[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[no subject]



the 'need to frag'  actually explain why error (404/403/500) can get
through, I think, because that they are small enough to pass w/o being
forced to frag (with one of the interface failed to frag) even with the
smallest MTU in the route.

# -----Original Message-----
# From: ale-bounces at ale.org [<a  rel="nofollow" href="mailto:ale-bounces";>mailto:ale-bounces</a> at ale.org] On 
# Behalf Of James P. Kinney III
# Sent: Thursday, April 14, 2005 11:58 AM
# To: Atlanta Linux Enthusiasts
# Subject: RE: [ale] apache wierdness
# 
# On Thu, 2005-04-14 at 10:30 -0400, Yu, Jerry wrote:
# &gt; what's the results for /index.html and /cgi-bin/printenv 
# when you try 
# &gt; it from
# &gt; 1) from localhost
# 
# works OK
# &gt; 2) from DMZ  or intranet, aka., behind the firewall which NATs the 
# &gt; apache
# works OK
# &gt; 2) from outside
# Works OK on some ISP's. Speakeasy is NOT one that works. 
# &gt; 
# &gt; apache log: does access_log shows the hang request as an success?
# Log shows connection but no request.
# 
# 
# 216.27.162.82 is my machine, 172.16.10.2 is the DMX internal 
# interface,
# 172.16.10.1 is the web server. 216.27.164.101 is the external 
# interface.
# Here's a tcp dump of the DMZ interface:
# 
# tcpdump: listening on eth1
# 09:19:44.310293 216.27.164.101.53964 &gt; 172.16.10.1.https: S
# 865145535:865145535(0) win 5840 &lt;mss 1460,sackOK,timestamp 
# 150425947 0,nop,wscale 2&gt; (DF)
# 09:19:44.310419 172.16.10.1.https &gt; 216.27.164.101.53964: S
# 2810103798:2810103798(0) ack 865145536 win 5792 &lt;mss 
# 1460,sackOK,timestamp 129832767 150425947,nop,wscale 0&gt; (DF) 
# 09:19:44.329400 216.27.164.101.53964 &gt; 172.16.10.1.https: . 
# ack 1 win 1460 &lt;nop,nop,timestamp 150425965 129832767&gt; (DF)
# 09:19:44.338396 216.27.164.101.53964 &gt; 172.16.10.1.https: P 
# 1:121(120) ack 1 win 1460 &lt;nop,nop,timestamp 150425965 129832767&gt; (DF)
# 09:19:44.338556 172.16.10.1.https &gt; 216.27.164.101.53964: . 
# ack 121 win
# 5792 &lt;nop,nop,timestamp 129832770 150425965&gt; (DF)
# 09:19:44.339059 172.16.10.1.https &gt; 216.27.164.101.53964: P 
# 1:123(122) ack 121 win 5792 &lt;nop,nop,timestamp 129832770 
# 150425965&gt; (DF)
# 09:19:44.364614 216.27.164.101.53964 &gt; 172.16.10.1.https: . 
# ack 123 win 1460 &lt;nop,nop,timestamp 150426001 129832770&gt; (DF)
# 09:19:44.392973 216.27.164.101.53964 &gt; 172.16.10.1.https: P 
# 121:645(524) ack 123 win 1460 &lt;nop,nop,timestamp 150426002 
# 129832770&gt; (DF)
# 09:19:44.425129 172.16.10.1.https &gt; 216.27.164.101.53964: . 
