LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 10-07-2011, 07:14 PM   #1
arri
LQ Newbie
 
Registered: Oct 2011
Posts: 2

Rep: Reputation: Disabled
troubleshooting: connection blocked, but only for 1 specific client and 1 specific NIC


Hi all,

I just signed-up after having successfuly worked with linux for serveral years now. i have experience with linux on both local/desktop installs, as well as managing server-configurations. most of this is with Debian. (stable, unstable)

Up until now i've always managed to work-out any issues without having to ask any questions, undoubtly also with help from solutions i've found here. but now i'm stuck with a mind-boggling issue that i'm unable to solve on my own.

Part of the problem is the fact it takes quite some effort to explain what exactly IS the problem (symptoms), and that it's unclear (to me) where in the networking-topology it could possibly be found. But what also doesn't help is the fact i've always put off 'lower level' networking as much as possible, because it requires substantial amounts of study to know exactly what you're doing. As i hate to do things only half, up until now i've studied enough to use ShoreWall for configuring a firewall, and being failrly confident that it's actually safe. Other than that, my real understanding of netfilter/iptables is fairly thin (and young). The rest of the day, i'm usually focussing on software development for desktop-, mobile and web-applications.

So, as for the problem i'm trying to deal with, i'm hoping to find some support here, in order to narrow down the issue, and possibly finding the cause. I'll try and explain the situation as brief and clear as possible.

The setup is a remote machine, running several services such as web- and mail-server amongst various others, for a numer of different domains.
For this machine i have 6 additional (public) IP-addresses, next to the machines' main ip. These extra addresses are statically routed through the machines main address, and have been bound to 'aliased' or 'virtual' NIC's. (eth0:0, eth0:1 etc..).

This is all working great, already for several years now. The problem that appeared just a few weeks ago is this:

From my office network, I can't connect anymore to the machines' 1st aliased NIC/IP, eth0:0


The very strange thing is that this problem ONLY appears when i'm trying to connect from that particular network, and ONLY trying to connect to that particular address. All other permutations are fine.

Analysing the server logs, i don't see anything special. In fact, nothing at all shows-up in the logs about refused connections or anything.
Analysing the local network, i've found there's virtually no respons from the server when trying to connect. The only respons there appears to be, is that there seems to be a host "but all ports are filtered" when i scan the address with
Code:
nmap -Pn
Another interesting observation, is that when logged-in into the server (through another nic/ip), i also can't connect the other way around to my home network, for instance when i specifically specify the outgoing address like this:

Code:
ssh -p2222 -d x.x.x.x y.y.y.y.y
and this is confirmed when scanning the address with nmap, or trying to do the same using telnet on various ports and, while the office-lan is connected using a simple consumer-grade cable-internet connection, without a firewal or anything special.


Another reason why it's so mind boggling to me, is that there hasn't been any changes lately, to any part of either the office-network or the servers' setup. Also, the hosting company/datacenter says there hasn't been any changes, and their system reports that it's working as expected.



Would anyone have any idea what i'm overlooking here?

Thanks for your time!

gr
arri
 
Old 10-17-2011, 08:43 PM   #2
sys-fire
LQ Newbie
 
Registered: Nov 2003
Location: USA
Distribution: Debian and Slackware
Posts: 17

Rep: Reputation: 0
Hmmm....maybe an update changed shorewall configuration? I would run 'diff' on shorewall config file against your backup config file.
 
Old 10-17-2011, 09:10 PM   #3
arri
LQ Newbie
 
Registered: Oct 2011
Posts: 2

Original Poster
Rep: Reputation: Disabled
hi sys-fire,

thanks for your thoughts!

however, ofcourse i've gone through the shorewall config over and over again.
but it's a fairly simple setup, and nothing had been changed there..

as shorewall is itsself actually configuring netfilter/iptables etc... i also started studying those in depth.
and although learnig alot, i didn't find what's causing this.

Not surprising thought, since before i had already done all sorts of traffic monitoring (both ends)
while trying to connect, and found that no pachages at all arrive at the remote hosts network.
this is true for connecting in either direction.

and that's where i loose it, because physically this is all about the same two networks, with the same
machines, that are all working just fine...
...except when trying to connect to that one NIC/ip.
...and only my office network has this problem.

because of that fact, it's currently not a HUGE problem, but not understanding what's causing it makes
me very angry

gr
arri
 
Old 10-18-2011, 11:31 AM   #4
countach74
Member
 
Registered: Feb 2011
Distribution: Ubuntu 10.04, Debian Squeeze
Posts: 46

Rep: Reputation: 8
Have you tried changing the IP? Could it be possible that another machine (or local interface) is attempting to share the IP in question? If that's the case, one way to test it would be to change the troublesome IP and then run an arp-scan on that NIC's interface and network (you could nmap as well, but if it's a machine that blocks pings, you may not get conclusive results).

My 2 cents, for what it's worth.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Way to make autofs mount to specific USB flash drive to specific folder? utahnix Linux - Software 2 11-24-2010 05:27 PM
IsThere a fridge, that we can program at specific date/time to unfreeze specific food frenchn00b General 3 07-21-2009 11:26 PM
How to force specific domain or user specific emails to proces in sendmail 8.13.5 FC5 peanutsa Linux - Newbie 1 03-22-2009 05:33 AM
Add specific troubleshooting forums raahee LQ Suggestions & Feedback 5 12-21-2005 11:36 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 08:50 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration