0

Discussion topic: Encrypted sites not connecting.

Reply
This message was authored by Bilseyboob This message was authored by: Bilseyboob

Encrypted sites not connecting.

I am experiencing issues with broadband connected to encrypted websites (https) 

I have a TP Deco Mesh Wifi system plugged into the Hub and Hub Wifi disabled. 

On many encrypted sites that I try and connect to the browser just hangs. Can take a minute or more to load, or time out completely.. When I connect to the same site on mobile data on the same device, it works fine. 

Guess it's a security thing on broadband but I can't see anything that would cause a problem. 

Reply

All Replies

This message was authored by jamesn123 This message was authored by: jamesn123

Re: Encrypted sites not connecting.

Posted by a Superuser, not a Sky employee. Find out more

Could be down to the fact you are using two routers on the network. Did you put the Deco in AP mode?

I am NOT a Sky Employee
Myself & Others offer our time to help others, please be respectful.
Bilseyboob
Topic Author
This message was authored by Bilseyboob This message was authored by: Bilseyboob

Re: Encrypted sites not connecting.

Thanks @jamesn123 changed to AP mode on the Deco and that seems to have improved it, though still getting some sticky pages. 

 

Created a new problem getting my Sky Q box on the network but have worked through some other discussions and seem to have managed that for now. Though I did have to turn the hub wifi back on and use that. I'm hoping that the Deco is smart enough to work around other networks. 

This message was authored by mae-3 This message was authored by: mae-3

Re: Encrypted sites not connecting.

@Bilseyboob 

 

Routing through 2 routers (double NAT) should not cause an issue with encrypted sites, only incorrect DNS responses would cause that issue and would usually be down to the broadband shield and age restrictions on the shield. Or a similar DNS restricting facility on the Deco system when in double NAT routed mode.

-------

Zen internet on FTTP (900Mbps down, 100Mbps up). SAT> IP (Apple 4K 2nd gen TV to LG C1 OLED UHD TV/Dolby Atmos Denon AVR, DacMagic Plus for Hi-Res audio), hosting own blog/forum (cluster), OPNsense & Zenarmor L4/L7 NGFW & DPI IDS/IPS, Asus ET12 Pro Tri-Band wifi, Linux, Gamer: Xbox Series X/i7 laptop, round-robin DNS over HTTPS, non-proprietary VoIP HD AMR-WB (G.722.2) and more... Beta tester Apple iOS/watchOS/tvOS/iPadOS/macOS.
This message was authored by jamesn123 This message was authored by: jamesn123

Re: Encrypted sites not connecting.

Posted by a Superuser, not a Sky employee. Find out more

@mae-3 wrote:

@Bilseyboob 

 

Routing through 2 routers (double NAT) should not cause an issue with encrypted sites, only incorrect DNS responses would cause that issue and would usually be down to the broadband shield and age restrictions on the shield. Or a similar DNS restricting facility on the Deco system when in double NAT routed mode.


But routing through two routers could cause temporary network stalls which makes it seem like sites wont load. 

I am NOT a Sky Employee
Myself & Others offer our time to help others, please be respectful.
This message was authored by mae-3 This message was authored by: mae-3

Re: Encrypted sites not connecting.

@jamesn123 

 

Absolute nonsense, I run double NAT here and so do many others it is even used on the internet behind hidden networks, eg: mobile networks without any issues whatsoever in that respect without stalls.

-------

Zen internet on FTTP (900Mbps down, 100Mbps up). SAT> IP (Apple 4K 2nd gen TV to LG C1 OLED UHD TV/Dolby Atmos Denon AVR, DacMagic Plus for Hi-Res audio), hosting own blog/forum (cluster), OPNsense & Zenarmor L4/L7 NGFW & DPI IDS/IPS, Asus ET12 Pro Tri-Band wifi, Linux, Gamer: Xbox Series X/i7 laptop, round-robin DNS over HTTPS, non-proprietary VoIP HD AMR-WB (G.722.2) and more... Beta tester Apple iOS/watchOS/tvOS/iPadOS/macOS.
This message was authored by jamesn123 This message was authored by: jamesn123

Re: Encrypted sites not connecting.

Posted by a Superuser, not a Sky employee. Find out more

@mae-3 wrote:

@jamesn123 

 

Absolute nonsense, I run double NAT here and so do many others it is even used on the internet behind hidden networks, eg: mobile networks without any issues whatsoever in that respect without stalls.


No need to be so hostile. I did not say it would happen I said its possible. If the two routers are conflicting with each other in terms of IP address space or particular devices, namely a Sky Q box which can take out an entire network if its not happy with its ethernet connection, then one could easily experience network 'stalls' e.g. packet collisions. 

I am NOT a Sky Employee
Myself & Others offer our time to help others, please be respectful.
This message was authored by mae-3 This message was authored by: mae-3

Re: Encrypted sites not connecting.

@jamesn123 

 

If the IP address space conflicts then it won't work at all and it certainly wouldn't only impact encrypted sites only unless there is some form of traffic interception or incorrect DNS responses which is basically the same as an interception.

 

And sorry about being a little sharp, that wasn't intended.

