Re: Traffic blocking (was: DNS lookup issue in 2.1.9)
John Dowdell <[email protected]>
| Newsgroups | gmane.comp.security.ipcop.user |
|---|---|
| Message-ID | <[email protected]> |
Hi all I have been rolling out a 2.1.9 firewall to live, had issues where all traffic on green and blue was blocked, retreated to soak test at home. Rebuilt from scratch with 2.1.8, waited couple of days, upgraded to 2.1.9. I have no extra firewall rules. I’m running NTP. My red is a DHCP client, green and blue running DHCP server. Not using orange. Not running proxy or URL filtering. OK I think I have replicated the problem now, in two separate ways. 1. In a fit of tidying my soak test rig yesterday lunchtime, I unplugged the red interface cable, tidied cabling then replugged. This sent dhcpd into a tailspin (see below) and all subsequent traffic from green and blue to red was blocked. 2. Late yesterday evening, something went pop and the same symptoms occurred. I don’t think I did anything to provoke this (but I’m open to discussion). Here is the log from the second of those two incidents, read bottom up. This is from System Log > Red. My red interface is running DHCP client towards my home router (BT Home Hub 5) and has been allocated 192.168.1.96. The home router is at 192.168.1.254, and does not support IPv6. The end result is that the red interface no longer has an IP address (as viewed in Status > Network Status). 23:09:31 dhcpcd[1394] exited 23:09:31 dhcpcd[1394] script_runreason: /usr/local/bin/dhcpcd.sh: WEXITSTATUS 1 23:09:31 dhcpcd[] unknown usage STOPPED 23:09:30 dhcpcd[] wan-1 has been brought down 23:09:29 dhcpcd[1394] wan-1: deleting default route via 192.168.1.254 23:09:29 dhcpcd[1394] wan-1: releasing lease of 192.168.1.96 23:09:29 dhcpcd[1394] if_deladdress6: :Operation not supported 23:09:29 dhcpcd[1394] wan-1: deleting address fe80::2e0:4cff:fe23:1c85 23:09:29 dhcpcd[1394] wan-1: removing interface 23:09:29 dhcpcd[1394] received signal ALRM from PID 5720, releasing 23:09:29 dhcpcd[5720] waiting for pid 1394 to exit 23:09:29 dhcpcd[5720] sending signal ARLM to pid 1394 23:09:29 red GUI hangup here is the log from the first incident (unplugging cable to Red) 13:09:26 dhcpcd[1361] exited 13:09:26 dhcpcd[1361] script_runreason: /usr/local/bin/dhcpcd.sh: WEXITSTATUS 1 13:09:26 dhcpcd[] unknown usage STOPPED 13:09:25 dhcpcd[] wan-1 has been brought down 13:09:24 dhcpcd[1361] wan-1: deleting default route via 192.168.1.254 13:09:24 dhcpcd[1361] wan-1: releasing lease of 192.168.1.96 13:09:24 dhcpcd[1361] if_deladdress6: :Operation not supported 13:09:24 dhcpcd[1361] wan-1: deleting address fe80::2e0:4cff:fe23:1c85 13:09:24 dhcpcd[1361] wan-1: removing interface 13:09:24 dhcpcd[1361] received signal ALRM from PID 3675, releasing 13:09:24 dhcpcd[3675] waiting for pid 1361 to exit 13:09:24 dhcpcd[3675] sending signal ARLM to pid 1361 Any help welcome. I recovered this by doing a reboot through the GUI, all services restored. Best regards John > On 19 Aug 2016, at 23:05, Jack Beglinger <[email protected]> wrote: > > Johm - > > one last thing. some in testing use unmanaged switches and > accendentally plug both red and green in to it. what happens under the > covers is the switch arp table entires will confused the macs.. 2 macs > to same box, so will work for short while then nothing. since all > traffic red and green are going to same nic (lowest mac). it is gotcha > that a quick late night test will burn you on. > > jack ------------------------------------------------------------------------------ _______________________________________________ IPCop-user mailing list [email protected] Manage your subscription or unsubscribe https://lists.sourceforge.net/lists/listinfo/ipcop-user