site Search:


 
    All Forums Hot Topics Gallery






how-to block ads


 
Search Topic:
Uniqs:
534
Share Topic
Posting?
Post a:
Post a:
AuthorAll Replies


Napsterbater
Premium,MVM
join:2002-12-28
Milledgeville, GA
Reviews:
·VOIPo
·Windstream
·BroadVoice

Anyone using RRAS on Win 2003 seen this?

I have a windows 2003 server running RRAS for NATing a PPPoE DSL connection and VPN for incoming connections.

For some reason it will not respond to my server trying to ping it for a health check, every single other device (on the WAN Side) can ping it just fine, there is internet connectivity both ways between these devices and no NAT in between.

No IP Filters in RRAS and no other firewalls.

Im stumped.
--
ASUS M4A79T Deluxe | AMD Phenom II x3 720 BE AM3 w/4 Cores @ 3.41Ghz(OC) | 4Gb DDR3 Memory @ 1600mhz | Sapphire ATI HD4870 1GB 800mhz/1000mhz(OC) | 2x500GB HDD's Raid 0 | Windows 7 Ultimate x64 Build 7600 (RTM) | Windstream DSL 12m (14.9m Sync)/766k


Jason24

join:2004-01-21
Davenport, FL

Did it previously work and just recently quit or has this never worked?



tekmunki
Tekmunki
Premium
join:2001-12-06
Lake City, FL

reply to Napsterbater
Enable the ICMP input filter.

Perhaps this will help:
»support.microsoft.com/kb/258030



Napsterbater
Premium,MVM
join:2002-12-28
Milledgeville, GA

reply to Jason24
Just started trying from this new IP, this did work from another IP.

The server pinging has a new IP, the server receiving the pings has not changed.



Napsterbater
Premium,MVM
join:2002-12-28
Milledgeville, GA

reply to tekmunki
ICMP is enable, every device I have tried is able to ping this IP except this one, and there are no filters anywhere that I can find.



Jason24

join:2004-01-21
Davenport, FL

reply to Napsterbater
Is the new IP on a residential connection? Can the new IP ping other endpoints?



Napsterbater
Premium,MVM
join:2002-12-28
Milledgeville, GA

No its in a datacenter, and yes it can ping my home connection that is in the same city on the same BRAS at the ISP, as well as many other endpoints.



tekmunki
Tekmunki
Premium
join:2001-12-06
Lake City, FL

Run wireshark on both sides, from that you can at least track down which side is dropping packets.



Napsterbater
Premium,MVM
join:2002-12-28
Milledgeville, GA
Reviews:
·VOIPo
·Windstream
·BroadVoice

OK I hate Windows/Computers...... Literally all i did was install Wireshark and I guess when it installed pcap it reinitialized the adapters and magically the damn thing started to respond to pings to that address again.

Thanks for the help guys.



tekmunki
Tekmunki
Premium
join:2001-12-06
Lake City, FL

said by Napsterbater:

OK I hate Windows/Computers...... Literally all i did was install Wireshark and I guess when it installed pcap it reinitialized the adapters and magically the damn thing started to respond to pings to that address again.

Thanks for the help guys.

HA! Well... Glad you got it working!
--
TekMunki
"There are 10 types of people in this world, those who understand binary and those who don't."

www.tekmunki.com


Napsterbater
Premium,MVM
join:2002-12-28
Milledgeville, GA
Reviews:
·VOIPo
·Windstream
·BroadVoice

Well never mind, guess it not exactly fixed, it worked for a bit now its back to messing up.

Ran Wireshark, I can see the IMCP echo request from the Outside server, but its coming trough the NAT and being forwarded to a server behind the NAT, which is responding but the response doesn't make it back out of the NAT.

Note the server its getting forwarded to is also pinging the server on the outside.

Now I'm really confused, for some reason this didn't happen before, and you cant even make RRAS forward ICMP if you wanted to but some how its doing it.
--
ASUS M4A79T Deluxe | AMD Phenom II x3 720 BE AM3 w/4 Cores @ 3.41Ghz(OC) | 4Gb DDR3 Memory @ 1600mhz | Sapphire ATI HD4870 1GB 800mhz/1000mhz(OC) | 2x500GB HDD's Raid 0 | Windows 7 Ultimate x64 Build 7600 (RTM) | Windstream DSL 12m (14.9m Sync)/766k



tekmunki
Tekmunki
Premium
join:2001-12-06
Lake City, FL

Have you cleared the arp cache and reset iptables in your router? Some more configuration info is needed,

Here's the pathing issue as I understand it:

server1 REQ => internet => router/NAT => rras server2 (CONFIRM ACK REPLY)

rras/server2 ACK => router/NAT => [DROPPED ECHO] => internet => server1 ping

Is there a deny rule in your ACL's blocking that packet from reaching that specific IP of server1- or perhaps you have some 1:1 NAT that may be overlapping the ACK packets.
--
TekMunki

"There are 10 types of people in this world, those who understand binary and those who don't."



www.tekmunki.com



Napsterbater
Premium,MVM
join:2002-12-28
Milledgeville, GA
Reviews:
·VOIPo
·Windstream
·BroadVoice

The RRAS server is the NAT server.

What should happen, and somtime does.

Server1 REQ -> Internet -> Server 2 / RRAS / NAT (CONFIRM ACK REPLY)
Server 2 ACK -> Internet -> Server 1

What is happening.

Server1 REQ -> Internet -> Server 2 / RRAS / NAT -> Server3 (CONFIRM ACK REPLY)
Server 3 ACK - > Server 2 NAT (DROPED) X

Note Server 3 is Pinging Server 1 itself from inside the NAT as well, but no problems out of it.

No Filtering, No 1 to 1 NAT.
--
ASUS M4A79T Deluxe | AMD Phenom II x3 720 BE AM3 w/4 Cores @ 3.41Ghz(OC) | 4Gb DDR3 Memory @ 1600mhz | Sapphire ATI HD4870 1GB 800mhz/1000mhz(OC) | 2x500GB HDD's Raid 0 | Windows 7 Ultimate x64 Build 7600 (RTM) | Windstream DSL 12m (14.9m Sync)/766k



Napsterbater
Premium,MVM
join:2002-12-28
Milledgeville, GA

This is freaking annoying, Worked for about 1 hr then it stopped again.


Sunday, 03-Jun 22:26:10 Terms of Use & Privacy | feedback | contact | Hosting by nac.net - DSL,Hosting & Co-lo
over 12.5 years online © 1999-2012 dslreports.com.
Most commented news this week
Hot Topics