Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Specific https site not working through pfsense

    Scheduled Pinned Locked Moved General pfSense Questions
    11 Posts 2 Posters 1.1k Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • stephenw10S Offline
      stephenw10 Netgate Administrator
      last edited by

      I would check the state table when testing to see if you have any traffic to/from that site.
      A pcap will show you more if needed. It could be an MTU issue in the route to that site for example.

      https://docs.netgate.com/pfsense/en/latest/troubleshooting/website-access-issues.html

      Steve

      Q 3 Replies Last reply Reply Quote 0
      • Q Offline
        qctech @stephenw10
        last edited by

        Thanks @stephenw10,

        I'm working through the connectivity and website access troubleshooting guides now.

        I also suspect MTU problems.

        1 Reply Last reply Reply Quote 0
        • Q Offline
          qctech @stephenw10
          last edited by

          @stephenw10

          Ok, so checked through and I get an interesting result when doing the ping fragmentation test. I get good results at 1468, 4 short of the "normal" 1472 that I would expect. I think this is vlan tag related and that I have got something wrong in the hypervisor (xcp-ng).

          Am I going to break anything if I set the MTU on the WAN interface to 1496 in interfaces>wan1 or should i put 1468 in the MSS

          1 Reply Last reply Reply Quote 0
          • Q Offline
            qctech @stephenw10
            last edited by

            Interestingly I have just established that my own website is also not working through this connection. Checking the state tables shows the following;
            LAN tcp 10.1.1.2:59812 -> 3.10.30.47:443 TIME_WAIT:TIME_WAIT 12 / 20 1 KiB / 17 KiB

            WAN1 tcp ...:14318 (10.1.1.2:59812) -> 3.10.30.47:443 TIME_WAIT:TIME_WAIT 22 / 20 3 KiB / 17 KiB

            1 Reply Last reply Reply Quote 0
            • stephenw10S Offline
              stephenw10 Netgate Administrator
              last edited by

              You should be able to set the MTU lower. PMTU should detect that and set TCP packet size accordingly. If it was a problem you have created locally I would expect it to affect all traffic not just one site. Seems more likely something in the route breaking PMTU in which case you might need to use MSS clamping.

              Steve

              Q 1 Reply Last reply Reply Quote 0
              • Q Offline
                qctech @stephenw10
                last edited by

                @stephenw10 understood, thanks for the assistance.

                What value would you suggest for the MSS? If I went really safe, say 1400 would that cause any serious problems?

                1 Reply Last reply Reply Quote 0
                • stephenw10S Offline
                  stephenw10 Netgate Administrator
                  last edited by

                  It should be fine at lower values. It's common to clamp at 1350 for VPN traffic for example.

                  Q 2 Replies Last reply Reply Quote 1
                  • Q Offline
                    qctech @stephenw10
                    last edited by

                    @stephenw10 fully understand the should. Don't worry I won't hold you responsible!!! (unless it works obviously).

                    I'm supposed to be on holiday this week and the job is about an 8 hour drive away so I want to avoid that if at all possible!

                    1 Reply Last reply Reply Quote 0
                    • Q Offline
                      qctech @stephenw10
                      last edited by

                      @stephenw10 Fingers crossed... that seems to have it sorted. I'll do some tuning once I'm able to be on site but for now all of the sites that I know were not loading are working fine.

                      Massive thanks, if you are every in Staffordshire let me know, I owe you beer or dinner or both! (genuinely thanks, you have no idea how stressed this has had me)

                      The learning opportunity for me now is to work out why I have never had this problem before. Another day, another lesson.

                      1 Reply Last reply Reply Quote 0
                      • stephenw10S Offline
                        stephenw10 Netgate Administrator
                        last edited by

                        Ah nice! Something probably changed in the route. Fireware update, router swapped etc. You could probably find where it was failing with enough tracetroute and pinging but finding someone to admit it's a problem and fix it is a different matter!

                        Steve

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.