• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Certificate Error When Opening Outlook

General pfSense Questions
4
30
5.1k
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • I
    Injection_Mold
    last edited by May 10, 2016, 6:20 PM May 10, 2016, 6:08 PM

    I just installed a new PFSense firewall. When users open Outlook on the wired LAN there is no issue, but when they connect to the WiFi they get this certificate error. Not sure where to start. Thank you for your help in advance.  Note: I am new to PFSense.

    Information:
    PFSense Firewall
    Local Exchange
    Local DNS
    CertError.jpg
    CertError.jpg_thumb

    1 Reply Last reply Reply Quote 0
    • V
      viragomann
      last edited by May 10, 2016, 9:28 PM

      Do you have captive portal activated on WiFi or a Proxy?

      1 Reply Last reply Reply Quote 0
      • I
        Injection_Mold
        last edited by May 11, 2016, 12:14 PM

        @viragomann:

        Do you have captive portal activated on WiFi or a Proxy?

        No I do not.

        1 Reply Last reply Reply Quote 0
        • M
          muswellhillbilly
          last edited by May 11, 2016, 12:59 PM

          Do your LAN and wifi networks run on different address ranges? Are they separated networks?

          1 Reply Last reply Reply Quote 0
          • I
            Injection_Mold
            last edited by May 11, 2016, 1:03 PM

            @muswellhillbilly:

            Do your LAN and wifi networks run on different address ranges? Are they separated networks?

            No.

            1 Reply Last reply Reply Quote 0
            • M
              muswellhillbilly
              last edited by May 11, 2016, 1:07 PM

              Feel free to give answers of more than one word at a time. We could go on like this forever unless you give a better idea of what your network is like.

              1 Reply Last reply Reply Quote 0
              • I
                Injection_Mold
                last edited by May 11, 2016, 1:52 PM

                @muswellhillbilly:

                Feel free to give answers of more than one word at a time. We could go on like this forever unless you give a better idea of what your network is like.

                I understand. I don't want to give irrelevant information and I don't really know what is causing this so I am not sure what info to give you. I apologize. What kind of information would you like to have?

                I have a new PFSense firewall. I have Cisco APs and a Cisco controller.  When users are connected via the wired LAN they get no cert error. When they connect to the WiFi (same LAN) they get the cert issue. Not sure if this is just a DNS issue or if I have something configured wrong on the Firewall. DNS and DHCP are handled by my DC.

                1 Reply Last reply Reply Quote 0
                • V
                  viragomann
                  last edited by May 11, 2016, 2:05 PM

                  @Injection_Mold:

                  Not sure if this is just a DNS issue or if I have something configured wrong on the Firewall. DNS and DHCP are handled by my DC.

                  So do a NS lookup once on WiFi and once on LAN and copare the responds.

                  1 Reply Last reply Reply Quote 0
                  • M
                    muswellhillbilly
                    last edited by May 11, 2016, 2:09 PM

                    Are you saying your LAN and wifi clients are using the same DHCP and DNS servers? From the look of it, I'd say not - if your LAN clients are seeing the correct name for the certificate but your wifi users aren't then it's very likely they're getting different information. Have you checked a LAN client's DNS information against the same info for one of your wifi users?

                    Edit: I see viragomann has already posted this idea while I was typing.

                    1 Reply Last reply Reply Quote 0
                    • I
                      Injection_Mold
                      last edited by May 11, 2016, 5:42 PM

                      @muswellhillbilly:

                      Are you saying your LAN and wifi clients are using the same DHCP and DNS servers? From the look of it, I'd say not - if your LAN clients are seeing the correct name for the certificate but your wifi users aren't then it's very likely they're getting different information. Have you checked a LAN client's DNS information against the same info for one of your wifi users?

                      Edit: I see viragomann has already posted this idea while I was typing.

                      Ok, not sure if this has any relevance to this issue but on the wired LAN all info matches the WiFi except DHCP server. For some reason DHCP says, 1.1.1.1, when on the WiFi. It has correct DHCP ip when on the wired.

                      1 Reply Last reply Reply Quote 0
                      • V
                        viragomann
                        last edited by May 11, 2016, 6:04 PM

                        So I presume your WiFi device isn't directly connected to pfSense, it's rather connected to an AP or a wireless range extender which runs its own DHCP?
                        ::)

                        You may be able to configure the DHCP server to provide the correct DNS servers.

