BES & WS

rated by 0 users
Answered (Verified) This post has 1 verified answer | 8 Replies | 2 Followers

Top 25 Contributor
98 Posts
cfowler posted on 30 Aug 2012 8:51 AM
Hey all; I have an odd situation where Blackberry users cannot surf internet correctly. When users attempt to go to http://www.google.ca they can get there just fine but when they search for something, they receive a connection timeout. BES is the only thing affected, all other accounts can surf fine. If the same user goes to https://www.google.ca and performs a search, the result is what you'd expect, a list of returned pages. I can't see anything from a WS perspective that's preventing this and I have limited knowledge about how BES and WS work together other than that BES is setup to use a proxy configuration that all devices are routed through. Any suggestions on what to look for / check? Thanks! C

CF

|

Answered (Verified) Verified Answer

Top 25 Contributor
98 Posts
Verified by cfowler

A tad late but thought I'd post the resolution for the sake of sharing & closure.

I found a bad MAC in the block page NIC configuration.  Changed the InjectDestMACAddress to the GW MAC & everything works as it should.

CF

|

All Replies

Top 10 Contributor
382 Posts
Moderator

Seems like HTTPS webstite is ok, but HTTP is not. Is this issue happening to all HTTP websties?

|
Top 25 Contributor
98 Posts

This issue appears to only affect Google (original post for details).  HTTPS has issues but it is because MDS is configured to deny SSL requests to servers that have certificates which are untrusted or expired.  Not sure if this would be related.  Other HTTP sites apear to be fine.

CF

|
Top 25 Contributor
98 Posts

Running a testlogserver against the active BES shows a few Category Blocked messages but those are for advertising sites - I recategorized them to permit thinking this might be the issue but it didn't help.  I just noticed that the testlogserver shows no information for the user.

When I performed a testlogserver against the active BES the other day it showed multiple user accounts.

To the best of my knowledge, BES is configured to act as a proxy for the devices and we have an AD account that BES should be using for this but that will depend on who's logged onto the BES server or what account the service (not sure which service) is running as.

CF

|
Top 10 Contributor
382 Posts
Moderator

Usually if there are blocked messages in the testlogserver result, you can just re-categorize the urls. But apparently this is not working for you. To figure out your issue, we need to undertsand your whole installation clearly to see how the traffic is routed. I suggest you open a ticket with our tech support team to do detailed troubleshooting.

|
Top 10 Contributor
986 Posts
Trusted Users (MVP)

CF -- I am using WCCP with a BES server around and have never had this issue.  We make sure the BES Server gets a policy by its IP address, but that shouldn't matter for you.

|
Top 25 Contributor
98 Posts

Solution: Settings / Network Agent / Global / Network Agent IP - list the BES as proxies.  This setting can be found in config.xml which I recovered during the migration process.  Had to remove / add & problem solved.

Thank you all for the suggestions!

C

CF

|
Top 25 Contributor
98 Posts

I think I spoke too soon.  It appears that identifying the BES as a proxy or cache simply removes BES from filtering.  This isn't what we're after.  We need Websense to filter all BES internet traffic.  The BES is configured to point to WS as the proxy.

I have very limited knowledge fo BES, all I know is that MDS is setup with a service account that WS used to filter & now does not.  Anyone have any suggestions?

Appreciate it.

C

CF

|
Top 25 Contributor
98 Posts
Verified by cfowler

A tad late but thought I'd post the resolution for the sake of sharing & closure.

I found a bad MAC in the block page NIC configuration.  Changed the InjectDestMACAddress to the GW MAC & everything works as it should.

CF

|
Page 1 of 1 (9 items)