Solved SSL issue for Webclient on CLIENT SIDE

Status
Not open for further replies.

craigreilly

Free User
Joined
Feb 1, 2012
Messages
4,134
Reaction score
577
Locally hosted 3cx auto renewed the cert this morning.
End user opened ticket. Fairly competent and has studied Cloud Security and such.
They wanted the 3cx Certificate so they could import it on their computer as the website was saying the connection is not private.
When they look at the certification path of the cert in the browser, it is giving them my gateway ip address and not the 3cx server FQDN. Confirmed their browser URL is pointing to the server FQDN.

Any ideas?
 
Locally hosted 3cx auto renewed the cert this morning.
End user opened ticket. Fairly competent and has studied Cloud Security and such.
They wanted the 3cx Certificate so they could import it on their computer as the website was saying the connection is not private.
When they look at the certification path of the cert in the browser, it is giving them my gateway ip address and not the 3cx server FQDN. Confirmed their browser URL is pointing to the server FQDN.

Any ideas?
Any kind of SSL Inspection enabled on the firewall/gateway?

Also, does it do the same if accessed from the outside?
 
This user actually is working from home. I've tested on my phone using cellular and no issues. Also working fine internally for me on 2 distinct browsers on Windows and 2 on Mac.

I'm using a Mikrotik here at the office... I only do QOS based on ports and IP destinations. But for 3cx only on 5060 and UDP 9000-10999.
 
So, if I understand this correctly:

User (at home) -> connects to Webclient via HTTPS FQDN ->

1. gets a SSL error because the certificate is actually the Microtik self-signed showing up?

2. doesn't get an error but still shows up as the gateway IP?
 
So Mikrotik port 80/443 is disabled under IP Service List... So, it shouldn't be that.

User closed their VPN and could connect to 3cx ok.
But with VPN on they can not. So something with the Mac L2TP VPN perhaps.
 
So Mikrotik port 80/443 is disabled under IP Service List... So, it shouldn't be that.

User closed their VPN and could connect to 3cx ok.
But with VPN on they can not. So something with the Mac L2TP VPN perhaps.
It is possible. VPNs on Macs are always a PITA.
 
VPN was it. Deleted VPN. Recreated the VPN. Logged into VPN. Logged into 3cx.
1626887843406.png
 
  • Like
Reactions: Evolute IT
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,081
Members
164,899
Latest member
mazet