# ack 645 win
# 6432 &lt;nop,nop,timestamp 129832779 150426002&gt; (DF)
# 09:19:44.453231 216.27.164.101.53964 &gt; 172.16.10.1.https: P 
# 645:816(171) ack 123 win 1460 &lt;nop,nop,timestamp 150426081 
# 129832779&gt; (DF)
# 09:19:44.453388 172.16.10.1.https &gt; 216.27.164.101.53964: . 
# ack 816 win
# 7504 &lt;nop,nop,timestamp 129832781 150426081&gt; (DF)
# 09:19:44.458288 172.16.10.1.https &gt; 216.27.164.101.53964: P 
# 123:370(247) ack 816 win 7504 &lt;nop,nop,timestamp 129832782 
# 150426081&gt; (DF)
# 09:19:44.465501 172.16.10.1.https &gt; 216.27.164.101.53964: . 370:1818
# (1448) ack 816 win 7504 &lt;nop,nop,timestamp 129832782 150426081&gt; (DF)
# 09:19:44.465655 172.16.10.2 &gt; 172.16.10.1: icmp: 
# 216.27.162.82 unreachable - need to frag (mtu 1465) [tos 0xc0]
# 09:19:44.531404 216.27.164.101.53964 &gt; 172.16.10.1.https: . 
# ack 370 win
# 1728 &lt;nop,nop,timestamp 150426168 129832782&gt; (DF)
# 09:19:44.531932 172.16.10.1.https &gt; 216.27.164.101.53964: . 1818:3266
# (1448) ack 816 win 7504 &lt;nop,nop,timestamp 129832789 150426168&gt; (DF)
# 09:19:44.532048 172.16.10.2 &gt; 172.16.10.1: icmp: 
# 216.27.162.82 unreachable - need to frag (mtu 1465) [tos 0xc0]
# 09:19:44.531943 172.16.10.1.https &gt; 216.27.164.101.53964: P 3266:3681
# (415) ack 816 win 7504 &lt;nop,nop,timestamp 129832789 150426168&gt; (DF)
# 09:19:44.569365 216.27.164.101.53964 &gt; 172.16.10.1.https: . 
# ack 370 win
# 1728 &lt;nop,nop,timestamp 150426206 129832782,nop,nop,sack sack 
# 1 {3266:3681} &gt; (DF)
# 09:19:45.545528 172.16.10.1.https &gt; 216.27.164.101.53964: . 370:1818
# (1448) ack 816 win 7504 &lt;nop,nop,timestamp 129832891 150426206&gt; (DF)
# 09:19:45.545624 172.16.10.2 &gt; 172.16.10.1: icmp: 
# 216.27.162.82 unreachable - need to frag (mtu 1465) [tos 0xc0]
# 09:19:47.585536 172.16.10.1.https &gt; 216.27.164.101.53964: . 370:1818
# (1448) ack 816 win 7504 &lt;nop,nop,timestamp 129833095 150426206&gt; (DF)
# 09:19:47.585668 172.16.10.2 &gt; 172.16.10.1: icmp: 
# 216.27.162.82 unreachable - need to frag (mtu 1465) [tos 0xc0]
# 09:19:51.665535 172.16.10.1.https &gt; 216.27.164.101.53964: . 370:1818
# (1448) ack 816 win 7504 &lt;nop,nop,timestamp 129833503 150426206&gt; (DF)
# 09:19:51.665681 172.16.10.2 &gt; 172.16.10.1: icmp: 
# 216.27.162.82 unreachable - need to frag (mtu 1465) [tos 0xc0]
# 
# 25 packets received by filter
# 0 packets dropped by kernel
# 
# &gt; 
# &gt; # -----Original Message-----
# &gt; # From: ale-bounces at ale.org [<a  rel="nofollow" href="mailto:ale-bounces";>mailto:ale-bounces</a> at ale.org] On 
