangle support please call or email support@untangle.com.

  3. #3
    Master Untangler jcoehoorn's Avatar
    Join Date
    Mar 2010
    Location
    York, NE
    Posts
    616

    Default

    I've seen this first hand when using protocol control to block socks 5 proxys. Something in Yahoo mail is flagged as a false-positive for SOCKS5.

    If you want to block socks 5 and still allow yahoo mail, you have to use the bandwidth control app to throttle SOCKS5 links down to speed that are unusable for actual traffic, and leave just enough bandwidth there for the single request in yahoo that trips the socks 5 filter as a false positive to finish.
    Four time Microsoft ASP.Net MVP managing an IBM System x3250 / X3440 / 8GB with Untangle 9.4 to protect 40Mbits for 450+ residential college students and associated staff and faculty

  4. #4
    Untangle Junkie dmorris's Avatar
    Join Date
    Nov 2006
    Location
    San Mateo, CA
    Posts
    11,754

    Default

    The rule interfering with yahoo was removed from everyone in 9.0.2

    edit: jcoehoorn may be onto something:
    http://forums.untangle.com/protocol-...l-control.html
    Attention: Support and help on the Untangle Forums is provided by volunteers and community members like yourself.
    If you need Untangle support please call or email support@untangle.com

  5. #5
    Master Untangler carboncow's Avatar
    Join Date
    Aug 2011
    Location
    Central Ohio
    Posts
    124

    Default

    Yep you nailed it!

    Can you explain why one PC can send from Yahoo! Mail and another cannot?

    It's #8734 Web-Php Pajax arbitrary command execution attempt

    Could be the difference in browsers versions executing different codes?

  6. #6
    Master Untangler carboncow's Avatar
    Join Date
    Aug 2011
    Location
    Central Ohio
    Posts
    124

    Default

    Quote Originally Posted by dmorris View Post
    The rule interfering with yahoo was removed from everyone in 9.0.2

    edit: jcoehoorn may be onto something:
    http://forums.untangle.com/protocol-...l-control.html
    I got 9.02 running.

    I loaded chrome and firefox on his system to test and they both worked fine, it's IE8 that is triggering the rule.

    he needs chrome anyways as IE prevents some webcams he needs to see for our resort, so this work around will suffice.

    thanks all!
    Attached Images Attached Images

  7. #7
    Master Untangler carboncow's Avatar
    Join Date
    Aug 2011
    Location
    Central Ohio
    Posts
    124

    Default

    OK found it, should I just turn it off?

    if it's removed or getting removed then it's been found to be invalid? Or should I keep and tell the user to try his alternate browser for his personal stuff?
    Attached Images Attached Images

  8. #8
    some dude hlarsen's Avatar
    Join Date
    Jul 2010
    Location
    sfba
    Posts
    1,323

    Default

    yeah just uncheck 'block' and it should be fine.
    Attention: Support on the Untangle Forums is provided by volunteers and community members.
    If you need official Untangle support please call or email support@untangle.com.

  9. #9
    Untangle Ninja sky-knight's Avatar
    Join Date
    Apr 2008
    Location
    Phoenix, AZ
    Posts
    16,976

    Default

    Heck just turn off the module. You shouldn't be running an IDS unless you're ready to deal with it anyway. A real working IDS is almost as much work as a block all firewall policy... it's constant management.
    Rob Sandling, BS:SWE, MCP
    Intouch Technology
    Phone: 480-272-9889
    NexgenAppliances.com
    Phone: 866-794-8879

  10. #10
    Untangle Junkie dmorris's Avatar
    Join Date
    Nov 2006
    Location
    San Mateo, CA
    Posts
    11,754

    Default

    Quote Originally Posted by sky-knight View Post
    Heck just turn off the module. You shouldn't be running an IDS unless you're ready to deal with it anyway. A real working IDS is almost as much work as a block all firewall policy... it's constant management.
    Yep. Agreed.
    Attention: Support and help on the Untangle Forums is provided by volunteers and community members like yourself.
    If you need Untangle support please call or email support@untangle.com

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  

SEO by vBSEO 3.6.0 PL2