For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

Rene_125890's avatar
Rene_125890
Icon for Nimbostratus rankNimbostratus
Apr 30, 2014

Problem with a PACFILE VS

I configured a VS that is used to Access 2 servers with a PACFILE service. Even though de members of the pool are up the PACFILE service is not working when I open a Browser that has configured the option to use an external script.

 

In this case, the PACFILE is used for prxy purposes, but the browser doesn't show me the window to put my user / pwd to define which categories I am able to Access.

 

5 Replies

  • I'm going to assume that you're talking about Capistrano here. If so, can you elaborate on your configuration and what you're trying to do?

     

  • So just to clarify, you have a VIP in front of your autoproxy service to load balance distribution of a pacfile? Is the browser getting the pacfile?

     

  • Okay, so let's say you have an HTTP URL configured in your browser. That URL points to an F5 VIP, and that F5 VIP load balances the pacfile servers. If you open the browser and only see traffic TO the VIP, but no return traffic, then there's a good chance the VIP itself is misconfigured. If you see return traffic, but none of it is the requested pacfile data, there's a good chance that either pool or pacfile servers are misconfigured. Do a packet capture on the server side of the proxy to see if there's any request and/or response traffic going to/from the pacfile servers.

     

  • mm, ok. do you mean that I have to analyze the traffic going out from the servers that contain the Pac File?

     

    Yes. If you can establish that you see request and response traffic on the server side of the proxy, then you know it's at least working at layer 4. Probably the easiest approach is to tcpdump on the F5.

     

  • Rene, when you insert a proxy between the client and a server, you essentially create two network paths. You have the client side between the browser and the proxy, and another between the proxy and the server. What we need to assess here then is WHERE the traffic is failing. I'm assuming you performed the tcpdump on the client side, so you now need to run another capture on the server side of the proxy. If you don't see traffic to the server on the server side, then you can reasonably assume that there's something wrong at the proxy.