strange ICMP problems

From: Bogdan TARU (bgd_at_icomag.de)
Date: 12/30/03

  • Next message: Michael Sierchio: "Re: Source Routing"
    Date: Tue, 30 Dec 2003 15:34:36 +0100
    To: freebsd-net@freebsd.org
    
    

            Hi,

     I've got some strange ICMP problems on my FreeBSD
     router/firewall. I'm trying to ping a host (dst) from this router,
     and I don't get any answer (100% packet loss). A tcpdump shows me
     (src=freebsd router/firewall, dst=destination host of the ping):

    src > dst: icmp: echo request (ttl 64, id 15739, len 84)
    dst > src: icmp: echo reply (ttl 58, id 33870, len 84)
    src > dst: icmp: time exceeded in-transit for
                  dst > src: icmp: echo reply [ttl 1]
                 (id 33870, len 84) [tos 0xc0] (ttl 254, id 6572, len 56)

     over and over and over again. This happens only with ICMP and only
     for this destination HOST! (It doesn't happen if I try from a
     different source box, though).

     I guess it's the freebsd router's fault, because it definitely
     receives a packet with ttl 58, and sends an ttl exceeded.

     The router is running freebsd 4.8-RELEASE, with IPF v3.4.31, and
     IPnat for natting. It's been running ok for about 100 days, and the
     problems with this destination hosts appeared suddenly, without
     configuration changes on any end.

     Any hints if IPF is really the problem?

     Thanks,
     bogdan

    _______________________________________________
    freebsd-net@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-net
    To unsubscribe, send any mail to "freebsd-net-unsubscribe@freebsd.org"


  • Next message: Michael Sierchio: "Re: Source Routing"

    Relevant Pages

    • Re: renaming of /tmp partition. Any adverse effect on OS
      ... The applications running under FreeBSD consider /home/app as the root ... FreeBSD hosts are being used for running our native applications. ... you are effectively disabling the required permissions on ... one host to check whether everything is fine or not. ...
      (comp.os.linux.setup)
    • Re: Problems using gssapi authentication from FreeBSD to Linux machines
      ... work between a FreeBSD host and a Linux host. ... STABLE code on the FreeBSD box, I've got forwardable Kerberos tokens ... but I can't get the Linux box to accept the Kerberos ...
      (FreeBSD-Security)
    • Re: Problems using gssapi authentication from FreeBSD to Linux machines
      ... work between a FreeBSD host and a Linux host. ... STABLE code on the FreeBSD box, I've got forwardable Kerberos tokens ... but I can't get the Linux box to accept the Kerberos ...
      (FreeBSD-Security)
    • Re: Yet another thread on the legality of port scanning
      ... Which portthe packets are sent to is ... If I do a "nice", normal portscan on a host - via TCP, UDP or ICMP I am ... This sort of behavior is ... If I try to flood your host with abnormally LARGE ICMP packets endlessly ...
      (Security-Basics)
    • Re: Interesting packets
      ... Really ICMP has many types, but ICMP is encapsulated in IP datagrams. ... Transportīs headers (UDP or TCP) are included in ICMP error messages. ... > find that ur host x.x.x.4 tried trace route or (some other type of ICMP ... > and tracking system please see: http://aris.securityfocus.com ...
      (Incidents)