# # Behalf 
# &gt; Of James P. Kinney III # Sent: Thursday, April 14, 2005 
# 8:12 AM # To: 
# &gt; rsj at radio.org; Atlanta Linux Enthusiasts # Subject: Re: 
# [ale] apache 
# &gt; wierdness # # On Wed, 2005-04-13 at 21:27 -0400, Randal 
# Jarrett wrote:
# &gt; # &gt; Since the IP address has changed have you made sure that # you 
# &gt; flushed # &gt; all the caches on your browser?
# &gt; # &gt;
# &gt; # Tried from a freshly built machine (2 actually, a linux 
# box and an 
# &gt; XP # Pro) with the same results.
# &gt; # &gt;
# &gt; # &gt; On Wed, 2005-04-13 at 16:46 -0400, James P. Kinney III wrote:
# &gt; # &gt; &gt; Scenario:
# &gt; # &gt; &gt;
# &gt; # &gt; &gt; apache server behind nat firewall.
# &gt; # &gt; &gt; Network changes just occurred.
# &gt; # &gt; &gt; Nat reconfigured to accept new external IP and 
# redirect to DMZ # 
# &gt; &gt; &gt; apache server.
# &gt; # &gt; &gt;
# &gt; # &gt; &gt; Situation:
# &gt; # &gt; &gt;
# &gt; # &gt; &gt; _partial_ connections. If login to web script with bad # user 
# &gt; name or # &gt; &gt; password, system returns the correct &quot;bad username or 
# &gt; password.
# &gt; # &gt; &gt; Login failed&quot; error message from the login script.
# &gt; # &gt; &gt;
# &gt; # &gt; &gt; Using a good combination, I get no response. It looks 
# # like a 
# &gt; server # &gt; &gt; hung on connect. wget eventually times out. BUT! The 
# &gt; person who # &gt; &gt; wrote the app on the server connects just 
# fine with 
# &gt; the # SAME LOGIN # &gt; &gt; THAT FAILS WITH ME?!?!?!
# &gt; # &gt; &gt;
# &gt; # &gt; &gt; Both of us see the same IP address. No errors in the 
# log files.
# &gt; # &gt; &gt;
# &gt; # &gt; &gt; If I try and access a perl script in cgi-bin called printenv 
# &gt; with # &gt; &gt; the perms set to no execute, I get an apache arror # 
# &gt; message telling # &gt; &gt; me it can't be execute. If the perms 
# are fixed, 
# &gt; the # server just sits # &gt; &gt; and does NOTHING.
# &gt; # &gt; &gt;
# &gt; # &gt; &gt; I have never seen something like this before and am # 
# comletely 
# &gt; perplexed.
# &gt; # &gt; &gt;
# &gt; # &gt; &gt; The firewall now has old and new connections on it (i.e. 
# &gt; # old IP and
# &gt; # &gt; &gt; new
# &gt; # &gt; &gt; IP) We are in the process of migrating to a new 
# ISP/data # line 
# &gt; provider.
# &gt; # &gt; &gt;
# &gt; # &gt; &gt; If everything failed to go through, I could understand it # 
# &gt; being the # &gt; &gt; network change. But some stuff comes 
# through. Static # 
# &gt; pages don't happen.
# &gt; # &gt; &gt; Error messages happen.
# &gt; # &gt; &gt;
# &gt; # &gt; &gt;
# &gt; # &gt; &gt; _______________________________________________
# &gt; # &gt; &gt; Ale mailing list
# &gt; # &gt; &gt; Ale at ale.org
# &gt; # &gt; &gt; <a  rel="nofollow" href="http://www.ale.org/mailman/listinfo/ale";>http://www.ale.org/mailman/listinfo/ale</a>
# &gt; # -- 
# &gt; # James P. Kinney III          \Changing the mobile computing world/
# &gt; # CEO &amp; Director of Engineering \          one Linux user         /
# &gt; # Local Net Solutions,LLC        \           at a time.          /
# &gt; # 770-493-8244                    \.___________________________./
# &gt; # <a  rel="nofollow" href="http://www.localnetsolutions.com";>http://www.localnetsolutions.com</a>
# &gt; #
# &gt; # GPG ID: 829C6CA7 James P. Kinney III (M.S. Physics) # 
# &gt; &lt;jkinney at localnetsolutions.com&gt; Fingerprint = 3C9E 6366 54FC # A3FE 
# &gt; BA4D 0659 6190 ADC3 829C 6CA7 #
# &gt; 
# &gt; This email and any attached files herein contain 
# information that is intended only for the use of the 
# individual or entity to whom it is addressed and may contain 
# information that is legally privileged, confidential or 
# otherwise exempt from disclosure under applicable laws. If 
# the reader of this message is not the recipient, any 
# disclosure, dissemination, distribution, copying or other use 
# or retention of this communication or its substance is prohibited.
# &gt; 
# &gt; 
# &gt; _______________________________________________
# &gt; Ale mailing list
# &gt; Ale at ale.org
# &gt; <a  rel="nofollow" href="http://www.ale.org/mailman/listinfo/ale";>http://www.ale.org/mailman/listinfo/ale</a>
# -- 
# James P. Kinney III          \Changing the mobile computing world/
# CEO &amp; Director of Engineering \          one Linux user         /
# Local Net Solutions,LLC        \           at a time.          /
# 770-493-8244                    \.___________________________./
# <a  rel="nofollow" href="http://www.localnetsolutions.com";>http://www.localnetsolutions.com</a>
# 
# GPG ID: 829C6CA7 James P. Kinney III (M.S. Physics) 
# &lt;jkinney at localnetsolutions.com&gt; Fingerprint = 3C9E 6366 54FC 
# A3FE BA4D 0659 6190 ADC3 829C 6CA7
# 


</pre>
<!--X-Body-of-Message-End-->
<!--X-MsgBody-End-->
<!--X-Follow-Ups-->
<hr>
<!--X-Follow-Ups-End-->
<!--X-References-->
<!--X-References-End-->
<!--X-BotPNI-->
<ul>
<li>Prev by Date:
<strong><a href="msg00315.html">[ale] apache wierdness</a></strong>
</li>
<li>Next by Date:
<strong><a href="msg00317.html">[ale] FreeNX on Fedora Core 3</a></strong>
</li>
<li>Previous by thread:
<strong><a href="msg00315.html">[ale] apache wierdness</a></strong>
</li>
<li>Next by thread:
<strong><a href="msg00290.html">[ale] Central meeting on Thursday</a></strong>
</li>
<li>Index(es):
<ul>
<li><a href="maillist.html#00316"><strong>Date</strong></a></li>
<li><a href="threads.html#00316"><strong>Thread</strong></a></li>
</ul>
</li>
</ul>

<!--X-BotPNI-End-->
<!--X-User-Footer-->
<!--X-User-Footer-End-->
</body>
</html>