-------

Zen internet on FTTP (900Mbps down, 100Mbps up). SAT> IP (Apple 4K 2nd gen TV to LG C1 OLED UHD TV/Dolby Atmos Denon AVR, DacMagic Plus for Hi-Res audio), hosting own blog/forum (cluster), OPNsense & Zenarmor L4/L7 NGFW & DPI IDS/IPS, Asus ET12 Pro Tri-Band wifi, Linux, Gamer: Xbox Series X/i7 laptop, round-robin DNS over HTTPS, non-proprietary VoIP HD AMR-WB (G.722.2) and more... Beta tester Apple iOS/watchOS/tvOS/iPadOS/macOS.
This message was authored by mae-3 This message was authored by: mae-3

Re: Encrypted sites not connecting.

@Bilseyboob 

 

One thing I agree with @jamesn123 is if you have the issue you are experiencing with double NAT then you have made a fundamental misconfiguration of the Deco system behind the Sky router.

 

1. You cannot wire the Sky Q system to the Deco system unless you do the complete Sky Q system and disable the Sky router wireless system.

2. The IP private address space on the Sky system is 192.168.0.1/24 and the Deco must be on a separate subnet outside this range if you wish to double NAT and route through both routers.

-------

Zen internet on FTTP (900Mbps down, 100Mbps up). SAT> IP (Apple 4K 2nd gen TV to LG C1 OLED UHD TV/Dolby Atmos Denon AVR, DacMagic Plus for Hi-Res audio), hosting own blog/forum (cluster), OPNsense & Zenarmor L4/L7 NGFW & DPI IDS/IPS, Asus ET12 Pro Tri-Band wifi, Linux, Gamer: Xbox Series X/i7 laptop, round-robin DNS over HTTPS, non-proprietary VoIP HD AMR-WB (G.722.2) and more... Beta tester Apple iOS/watchOS/tvOS/iPadOS/macOS.
Bilseyboob
Topic Author
This message was authored by Bilseyboob This message was authored by: Bilseyboob

Re: Encrypted sites not connecting.

Hi @mae-3 


I have the Deco in AP mode now and after fully resetting the wifi adapter on the sky Q have managed to get it to join the network via the Deco. 

 

Still some problematic pages when accessing via wifi though which I can't see are linked to parental controls as I have no special rules set. The national lottery seems to cause issues for some reason! 

This message was authored by mae-3 This message was authored by: mae-3

Re: Encrypted sites not connecting.

@Bilseyboob 

 

On the command prompt can you do a 'nslookup national-lottery.co.uk' without the single quotes and post the results?

-------

Zen internet on FTTP (900Mbps down, 100Mbps up). SAT> IP (Apple 4K 2nd gen TV to LG C1 OLED UHD TV/Dolby Atmos Denon AVR, DacMagic Plus for Hi-Res audio), hosting own blog/forum (cluster), OPNsense & Zenarmor L4/L7 NGFW & DPI IDS/IPS, Asus ET12 Pro Tri-Band wifi, Linux, Gamer: Xbox Series X/i7 laptop, round-robin DNS over HTTPS, non-proprietary VoIP HD AMR-WB (G.722.2) and more... Beta tester Apple iOS/watchOS/tvOS/iPadOS/macOS.
Bilseyboob
Topic Author
This message was authored by Bilseyboob This message was authored by: Bilseyboob

Re: Encrypted sites not connecting.

Server:  SkyRouter.Home
Address:  192.168.0.1
 
Non-authoritative answer:
Address:  194.246.78.128
This message was authored by mae-3 This message was authored by: mae-3

Re: Encrypted sites not connecting.

@Bilseyboob 

 

Can you do a lookup of www.national-lottery.co.uk with the command 'nslookup www.national-lottery.co.uk' and post the results, please?

-------

Zen internet on FTTP (900Mbps down, 100Mbps up). SAT> IP (Apple 4K 2nd gen TV to LG C1 OLED UHD TV/Dolby Atmos Denon AVR, DacMagic Plus for Hi-Res audio), hosting own blog/forum (cluster), OPNsense & Zenarmor L4/L7 NGFW & DPI IDS/IPS, Asus ET12 Pro Tri-Band wifi, Linux, Gamer: Xbox Series X/i7 laptop, round-robin DNS over HTTPS, non-proprietary VoIP HD AMR-WB (G.722.2) and more... Beta tester Apple iOS/watchOS/tvOS/iPadOS/macOS.
Bilseyboob
Topic Author
This message was authored by Bilseyboob This message was authored by: Bilseyboob

Re: Encrypted sites not connecting.

Server:  SkyRouter.Home
Address:  192.168.0.1
 
Non-authoritative answer:
Address:  217.163.91.193
This message was authored by mae-3 This message was authored by: mae-3

Re: Encrypted sites not connecting.

@Bilseyboob 

 

The responses from the DNS servers are correct for Sky for IPv4.

 

Can you try disabling LAN side IPv6 in the router interface, it is under the LAN Advanced setup. And see whether that fixes the issue.

-------

Zen internet on FTTP (900Mbps down, 100Mbps up). SAT> IP (Apple 4K 2nd gen TV to LG C1 OLED UHD TV/Dolby Atmos Denon AVR, DacMagic Plus for Hi-Res audio), hosting own blog/forum (cluster), OPNsense & Zenarmor L4/L7 NGFW & DPI IDS/IPS, Asus ET12 Pro Tri-Band wifi, Linux, Gamer: Xbox Series X/i7 laptop, round-robin DNS over HTTPS, non-proprietary VoIP HD AMR-WB (G.722.2) and more... Beta tester Apple iOS/watchOS/tvOS/iPadOS/macOS.
Reply

Was this discussion not helpful?

No problem. Browse or search to find help, or start a new discussion on Community.

Start a new discussion

On average, new discussions are replied to by our users within 4 hours

New Discussion