Koozali.org: home of the SME Server

Can´t browse to most sites

Jorge Sá

Can´t browse to most sites
« on: December 05, 2003, 09:10:58 PM »
Its the first time i am using this forum to post a problem. I live in Portugal and use Adsl for internet access (Isp Telepac). Last Tuesday early in the morning (27/11/03) I noticed something strange: I could not browse to some sites I frequently use (www.dyndns.org), though I could ping them, by ip and by name. I can even access mail and ftp on some sites (ftp.micro$oft.com, for example) but couldn't browse them. My server is a dual Pentium Pro machine with 256M Ram and several scsi disks, eth0 is Intel Pro100+ (e100), eth1 is Via Rhine 10M (pcnet), all running SME 6b3 in server and gtw dedicated mode, with the last updates. I only use it to share internet access/firewalling and as a file server, though I have not disabled the other services (No need to). I use the dyndns client with success to have a fixed URL in order to ssh to it. My internet access is 256/128 PPPoE Adsl, and ip renews once a day, very early in the morning. I use a Zyxel Adsl router (bridging mode) Prestige 650H connected to eth1. When I first noticed the problem I was on a workstation and tried all of the above (no www or telnet to port 80, ftp ok, mail (25 and 110) ok).
Then I opened a server console to find exactly the same symptoms. All was working well half an hour before!. I checked the router configuration (even loaded the firmware and default setup) and still the same. Then I hooked a Windoze Xp wks directly to the bridged router, created a PPPoE connection and I could surf! Then I changed the Zyxel back in Ip router mode, configured pppoe, reconfigured SME for internet access via dhcp with mac address, put the router ip as an external dns and obtained the same results, both in the server and the wks! But one workstation directly connected to the router could surf all sites! I have read the threads on this and other forums and have been toying with MTU's since them, but with no success. I installed another machine (Celeron 400, 128M, 6G, two RTL8029 10M) exactly the same way and hooked it up to my cable modem, at my house. A laptop connected to the internal adapter can surf all the sites I can't at work! I can ssh to it by dyndns address from a wks at work (one directly connected to the router, that is). Talked to my Isp and they said they have changed DSLAM's (or reconfigured them) and changed DNS. It is not dns (names are resolved in ping, traceroute, telnet), seems to be Tcp but  I cant figure it out (MTU, MSSclamp). In despair, I brought the test SME machine to work, hooked it up to the router, and flushed all chains and Nat rules. It is the same. If I use lynx to connect to www.dyndns.org it stops for a very long time (about 5 mins) and then says it cant connect. If I go to another console and run netstat -a i see a SYN_SENT from ext ip:1054 and TIME_WAIT from ext ip:www but no ESTABLISHED! Can anyone please help me?

Reinhold

Re: Can´t browse to most sites
« Reply #1 on: December 09, 2003, 12:04:52 PM »
Jorge,

(Your post is VERY hard to read so you might try to reformat ).
From what I understand:
- your isp has changed switching hardware (DSLAM)
- and/or you ISP changed DNS (=their master DNS)

Try setting "select Master DNS" and use the ISP NEW DNS SERVER IP in the admin menu  (logging in locally) ... at least that should guarantee that you SME box really does resolve.

Jorge Sá

Re: Can´t browse to most sites
« Reply #2 on: December 09, 2003, 07:01:02 PM »
Ok! My fault! I'm just a newbie at this, sorry...To sum it up:

1) Have been installing SME from v5.1 upwards (srv and gtw ded.) without any difficulties - as a Web proxy and fileserver , using adsl and cable connections, with several modems and routers.

2) At work, I have a 6b3 SME with adsl connection (PPPoE, dynamic IP) through a bridged router (modem), configured as server and gateway dedicated.

3)All was working well, when one morning I noticed I could not access some sites (www.dyndns.org, www.microsoft.com) from a workstation. But I could ping them by  name and address. Traceroute works as well (by name and address). I cannot telnet to port 80 of those sites. It waits for about 5/6 mins then says can't connect. Netstat shows syn_sent, but  no ack or established!. The same happens on the server console, and the internet test stopped working too. But I can do ftp.microsoft.com! why www does not work anymore?

4) Changed the modem back as a router, changed sme config accordingly (dhcp on ext .int., external dns) and Window$ machines connected directly to the router can now browse, but not the sme or the winboxes on its lan!

5) Think it must have something to do with Isp/adsl, because the same sme server 6b3 works through a cable connection at another site with the same layout!

6) ifconfig appears correct, ppp0 is getting its IP, dns is working. Pls suggest
steps for debugging ....