Koozali.org: home of the SME Server

7.3 smeserver yum failing

Offline electroman00

  • *****
  • 491
  • +0/-0
Re: 7.3 smeserver yum failing
« Reply #15 on: May 25, 2009, 08:48:46 PM »
Quote
it's wireless hi-speed from a local ISP.

That's fine, works just like any other wired or wireless network.

It's not a problem with SME server.
It's not a problem with your isp.
It's not a problem with a proxy or a transparent proxy.

It's a 100% private network config issue.

The test clearly indicates that.

10  ... (host 172.31.0.3 is not responding) >>>> http://en.wikipedia.org/wiki/IP_address
11  ... (host 192.168.0.17 is not responding)

Lets look at it again....

 1  +-++-+-++--++  host: 203.221.91.1  max: 1500 bytes EXTERNAL
 2  +-++-+-++--++  host: 203.220.7.193  max: 1500 bytes EXTERNAL
 3  +-++-+-++--++  host: 203.220.112.141  max: 1500 bytes EXTERNAL
 4  +-++-+-++--+.+  host: 203.220.112.141  max: 1500 bytes EXTERNAL
 5  +-++-+-++--++  host: 202.7.162.61  max: 1500 bytes EXTERNAL
 6  +-++-+-++--++  host: 66.162.129.149  max: 1500 bytes EXTERNAL
 7  +-++-+-++--++  host: 64.129.248.19  max: 1500 bytes EXTERNAL
 8  +-++-+-++--++  host: 208.38.16.146  max: 1500 bytes EXTERNAL
 9  +-++-+-++--++  host: 208.38.15.166  max: 1500 bytes EXTERNAL
10  ... (host 172.31.0.3 is not responding) INTERNAL
11  ... (host 192.168.0.17 is not responding) INTERNAL
12  +-++-+-++--++  host: 72.45.88.114  max: 1500 bytes EXTERNAL

10 and 11 shouldn't be there, they are private address's beyond your modem, the outside world like in WWW.


Quote
ISP wireless equip, cisco switch, fortigate router, sme server.

Why is the switch between ISP wireless equip and the fortigate, exactly what is connected to it?

Here what it should look like.

mturoute to 72.19.14.11, 30 hops max, variable sized packets
* ICMP Fragmentation is not permitted. *
* Maximum payload is 2040 bytes. *
 1  +-++-+-++--++  host: 112.221.91.1  max: 1500 bytes
 2  +-++-+-++--++  host: 112.220.7.193  max: 1500 bytes
 3  +-++-+-++--++  host: 112.220.112.77  max: 1500 bytes
 4  +-++-+-++--++  host: 112.220.112.77  max: 1500 bytes
 5  +-++-+-++--++  host: 202.7.162.61  max: 1500 bytes
 6  +-++-+-++--++  host: 86.162.129.149  max: 1500 bytes
 7  +-++-+-++--++  host: 86.192.242.190  max: 1500 bytes
 8  +-++-+-++--++  host: 86.109.6.136  max: 1500 bytes
 9  +-++-+-++--++  host: 86.109.6.7  max: 1500 bytes
10  +-++-+-++--++  host: 86.109.6.5  max: 1500 bytes
11  +-++-+-++--++  host: 86.109.6.1  max: 1500 bytes
12  +-++-+-.++--++  host: 86.109.6.39  max: 1500 bytes
13  +-++-+-++--++  host: 86.109.6.37  max: 1500 bytes
14  +-++-+-++--++  host: 86.109.6.35  max: 1500 bytes
15  +-++-+-++--++  host: 86.109.6.105  max: 1500 bytes
16  +-++-+-++--++  host: 29.95.228.201  max: 1500 bytes
17  +-++-+-++--++  host: 29.95.232.67  max: 1500 bytes
18  +-++-+-++--++  host: 72.19.14.11  max: 1500 bytes

ALL EXTERNAL

If you want yum to work, fix the network.

Yum will not work unless your network is 100%, that's a fact.

The test clearly shows it's not 100%, fact.

That's why I gave you that particular test.

Offline Stefano

  • *
  • 10,894
  • +3/-0
Re: 7.3 smeserver yum failing
« Reply #16 on: May 25, 2009, 09:02:21 PM »
That's fine, works just like any other wired or wireless network.

It's not a problem with SME server.
It's not a problem with your isp.
It's not a problem with a proxy or a transparent proxy.

It's a 100% private network config issue.


hops 10 and 11 are of his ISP..
it's a widely used (mis)configuration of many wireless ISP

I've noticed the same behaviour with a customer of mine, here, in italy

OP can't fix anything as it's outside his router..

Ciao
Stefano

Offline electroman00

  • *****
  • 491
  • +0/-0
Re: 7.3 smeserver yum failing
« Reply #17 on: May 26, 2009, 05:38:40 PM »
Took me a while to figure it out.

It's not a mis config.

I kept forgetting it's wireless on the wan side of the fence.

These are the wireless link IP's and they disabled ping response for obvious reasons, not that it matters much.

