LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 11-30-2006, 10:20 PM   #1
romeo_tango
Member
 
Registered: Nov 2006
Distribution: Mint
Posts: 148

Rep: Reputation: 15
Help! an IP Conflict in a strange case...


Hello all,

Well my english is not too good to chit-chat, so i'm sorry if i'll go straight.

We have 8 servers, each running RHEL 4.3 and the first one is their gateway's with a public IP. (the gateway's ip is 10.10.10.1). Let's say the public IP is 20x.a.b.158. The rest are having just local IP. (10.10.10.2 to 10.10.10.8).

We have a firewall using iptables, so that the 'local ip' servers could be accessed via SSH with dnat-ted port, for example :
- ssh 20x.a.b.158 -p 2022 (to the 10.10.10.2)
- ssh 20x.a.b.158 -p 3022 (to the 10.10.10.3)
- ssh 20x.a.b.158 -p 4022 (to the 10.10.10.4)
- and so on

Here is the problem, we have another Win2K server, (20x.a.b.148 and 10.10.10.9) which happen to have an IP conflict in the system. At first i thought that it was the local's IP that causing the trouble so I immedeately change it to another one. But it doesn't solve the problem.

When I looked at the Event Viewer in the Win2k server there was an error :
"The system detected an address conflict for IP Address 20x.a.b.148 with the
system having network hardware address 00:ww:xx:yy:zz:30. Network operations
on this systems maybe disrupted as a result."

I checked all the servers we have and found that the mac address 00:ww:xx:yy:zz:30 is belong to the local interface of the 20x.a.b.158 which is 10.10.10.1.
After a few check, i found that if we were behind the firewall (10.10.10.1 to 10.10.10.8), we could run this command :
ssh 20x.a.b.148 (while the IP is currently belong to a Win2K server!).
I entered the password, and the "impossible ssh" command bring me to the 10.10.10.1.

Does anybody here has faced this kind of problem?
This is only happening between the 20x.a.b.158 and 20x.a.b.148. We have another servers running too such as 20x.a.b.147 and else and there are no problem at all.

Any help?
 
Old 12-01-2006, 12:09 AM   #2
w7hd
Member
 
Registered: Aug 2004
Location: Tucson, AZ
Distribution: Ubuntu 9.04 & 10.10, RHEL 4 & 5
Posts: 48
Blog Entries: 3

Rep: Reputation: 16
IP Conflict

The source of your problem appears to be the DNAT. It must only be applied to the EXTERNAL interface - not the internal interface. The whole idea is to allow external boxes to access the 10.10.10.x using the 20x.a.b.158:x022 port. The fact that you can access it from inside the firewall using the 20x.a.b.158 address indicates this is being applied to both interfaces.

Hope this helps.
 
Old 12-01-2006, 12:54 AM   #3
romeo_tango
Member
 
Registered: Nov 2006
Distribution: Mint
Posts: 148

Original Poster
Rep: Reputation: 15
In the iptables configuration's, we are using these terms :
$INET_IFACE="eth1" and $LAN_IFACE="eth0"

and I am sure that there is no DNAT rule for $LAN_IFACE in the configuration. I already
"cat firewall.sh | grep LAN_IFACE" and check it out.

all the DNAT is happen in the INET_IFACE.

or did i miss something here?
 
Old 12-01-2006, 06:53 AM   #4
w7hd
Member
 
Registered: Aug 2004
Location: Tucson, AZ
Distribution: Ubuntu 9.04 & 10.10, RHEL 4 & 5
Posts: 48
Blog Entries: 3

Rep: Reputation: 16
Hmmm. Very strange, as you said. Do you by chance have dual IP addresses on the Win2K box -OR- have the 20x.a.b.148 address defined? That would do it. Or does the Win2K box only have the 10.10.10.1 address?
 
  


Reply

Tags
conflict, dnat, rhel



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
mesa-6.x claims to support OpenGL 1.5, but in my case does not in my case. qwijibow Programming 2 11-23-2006 07:14 AM
Converting sLoPPy cASE to Pretty Case with tr lowpro2k3 Programming 4 04-13-2005 08:13 PM
Why are all my upper case files being shown as lower case?? [Kernel 2.6.9-1.667 FC3] t3gah Fedora 4 03-11-2005 04:09 PM
Lower case to upper case letter sudhasmyle Programming 1 12-03-2004 04:15 AM
strange, strange alsa problem: sound is grainy/pixellated? fenderman11111 Linux - Software 1 11-01-2004 05:16 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 05:19 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration