Norton Safety Minder causes browser to freeze

Hi

I have a RB750 with RouterOS v4.11

Port 1 is WAN, Port 2 is our office, Port 3 is our Lounge AP, Port 4 is our 3G router for redundancy, and Port 5 is another AP in another area.

I have Bridged port 3 & 5, and hotspot is set to run on this “hs-bridge” guests are able to use the internet after logging in.

however, we also have a “guest” computer with Norton Safety Minder installed (to protect kids from danger)

I have spent a lot of time with Norton Engineering Support Team trying to figure out why my browser is freezing when I enable Norton Safety Minder.

I have since found that its either hotspot or bridge on the RB750 which is causing the problem on my RB750

When I connect the computer to a port that is not bridged and does not have hotspot running on it, then the Browser does not freeze.

It seems that packets are dropped between the computer and Norton server.

Any ideas?
supout.zip (252 KB)

You might want to try either bypassing the computer with the Norton program on it (easier), or allow access to Norton through the walled-garden. It is probably locking up because of the hotspot redirect.

/ip hotspot ip-binding
add mac-address=xx:xx:xx:xx:xx:xx type=bypassed

or

/ip hotspot walled-garden
add dst-host=www.norton.com action=allow

You might want to change the URL or add additional URLs depending on what norton needs.

what browser are you using?

Both IE and firefox. Both freeze. its definately not the browser.

So the Norton Safety Minder computer won’t work. Does it get a login page? If not, it is probably because the Safety Minder is trying to contact Norton to see if the site is ok, but it can’t get through the hotspot to find out if the hotspot ip/url login page is ok.

Did you try bypassing that computer through the hotspot as I suggested?

For now Norton Safety Minder is disabled and the computer has internet access without the browser freezing.

If I add the rule you suggest, will the computer have unlimited (time) access? I want to avoid this. The user must purchase a voucher.

Earlier in my testing I was already logged into the hotspot. Browsing was fine until I enable Norton Safety Minder.

Another reason I dont like this ‘solution’ is because some guests might have Norton Safety Minder on their computer, and they will be bugging me when their browser freezes.

I will look into this. I already have symantec.com and symantecliveupdate.com. I will see what Norton Engineering Support Team suggest.

right now somebody is using the computer so I cant do any further testing.

If you talk to Norton tech support, find out what URLs/ips and ports are used by Safety Minder to verify the website URL/ip. Then bypass only those through “/ip hotspot walled-garden” or “/ip hotspot walled-garden ip”. That way the browser won’t freeze when Safety Minder does a check when behind the hotspot and not logged in.

ADD: You also should mention to them that the computer is being redirected to a localnet URL/ip before being allowed internet access. I found on the internet after a short Google search that at one time Safety Minder was having issues with private localnet ips (192.168.x.x and 10.x.x.x).

I see KatieQ answered your question on the Norton forum. These are the URLs she recommended bypassing with the walled garden:
onlinefamily.norton.com
o2comm.norton.com

Yes,

I have inserted norton.com (this will allow both of the above)

I also inserted cavern.co.za (my router internal address is in the RB750 dns as a static entry: hotspot.cavern.co.za) This fixes the private localnet issue.

Everything works as advertised.

Now after a few days without trouble, the 2 computers with Norton Safety minder which are on the hotspot interface have the Browser Freeze problem.

After disabling the Norton Safety Minder I get the error “Alert: The URL is not valid and can not be loaded.”

The 3rd computer with the Norton software is not on the hotspot interface, and works fine.

I suspect that Norton keep changing their software or the sites they try to contact on the internet. It is flawed software and I am going to remove it from the 2 computers on the hotspot interface.

It could be the dns entries expired, and no longer let Norton through. You might want to check “/ip dns cache” entries and see if the *.norton.com entries are there. This “dns timeout” with the walled garden is supposed to be solved in V5, but it is still a beta release to me. This dns issue affects payments to PayPal also.