public inbox for gentoo-user@lists.gentoo.org
 help / color / mirror / Atom feed
From: Harry Putnam <reader@newsguy.com>
To: gentoo-user@lists.gentoo.org
Subject: [gentoo-user]  Re: Curious ping problem with no FW
Date: Tue, 22 Jul 2008 10:16:41 -0500	[thread overview]
Message-ID: <87ej5mj6ee.fsf@newsguy.com> (raw)
In-Reply-To: 200807201658.29960.michaelkintzios@gmail.com

Mick <michaelkintzios@gmail.com> writes:

> On Monday 14 July 2008, Harry Putnam wrote:
>> I've had a problem with being able to ping out to the internet from my
>> gentoo box, while at the same time I'm able to ping outbound from
>> several windows boxes on same home lan.
>>
>> I don't run a firewall at all from linux but do have a Netgear
>> switch/router/Firewall upstream between me and the internet cable
>> modem.
> [snip..]
>
>> My router/fw can be set to deny specific machines outbound traffic but
>> that is not done in this case.  So the solution must reside somewhere
>> in my gentoo install.
>
> It may be worth checking your router's firewall rules once more.  Is the 
> gentoo box connected to the router in the same fashion as the MSWindows 
> boxen, or is it in some funny DMZ set up?

The section involving blocking has nothing whatever set.

> What do the firewall logs show?

Since there is nothing outgoing set to log, it says nothing.

>> What things should I be checking.
>
> If as you say you have no firewall on the Gentoo box then you ought to have a 
> quick look at your kernel.  Use sysclt:
>
> /sbin/sysctl -a

Here I see:
  sysctl -a|grep 'net.*icmp'

  net.ipv4.icmp_echo_ignore_all = 0
  net.ipv4.icmp_echo_ignore_broadcasts = 1
  net.ipv4.icmp_ignore_bogus_error_responses = 1
  net.ipv4.icmp_errors_use_inbound_ifaddr = 0
  net.ipv4.icmp_ratelimit = 250
  net.ipv4.icmp_ratemask = 6168

But not sure what any of it means.  The first line looks kind of
ominous though.

>> A ping attempt like this:
>>
>>   ping ftp.ucsb.edu
>>   PING ftp.ucsb.edu (128.111.24.43) 56(84) bytes of data.
>>
>> Just never moves any further, but you can see it has resolved the
>> alpha address to numeric forum so must have contacted and received
>> info from the nameserver.
>
> Or from your router if it acts as a caching DNS resolver?

I don't think so, at least there is no mention in the documentation of
such a feature.





  reply	other threads:[~2008-07-22 15:17 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2008-07-14 17:31 [gentoo-user] Curious ping problem with no FW Harry Putnam
2008-07-19 19:16 ` [gentoo-user] " Miernik
2008-07-20 15:58 ` [gentoo-user] " Mick
2008-07-22 15:16   ` Harry Putnam [this message]
2008-07-23 21:14     ` [gentoo-user] " Mick

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=87ej5mj6ee.fsf@newsguy.com \
    --to=reader@newsguy.com \
    --cc=gentoo-user@lists.gentoo.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox