Lot of http:443 in Proxy log viewer

Hi together,

I am not sure but I think this is new -

I have every day lot of entries from several PC´s in the Proxy log viewer where the website is only http:443

Any idea why?

Hi,

this sounds like a broken client application that

  • either tries to speak plain HTTP on port 443 (bad idea) or
  • fails to indicate the destination FQDN properly to the proxy.

Having the proxy logs at hand, you could determine the clients’ source IP address, and run a tcpdump for capturing the actual traffic emitted by it to IPFire’s web proxy.

However, I don’t think this is something to worry about - just the everyday background noise of devices doing things in an - um - non-optimal fashion. :slight_smile:

Thanks, and best regards,
Peter Müller