                        1 Reply Last reply Reply Quote 0
                        • I
                          Injection_Mold
                          last edited by May 11, 2016, 6:21 PM

                          @viragomann:

                          So I presume your WiFi device isn't directly connected to pfSense, it's rather connected to an AP or a wireless range extender which runs its own DHCP?
                          ::)

                          You may be able to configure the DHCP server to provide the correct DNS servers.

                          The APs report to the controller. The controller is directly connected to the main switch with a LAN ip. I am not using the controller for DHCP. Only the DC for DHCP.

                          1 Reply Last reply Reply Quote 0
                          • V
                            viragomann
                            last edited by May 11, 2016, 6:47 PM

                            And you also get different DNS servers when you are on WiFi and on wired?
                            Have you compared nslookups for your Exchange on both nets yet?

                            If there are simple APs in default mode, they should forward DHCP requests to a DHCP server, presume this is pfSense.

                            1 Reply Last reply Reply Quote 0
                            • J
                              johnpoz LAYER 8 Global Moderator
                              last edited by May 11, 2016, 6:58 PM

                              he is tunneling traffic back to the controllers it sounds like to me..  And he most likely has a captive portal setup on his wlc..  And cert error is what he is getting form that not his exchange cert..

                              An intelligent man is sometimes forced to be drunk to spend time with his fools
                              If you get confused: Listen to the Music Play
                              Please don't Chat/PM me for help, unless mod related
                              SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                              1 Reply Last reply Reply Quote 0
                              • I
                                Injection_Mold
                                last edited by May 11, 2016, 7:05 PM May 11, 2016, 7:01 PM

                                @viragomann:

                                And you also get different DNS servers when you are on WiFi and on wired?
                                Have you compared nslookups for your Exchange on both nets yet?

                                If there are simple APs in default mode, they should forward DHCP requests to a DHCP server, presume this is pfSense.

                                All other info was correct except DHCP. So I started digging through my Cisco wireless controller and found that DHCP proxy mode was set to global on my WiFi. (After reading some Cisco documentation, apparently this is set to DHCP proxy mode by default). I disabled that and now my WiFi DHCP server ip is correct. Not sure if this will resolve the cert issue or not. I am going to continue watching this closely and see if the issue comes up again. I am not saying this fixed my Cert error issue but it has resolved the DHCP server ip issue.

                                1 Reply Last reply Reply Quote 0
                                • I
                                  Injection_Mold
                                  last edited by May 11, 2016, 7:02 PM

                                  @johnpoz:

                                  he is tunneling traffic back to the controllers it sounds like to me..  And he most likely has a captive portal setup on his wlc..  And cert error is what he is getting form that not his exchange cert..

                                  See my latest reply to viragomann. Not sure if that is what was causing the Cert issue. Will watch closely the next couple of days to see if the cert issue comes up again.

                                  1 Reply Last reply Reply Quote 0
                                  • J
                                    johnpoz LAYER 8 Global Moderator
                                    last edited by May 11, 2016, 7:06 PM

                                    why do you have to wait/watch - why not jump on the wifi and test it?

                                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                                    If you get confused: Listen to the Music Play
                                    Please don't Chat/PM me for help, unless mod related
                                    SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                                    1 Reply Last reply Reply Quote 0
                                    • I
                                      Injection_Mold
                                      last edited by May 11, 2016, 7:08 PM

                                      @johnpoz:

                                      why do you have to wait/watch - why not jump on the wifi and test it?

                                      Ok i just tested. Still getting Cert issue. The cert is issued by pfsense.

                                      1 Reply Last reply Reply Quote 0
                                      • I
                                        Injection_Mold
                                        last edited by May 11, 2016, 8:09 PM May 11, 2016, 7:11 PM

                                        @johnpoz:

                                        why do you have to wait/watch - why not jump on the wifi and test it?

                                        So the cert, which is issued by PFSense, is trying to resolve mail.domain.com even though I have my Outlook pointing to server.domain.local. Is this a NAT or Rule issue with pfsense. When I try to tracert mail.domain.com from LAN it resolves to my WAN ip. Should this be resolving to local ip from lan?

                                        1 Reply Last reply Reply Quote 0
                                        • V
                                          viragomann
                                          last edited by May 11, 2016, 8:24 PM

                                          Outlook doesn't need an MX record to communicate with Exchange.

                                          Maybe the old IP is still in your DNS cache. Try to flush the cash.

                                          1 Reply Last reply Reply Quote 0
                                          6 out of 30
                                          • First post
                                            6/30
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.