The Great Google, Firefox, Fortigate Incompatibility Caper

gmail-ssl-error-message.png

Don't feel alone. I don't understand what that error message is saying either. I'm just plagued with it!

It's a tech problem at work. It's an incompatibility between Firefox 3.0, Google's encrypted sites (like Gmail, Adsense, Webmaster Tools, Google Docs, etc) and our Fortigate firewall. Intermittently my web requests to Google get rejected with error messages. It can take a half dozen retries before my Gmail is sent or other task completed.

It's a strange problem because it's both software related and intermittent. You expect problems like these to follow hard and fast rules. What am I doing differently the fifth time I press retry than the fourth or third or second?

There is very little about this online. I can find people with my problem. I find a smaller subset who've realized it's this specific firewall box that's the wild card. I can't find anyone with concrete tips to make the problem go away!

It wasn't this way until Firefox went from version 2 to 3. It only happens with Google's SSL encrypted sites.

It's driving me slightly nuts.



3 Comments

Jim said:

Have you asked your IT guy to check the firewall log at the times you try to do this? There may be something getting logged.

It could be that the SSL traffic coming into the firewall is getting blocked even though the outbound request is opening port 443.

If you're running Windows XP or heaven forbid Vista did you try disabling Windows firewall?

Heem Author Profile Page said:

add:

to the firewall's https profile

allow-ssl-unknown-sess-id

Chard said:

Check this out:
http://kc.forticare.com/default.asp?id=3737&Lang=1&SID=

Comment above mine is correct, change the fortigate to allow unknown session ID's.

This is only a problem because Firefox is more strict about following SSL rules than IE, and SSL3 does not allow resending sessionID's for the fortigate to cache.

Reducing to SSL2 should work too if Firefox.

Leave a comment

Email this page

Email Geoff

My Bio

My Resume

Weather/Environment

Time Lapse Photography

CelebShowAndTell

Archives

About this Entry

This page contains a single entry by Geoff Fox published on 11/18/08 6:42 PM.

Great Movies Or Faulty Memories? was the previous entry in this blog.

Too Cold Too Early is the next entry in this blog.

As of 05/28/09 at 3:14 AM, I have published 3549 individual entries and received 4980 comments. The counter at the very bottom of the screen shows the total pages served.

For the most recent entries, click the main index. You can see a full listing of every entry since the beginning in the archives.