Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Wierd issue with Akamai sites on SSL

    Scheduled Pinned Locked Moved Firewalling
    4 Posts 2 Posters 535 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D Offline
      djzort
      last edited by

      Every few days, SSL websites that use the akamai cdn "stop working" - that is they just spin in the browser and time out.

      Non-akamai ssl websites seem to work ok (although its hard to be comprehensive as the internet has quite a few websites these days) - but the pattern seems to be akamai.

      I have placed a packet dump at https://www.cloudshark.org/captures/a5ce20efde0d

      Anyones thoughts at this point would be much appreciated

      1 Reply Last reply Reply Quote 0
      • H Offline
        Harvy66
        last edited by

        Are you doing and HTTPS proxying or what do you use for your DNS?

        1 Reply Last reply Reply Quote 0
        • D Offline
          djzort
          last edited by

          I am not https proxying and dns is using 8.8.8.8 and 8.8.4.4

          1 Reply Last reply Reply Quote 0
          • D Offline
            djzort
            last edited by

            Hardware TCP Segmentation Offloading and  Hardware Large Receive Offloading  are disabled.

            disabling  Hardware Checksum Offloading  doesnt make any difference

            HCO on:

            wan: https://www.cloudshark.org/captures/24c60923d13a
            lan: https://www.cloudshark.org/captures/2ceb97ce1ab6

            HCO off:

            wan: https://www.cloudshark.org/captures/97f8b49b4e73
            lan: https://www.cloudshark.org/captures/755e2060d8ff

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.