Hi Aaron,
I did check the bigdlog and didn't find anything useful. I see a 400 Bad Request but I'm just not sure what. I've put the output below in case you see anything I should clue in on. I will check the ISA/OWA logs next.. Thanks for the continued advice! I think getting the Wireshark trace decrypted would help a lot.. just don't know if I can get that working just yet.
Oh, I noticed the bigdlog file is growing at a rate of 250MB every 5 hours. How do I disable it again?
Thanks!
Brian
BIGDLOG output (for monitor in question):
2012-01-20 19:20:50.103037: ID 408 :(_do_ping): time to ping, now=1327105250.098992 [ addr=::ffff:192.168.253.170:443 mon=https fd=-1 pend=0 up_intvl=5 dn_intvl=5 timeout=16 time_until_up=0 immed=0 next_ping=1327105250.008992 last_ping=1327105245.068992 deadline=1327105266.008992 snd_cnt=2349 rcv_cnt=2349 ]
2012-01-20 19:20:50.103113: ID 408 :(_send_active_service_ping): pinging [ addr=::ffff:192.168.253.170:443 srcaddr=none ]
2012-01-20 19:20:50.103188: ID 408 :(_connect_to_service): creating new socket [ addr=::ffff:192.168.253.170:443 ]
2012-01-20 19:20:50.103313: ID 408 :(_connect_to_service): connect: Operation now in progress [ addr=::ffff:192.168.253.170:443 srcaddr=::ffff:192.168.253.5:50862 ]
2012-01-20 19:20:50.103414: ID global:(_main_loop): about to select for 0.100000s
2012-01-20 19:20:50.104799: ID 408 :(_main_loop): wfd selected [ addr=::ffff:192.168.253.170:443 srcaddr=::ffff:192.168.253.5:50862 fd=37 pend=1 ]
2012-01-20 19:20:50.104928: ID 408 :(_send_active_service_ping): pinging [ addr=::ffff:192.168.253.170:443 srcaddr=::ffff:192.168.253.5:50862 ]
2012-01-20 19:20:50.105036: ID 408 :(_send_active_service_ping): writing [ addr=::ffff:192.168.253.170:443 srcaddr=::ffff:192.168.253.5:50862 ] send=GET /\x0d\x0a
2012-01-20 19:20:50.105300: ID global:(_main_loop): about to select for 0.090000s
2012-01-20 19:20:50.106791: ID 408 :(_main_loop): rfd selected [ addr=::ffff:192.168.253.170:443 srcaddr=::ffff:192.168.253.5:50862 fd=37 pend=0 ]
2012-01-20 19:20:50.106924: ID 408 :(_recv_active_service_ping): reading [ addr=::ffff:192.168.253.170:443 srcaddr=::ffff:192.168.253.5:50862 ]
2012-01-20 19:20:50.107003: ID 408 :(_send_active_service_ping): pinging [ addr=::ffff:192.168.253.170:443 srcaddr=::ffff:192.168.253.5:50862 ]
2012-01-20 19:20:50.107074: ID 408 :(_send_active_service_ping): writing [ addr=::ffff:192.168.253.170:443 srcaddr=::ffff:192.168.253.5:50862 ] send=GET /\x0d\x0a
2012-01-20 19:20:50.107352: ID 408 :(_send_active_service_ping): sent ping [ addr=::ffff:192.168.253.170:443 srcaddr=::ffff:192.168.253.5:50862 ]
2012-01-20 19:20:50.107458: ID global:(_main_loop): about to select for 0.090000s
2012-01-20 19:20:50.108781: ID 408 :(_main_loop): rfd selected [ addr=::ffff:192.168.253.170:443 srcaddr=::ffff:192.168.253.5:50862 fd=37 pend=0 ]
2012-01-20 19:20:50.108872: ID 408 :(_recv_active_service_ping): reading [ addr=::ffff:192.168.253.170:443 srcaddr=::ffff:192.168.253.5:50862 ]
2012-01-20 19:20:50.109064: ID 408 :(_recv_active_service_ping): rcvd 2111 bytes: -->HTTP/1.1 400 Bad Request ( The data is invalid. )\x0d\x0aConnection: close\x0d\x0aPragma: no-cache\x0d\x0aCache-Control: no-cache\x0d\x0aContent-Type: text/html\x0d\x0aContent-Length: 1946 \x0d\x0a\x0d\x0a\x0d\x0aThe page cannot be displayed\x0d\x0a\x0d\x0a\x0d\x0a\x0d\x0a\x0d\x0a\x0d\x0a\x0d\x0a\x0d\x0a\x0d\x0a \x0d\x0a
\x0d\x0a \x0d\x0a The page cannot be displayed\x0d\x0a
\x0d\x0a
\x0d\x0a Explanation: There is a problem with the page you are trying to reach and it cannot be displayed.
\x0d\x0a
\x0d\x0a \x0d\x0a \x0d\x0a\x0d\x0a Try the following: \x0d\x0a \x0d\x0a Refresh page: Search for the page again by clicking the Refresh button. The timeout may have occurred due to Internet congestion.\x0d\x0a Check spelling: Check that you typed the Web page address correctly. The address may have been mistyped.\x0d\x0a Access from a link: If there is a link to the page you are looking for, try accessing the page from that link.\x0d\x0a\x0d\x0a \x0d\x0a \x0d\x0a\x0d\x0a Technical Information (for support personnel) \x0d\x0a \x0d\x0a Error Code: 400 Bad Request. The data is invalid. (13)\x0d\x0a\x0d\x0a
\x0d\x0a\x0d\x0a<-- [ addr=::ffff:192.168.253.170:443 srcaddr=::ffff:192.168.253.5:50862 ]
2012-01-20 19:20:50.109169: ID 408 :(_ssl_shutdown_service): shutting down, return ssl true [ addr=::ffff:192.168.253.170:443 srcaddr=::ffff:192.168.253.5:50862 mon=https fd=37 ]
2012-01-20 19:20:50.109291: ID 408 :(_ssl_shutdown_service_internal): recurse from 388
[ addr=::ffff:192.168.253.170:443 mon=https ]
2012-01-20 19:20:50.109371: ID 408 :(_ssl_shutdown_service): shutting down, return ssl true [ addr=::ffff:192.168.253.170:443 srcaddr=::ffff:192.168.253.5:50862 mon=https fd=37 ]
2012-01-20 19:20:50.109455: ID 408 :(_recv_active_service_ping): got data [ addr=::ffff:192.168.253.170:443 srcaddr=none ]