Re: Detect where a connection drop occurs

William Kenworthy <[email protected]> Fri, 22 Feb 2013 15:57:55 +0800
Newsgroups gmane.linux.gentoo.server
Message-ID <[email protected]>
This is a multi-part message in MIME format.
--------------050601040901070006070207
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

tcptracerout is entirely appropriate here (its not the same as traceroute=
)

Whats the routing table say? (route -n)

BillK


On 22/02/13 15:44, Mateusz Arkadiusz Mierzwinski wrote:
> Hi,
>
> 1. netstat -ant
> 2. if returns 0.0.0.0:548 <http://0.0.0.0:548> its ok
> 3. else: check your service if it's connected to VPN interface only.
>
> 4. Traceroute to HOST not PORT. Port pinging can be blocked by your
> Internet Provider.
> 5. Check Your IPtables rules if You don't block any ports or set
> connlimit, rejects etc.: iptables -L
> 6. Check Your IDS software like Prelude/Snort.
>
> Best regards,
> MM
>
>
> 2013/2/22 Vin=C3=ADcius Ferr=C3=A3o <[email protected]
> <mailto:[email protected]>>
>
>     Hello dudes,
>
>     I've configured an service and I know it's working normally
>     through TCP port 548. But I'm only able to connect to it using a
>     VPN connection.
>
>     I need to debug it detecting where (in which hop) the connection
>     is being dropped.
>
>     Any ideias on how to do that?
>
>     I've tried tcptraceroute without success:
>
>     sudo tcptraceroute www.mydomain.com <http://www.mydomain.com> 548
>     Selected device en0, address 172.16.144.115, port 49302 for
>     outgoing packets
>     Tracing the path to www.mydomain.com <http://www.mydomain.com>
>     (146.164.36.7) on TCP port 548 (afpovertcp), 30 hops max
>      1  172.16.144.1  0.769 ms  0.598 ms  0.686 ms
>      2  * * *
>      3  * * *
>      4  * * *
>      5  * * *
>      6  * * *
>      7  * * *
>      8  * * *
>      9  * * *
>     10  * * *
>     11  * * *
>     12  * * *
>     13  * * *
>     14  * * *
>     15  * * *
>     16  * * *
>     17  * * *
>     18  * * *
>     19  * * *
>     20  * * *
>     21  * * *
>     22  * * *
>     23  * * *
>     24  * * *
>     25  * * *
>     26  * * *
>     27  * * *
>     28  * * *
>     29  * * *
>
>     Thanks in advance,
>
>
>     *Vin=C3=ADcius Ferr=C3=A3o*: Administrador de Sistemas
>     www.ferrao.eti.br <http://www.ferrao.eti.br> | +55 (21) 8888-2619
>     <tel:%2B55%20%2821%29%208888-2619>
>
>


