Community


403 Tunnel or SSL Forbidden just cropped up

gary N, User (Posts: 3)
Jul 14, 2014 12:02:44 pm EDT
Support level: Free or trial
The host logs show this on startup (Masked ID)
2014-07-14 12:46:33:296 96 Internet-ID: Connection established ID: S-2277XXXX-XXXX-XXXX; Port: 563

Anytime a client tries to connect, I get this logged on host. So this tells me that something from client is getting through.

2014-07-14 12:47:11:796 63 Exception: 403 Tunnel or SSL Forbidden (EIdHttpProxyError). Information
2014-07-14 12:47:12:015 63 Exception: Socket Error # 10054 Connection reset by peer. (EIdSocketError). Information
2014-07-14 12:47:12:062 63 Exception: Socket Error # 10054 Connection reset by peer. (EIdSocketError). Information

I tested from a Windows client and an iOS client. Both show the same error on Host logs.
on iOS I get error message "Host not found". On the windows client, I get the useless "Connection to xxx failed. Mode <Authorization>"

To rule out client WiFi network, on iOS device, I used the cellular data network, and same error in host logs.
On windows client, I verified I can telnet to server.rutils.com:5656
And since I see log entries in the hosts logs anytime I try to connect with remote clients, it does not look like a proxy/firewall issue on either side.
Searching for "403 Tunnel or SSL Forbidden" in forum gives no results.

An suggestions would be appreciated. I moved from  [censored] to RU but its been a beast to configure when I first attempted it 5 months back. After configuration, it worked liek a charm till today. I use it almost daily.

Thanks
Anton Kalugin, User (Posts: 209)
Jul 14, 2014 1:37:04 pm EDT
Support level: Free or trial
Hello Gary,

Thank you for your message.

Is there any proxy server running on the Host machine?

Looking forward to your reply.
gary N, User (Posts: 3)
Jul 14, 2014 2:08:59 pm EDT
Support level: Free or trial
Anton,

Yes, there is a proxy server running on the remote host side only. Always had one.
The clients are on an open network.

The proxy requires password credentials. I have the right password etc because I can connect via browser when I get the proxy challenge and enter the id/password.

And with proxy, I can get to the port 443/563 pair which is necessary & sufficient as per the KB article.

I did not have to check NTLM in the past but since it did not work today, I gave that a shot as well. No luck.

Thanks
Anton Kalugin, User (Posts: 209)
Jul 14, 2014 2:36:06 pm EDT
Support level: Free or trial
Gary,

Could you please try to disable proxy server temporarily, so that we can determine the reason of the problem. It is possible that a proxy server is not guilty.
gary N, User (Posts: 3)
Jul 14, 2014 3:01:21 pm EDT
Support level: Free or trial
Anton,

I will not be able to disable the proxy unfortunately since I do not have access to a port in the floor that is on the open network.

Is it possible that RU server can be holding onto stale proxy credentials. Hence the behavior wrt to RU is different than behavior wrt to other apps that use the same proxy?

But then, why would it log "Connection established ID: S-2277XXXX-XXXX-XXXX; Port: 563"
Port 563 on this network is blocked unless we use the proxy.

I tried completely disabling the proxy settings and then the remote logs would have message "Internet-ID ErrorCode <> 0"
I really wish the logs had more details such as IP & port  so we could debug.
Anton Kalugin, User (Posts: 209)
Jul 14, 2014 3:24:32 pm EDT
Support level: Free or trial
Gary,

I have created a tech support ticket from your message. You will be replied shortly.

* Website time zone: America/New_York (UTC -4)