LinuxQuestions.org
Go Job Hunting at the LQ Job Marketplace
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices

Reply
 
LinkBack Search this Thread
Old 01-20-2005, 05:42 PM   #1
Moloko
Member
 
Registered: Mar 2004
Location: Netherlands
Distribution: Debian
Posts: 729

Rep: Reputation: 30
Can't get to all sites using nat router?


I'm behind a nat router (server with iptables) and 99% of the connectivity works just fine, but I can't get to some sites. Slashdot.org and www.devx.com don't show up in the browser??

I checked the routing, the firewall, the interfaces, resolv.conf, hosts files etc., but I can't find anything wrong. As I said, except for the mentioned sites everything works just fine. I can surf all I want, stream audio, use ssh and the lot.

Where's the catch?
 
Old 01-20-2005, 06:13 PM   #2
azrael808
Member
 
Registered: Dec 2004
Location: London, UK
Distribution: Fedora and CentOS
Posts: 43

Rep: Reputation: 15
Can you ping these web addresses? If you can't get a reply, it maybe because they don't respond to pings, but you should still be able to see the IP address resolved from the URL.

I can't think off the top of my head why you can't access certain sites.

Pete
 
Old 01-20-2005, 06:18 PM   #3
Moloko
Member
 
Registered: Mar 2004
Location: Netherlands
Distribution: Debian
Posts: 729

Original Poster
Rep: Reputation: 30
Pings do get rejected with slashdot, but it's ip does show up.
 
Old 01-20-2005, 06:18 PM   #4
leonscape
Senior Member
 
Registered: Aug 2003
Location: UK
Distribution: Debian SID / KDE 3.5
Posts: 2,313

Rep: Reputation: 47
Could be an ECN problem?

ECN website detailing problems
 
Old 01-20-2005, 06:39 PM   #5
Moloko
Member
 
Registered: Mar 2004
Location: Netherlands
Distribution: Debian
Posts: 729

Original Poster
Rep: Reputation: 30
I can visit the 'hall-of-shame' sites just fine, so I guess not.
 
Old 01-20-2005, 06:54 PM   #6
leonscape
Senior Member
 
Registered: Aug 2003
Location: UK
Distribution: Debian SID / KDE 3.5
Posts: 2,313

Rep: Reputation: 47
You sometimes don't have to be visiting the sites, just pass through a router somewhere that doesn't handle ECN properly.

less /proc/sys/net/ipv4/tcp_ecn

Will either be 1 or 0 for on or off. You can turn it off with

echo 0 > /proc/sys/net/ipv4/tcp_ecn

and retry accessing the sites if it was on. Its worth a try anyway.
 
Old 01-20-2005, 07:02 PM   #7
Moloko
Member
 
Registered: Mar 2004
Location: Netherlands
Distribution: Debian
Posts: 729

Original Poster
Rep: Reputation: 30
It's off.
 
Old 01-20-2005, 07:04 PM   #8
Moloko
Member
 
Registered: Mar 2004
Location: Netherlands
Distribution: Debian
Posts: 729

Original Poster
Rep: Reputation: 30
Hmm, it gets more interesting, Konqueror works, Firefox doesn't. I think I'll figure it out. At least it's not my home-cooked router
 
Old 01-20-2005, 07:09 PM   #9
Moloko
Member
 
Registered: Mar 2004
Location: Netherlands
Distribution: Debian
Posts: 729

Original Poster
Rep: Reputation: 30
Relay that, slashdot works in Konqi, devx.com doesn't. I'll be digging for leftovers from the previous configuration as I was connected to the internet directly at first using the workstation and not the server.
 
Old 01-20-2005, 07:28 PM   #10
Moloko
Member
 
Registered: Mar 2004
Location: Netherlands
Distribution: Debian
Posts: 729

Original Poster
Rep: Reputation: 30
Slashdot worked for one page in Konq, now it doesn't anymore. I'm going nuts here...
 
Old 01-21-2005, 07:07 AM   #11
Moloko
Member
 
Registered: Mar 2004
Location: Netherlands
Distribution: Debian
Posts: 729

Original Poster
Rep: Reputation: 30
A quick test with Knoppix gives the same results on the workstation. Running tcpdump on the external interface on the server does show traffic, but nothing shows up in the browser on the workstation.

I can reach slashdot on the server with lynx, so apparantly something goes wrong when translating the source with nat. It's very strange that most sites do work, but some don't. Any clues?
 
Old 01-21-2005, 03:56 PM   #12
Moloko
Member
 
Registered: Mar 2004
Location: Netherlands
Distribution: Debian
Posts: 729

Original Poster
Rep: Reputation: 30
It's in the Maximum Transfer Unit, MTU. The default setting of 1492 or even 1500 doesn't work well with NAT when connected with pppoe. Decreasing to 1452 works.
 
Old 01-28-2005, 07:30 PM   #13
WolfCub
Member
 
Registered: Nov 2003
Location: Canada
Distribution: Debian
Posts: 175

Rep: Reputation: 30
ahh
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Logs of accessed sites per IP in NAT jeffvph Linux - Networking 1 12-04-2005 07:35 PM
ipv6 NAT router pIscIs Slackware 4 11-19-2005 03:24 PM
how to use my Ip address if having a NAT router poeta_boy Linux - Networking 5 04-17-2004 06:10 PM
NAT / Router RH9 kdd281 Linux - Networking 3 11-24-2003 02:02 PM
NAT Linux Router, How to filter Porn and Ad sites ?(no squid) phtkiller Linux - Networking 8 10-15-2003 12:04 PM


All times are GMT -5. The time now is 05:06 AM.

Main Menu
 
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: @linuxquestions
Open Source Consulting | Domain Registration