--------------050601040901070006070207
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<html>
  <head>
    <meta content=3D"text/html; charset=3DUTF-8" http-equiv=3D"Content-Ty=
pe">
  </head>
  <body text=3D"#000000" bgcolor=3D"#FFFFFF">
    <div class=3D"moz-cite-prefix">tcptracerout is entirely appropriate
      here (its not the same as traceroute)<br>
      <br>
      Whats the routing table say? (route -n)<br>
      <br>
      BillK<br>
      <br>
      <br>
      On 22/02/13 15:44, Mateusz Arkadiusz Mierzwinski wrote:<br>
    </div>
    <blockquote
cite=3D"mid:[email protected]=
l.com"
      type=3D"cite">Hi,<br>
      <br>
      1. netstat -ant<br>
      2. if returns <a moz-do-not-send=3D"true" href=3D"http://0.0.0.0:54=
8">0.0.0.0:548</a>
      its ok<br>
      3. else: check your service if it's connected to VPN interface
      only.<br>
      <br>
      4. Traceroute to HOST not PORT. Port pinging can be blocked by
      your Internet Provider.<br>
      5. Check Your IPtables rules if You don't block any ports or set
      connlimit, rejects etc.: iptables -L <br>
      6. Check Your IDS software like Prelude/Snort.<br>
      <br>
      Best regards,<br>
      MM<br>
      <br>
      <br>
      <div class=3D"gmail_quote">2013/2/22 Vin=C3=ADcius Ferr=C3=A3o <spa=
n
          dir=3D"ltr">&lt;<a moz-do-not-send=3D"true"
            href=3D"mailto:[email protected]" target=3D"_blank">v=
[email protected]</a>&gt;</span><br>
        <blockquote class=3D"gmail_quote" style=3D"margin:0 0 0
          .8ex;border-left:1px #ccc solid;padding-left:1ex">
          <div style=3D"word-wrap:break-word">Hello dudes,
            <div><br>
            </div>
            <div>I've configured an service and I know it's working
              normally through TCP port 548. But I'm only able to
              connect to it using a VPN connection.</div>
            <div><br>
            </div>
            <div>I need to debug it detecting where (in which hop) the
              connection is being dropped.</div>
            <div><br>
            </div>
            <div>Any ideias on how to do that?</div>
            <div><br>
            </div>
            <div>I've tried tcptraceroute without success:</div>
            <div><br>
            </div>
            <div>
              <div>sudo tcptraceroute <a moz-do-not-send=3D"true"
                  href=3D"http://www.mydomain.com" target=3D"_blank">www.=
mydomain.com</a>
                548</div>
              <div>Selected device en0, address 172.16.144.115, port
                49302 for outgoing packets</div>
              <div>Tracing the path to <a moz-do-not-send=3D"true"
                  href=3D"http://www.mydomain.com" target=3D"_blank">www.=
mydomain.com</a>
                (146.164.36.7) on TCP port 548 (afpovertcp), 30 hops max<=
/div>
              <div>=C2=A01 =C2=A0172.16.144.1 =C2=A00.769 ms =C2=A00.598 =
ms =C2=A00.686 ms</div>
              <div>=C2=A02 =C2=A0* * *</div>
              <div>=C2=A03 =C2=A0* * *</div>
              <div>=C2=A04 =C2=A0* * *</div>
              <div>=C2=A05 =C2=A0* * *</div>
              <div>=C2=A06 =C2=A0* * *</div>
              <div>=C2=A07 =C2=A0* * *</div>
              <div>=C2=A08 =C2=A0* * *</div>
              <div>=C2=A09 =C2=A0* * *</div>
              <div>
                10 =C2=A0* * *</div>
              <div>11 =C2=A0* * *</div>
              <div>12 =C2=A0* * *</div>
              <div>13 =C2=A0* * *</div>
              <div>14 =C2=A0* * *</div>
              <div>15 =C2=A0* * *</div>
              <div>16 =C2=A0* * *</div>
              <div>17 =C2=A0* * *</div>
              <div>18 =C2=A0* * *</div>
              <div>19 =C2=A0* * *</div>
              <div>20 =C2=A0* * *</div>
              <div>21 =C2=A0* * *</div>
              <div>22 =C2=A0* * *</div>
            </div>
            <div>23 =C2=A0* * *</div>
            <div>24=C2=A0=C2=A0* * *</div>
            <div>25=C2=A0=C2=A0* * *</div>
            <div>26=C2=A0=C2=A0* * *</div>
            <div>27=C2=A0=C2=A0* * *</div>
            <div>28=C2=A0=C2=A0* * *</div>
            <div>29=C2=A0=C2=A0* * *</div>
            <div><br>
            </div>
            <div>Thanks in advance,</div>
            <div><br>
            </div>
            <div><br>
              <div>
                <div style=3D"line-height:13px;margin:6px
                  0;padding:8px;border-top:1px #999999
                  dotted;border-bottom:1px #999999
                  dotted;font-family:'Lucida
                  Grande',Verdana,Arial,Sans-Serif;font-size:11px;color:#=
336699">
                  <b style=3D"color:#336699">Vin=C3=ADcius Ferr=C3=A3o</b=
>:
                  Administrador de Sistemas <br>
                  <a moz-do-not-send=3D"true"
                    href=3D"http://www.ferrao.eti.br"
                    style=3D"color:#336699;text-decoration:none;border-bo=
ttom:1px
                    #999999 dotted" target=3D"_blank">www.ferrao.eti.br</=
a>
                  | <a moz-do-not-send=3D"true"
                    href=3D"tel:%2B55%20%2821%29%208888-2619"
                    value=3D"+552188882619" target=3D"_blank">+55 (21)
                    8888-2619</a>
                </div>
              </div>
              <br>
            </div>
          </div>
        </blockquote>
      </div>
      <br>
    </blockquote>
    <br>
  </body>
</html>

--------------050601040901070006070207--