10  ... (host 172.31.0.3 is not responding) INTERNAL
11  ... (host 192.168.0.17 is not responding) INTERNAL

So the wan side is OK for all we can assume at this point.

What I would say is connect SME directly to the Wireless with nothing else, just SME and retest.

That will verify the upstream Wan with SME.

If that works, then it's a foobar network and we're back to Lan side hunting & diag.

Really need to verify SME by itself working with the Wireless ISP.

hth

Offline electroman00

  • *****
  • 491
  • +0/-0
Re: 7.3 smeserver yum failing
« Reply #18 on: May 26, 2009, 05:48:04 PM »
At this point we don't know if the problem is WAN or LAN side.

Need to eliminate one or the other.

No sense trying to fix the Lan side if the Wan side doesn't work.

Offline dilligaf

  • *
  • 266
  • +0/-0
    • http://www.willcraft.com
Re: 7.3 smeserver yum failing
« Reply #19 on: June 02, 2009, 03:34:35 AM »
poking around at fortinet newsgroups, fortinet and some other utm appliances have these issue, is there a way to manually get all the updates?:

There were some mention several months ago about this issue with CentOS linux (not all linuxes); you can do some googling and you'll find that it's not a fortinet only episode, it happened with some other vendor.

I use fedora with yum updates, my box is behind fortigate running 4.0, with no issues. I' ve tested with and without AV for HTTP;
You can test if the issue arises with centOS yum behind a FGT using AV HTTP in the protection profile for that traffic.

Also test with this: (mirrors.kernel.org is a yum updates host)
echo -e "TRACE / HTTP/1.1\nHost: mirrors.kernel.org\n\n" | nc mirrors.kernel.org 80

I'll try with/without HTTP AV profile and if you cannot determine the cause, i'll recommend updating linux servers with apt-get (this issue seems to be only yum related)
« Last Edit: June 02, 2009, 03:36:13 AM by dilligaf »

Offline electroman00

  • *****
  • 491
  • +0/-0
Re: 7.3 smeserver yum failing
« Reply #20 on: June 02, 2009, 06:09:49 PM »
Suggest you connect SME and only SME to your modem and test yum.

That will tell you if sme and www will work, if it does work, then the problem is your network setup.
I see you've had other issues, my guess, since I don't have info and not sitting at your network, you  have a network issue.

Yum is finicky about the network working 100%.
Yum is deliberately programmed to test the packet stream to ensure it's ok, so it doesn't d/l corrupt files and save them.
Makes no sense updating with corrupted d/l files.

From the info you have given so far, your network is not setup properly.
Connect SME in gateway mode so you can admin from the internal interface and connect directly to the modem.
Once you report the results, then it's possible someone will look into a yum issue, if it still doesn't work.
Chances are it will.
As of now your lan has not been verified to be setup properly.
Need to isolate SME connected to the modem only.

Your mtu tested good source to destination firewall to firewall.

We know the yum servers are ok and it looks like the wan to you is ok.
That leaves your internal network and that has yet to be confirmed ok.

You have a packet framing issue, that is what yum is telling you, well maybe not you, certainly me.
Something on your network is the likely cause.

Quote
I use fedora with yum updates, my box is behind fortigate running 4.0, with no issues.
Well there ya go, at least fedora is setup properly.
That doesn't mean SME is.

Everyone on the internet that has the exact same error report as you, also has a network setup issue.
Takes 10-15 min to test SME direct to the modem,  a lot less time then you've spent searching the internet.

So get er done, then we'll go from there....
We're not going to fix yum for each person who has a foobar network.
Fix your network.
There are a lot of folks that use SME and yum works for them.
Kinda says it all in a nut shell.

Beside all that, nobody is going to waste their time fixing yum if it ain't broke and
they won't try unless sme is connected directly to the modem, which rules out your network setup
as the issue during the possible bug diagnosis.

If sme still still doesn't work directly connected, make sure you have a clean install and nothing else
connected to the modem.
Leave sme connected to the modem in gateway mode so you have access
from the gateway interface.
You can connect Fedora or a Win client to SME's gateway interface.
Then file a bug in the bug tracker.

Have you read here?
Goto that thread, top right click Notify, then you'll get notification of new posts in that thread also.
Interesting new findings there, last posts, read them.

You can have packet framing issues on a network you think is perfectly set up.
Most everything will work, yum and VPN will not.

Quote
echo -e "TRACE / HTTP/1.1\nHost: mirrors.kernel.org\n\n" | nc mirrors.kernel.org 80

That line does nothing more the opens a connection to the designated server, much the same method that yum uses.
We already know you can hit the servers with yum, so that line should work ok for you.
If you made a connection with it, then the ability to connect to the servers is ok.

However it doesn't tell you that you don't have a network packet framing issue, that test simply can't.

HTH

Offline Stefano

  • *
  • 10,894
  • +3/-0
Re: 7.3 smeserver yum failing
« Reply #21 on: June 03, 2009, 10:13:23 AM »
it is behind a fortigate firewall (same as many "working" installs)

as you can read here it's a yum issue with fortigate fw/AV

HTH
ciao

Stefano