Solaris 9 connection problems



Hello

I have a problem with a Netra T1 running Solaris 9 that has recently
been moved to a new remote location and been given a new ip address

Since the move some (but not all) of the hosts that could previously
connect to it can no longer do so (this seems to affect all protocols
but I have been using ssh for testing). I have been trying connections
from 2 identical linux servers on the same subnet (as each other) only
one of which can connect to the server

The server is behind a (Juniper NetScreen) firewall which is not under
my control although I am assured that the subnet that the test clients
are on is allowed through (and I know it works for one of the clients)

There is also a linux server at the new location which none of the
clients have any problems connecting to (and which can connect to the
Netra)

I tried running snoop on the Netra and tcpdump on the affected client
then attempting an ssh connection:

On the client I see only Syn packets leaving for the server

On the server I see the Syn packets arriving and Syn Ack and Ack packets
leaving

The test client's ip addresses are both in /etc/hosts.allow and the
AllowUsers line in sshd_config isn't tied by address

I'm not seeing any errors in the sshd log

I'm not sure whether the fact that I see Syn Ack packets leaving the
interface means that the connection is making it all the way up the
stack to the OS level and being blocked there or whether I would still
see the beginings of the TCP handshake in any case or whether the fact
that these packets are getting as far as leaving the interface means I
should suspect the firewall is blocking them on the way back out?

I'm also confused why this is affecting connections from some clients
and not others

Any thoughts appreciated

David





DAVID PROFFITT
SYSTEMS ADMINISTRATOR

200 GRAY'S INN ROAD
LONDON
WC1X 8XZ
UNITED KINGDOM
T +44 (0)20 7430 4705
F
E DAVID.PROFFITT@xxxxxxxxx
WWW.ITN.CO.UK
Please Note:



Any views or opinions are solely those of the author and do not necessarily
represent
those of Independent Television News Limited unless specifically stated.
This email and any files attached are confidential and intended solely for the
use of the individual
or entity to which they are addressed.
If you have received this email in error, please notify postmaster@xxxxxxxxx

Please note that to ensure regulatory compliance and for the protection of our
clients and business,
we may monitor and read messages sent to and from our systems.

Thank You.
_______________________________________________
sunmanagers mailing list
sunmanagers@xxxxxxxxxxxxxxx
http://www.sunmanagers.org/mailman/listinfo/sunmanagers



Relevant Pages

  • Re: MsgCommunicator v.2.00: Instant Messenger SDK, now with databases support
    ... expect persistent connections. ... they will wait for the server to pick them up. ... your Clients can stay "off-line" for about 30 minutes before they have to ... requests *simultaneously*. ...
    (borland.public.delphi.thirdpartytools.general)
  • sockets, closing and TIME_WAIT
    ... During heavy load the server can't follow anymore because the sockets ... my server should be able to handle 10 clients connecting ... This gets a free position in the array of connections, ...
    (comp.unix.programmer)
  • Re: TCP/IP redundant connections
    ... The clients have persistent TCP connections to the server, ...
    (freebsd-hackers)
  • Re: Intermittent Network Connections
    ... I've just reconnected the Server LAN nic 1 to the ethernet switch (the same ... Server IP config and Client IP config attached. ... > turn is connected to an ADSL modem out to the internet The clients connect to ... >> Clients can sucessfully log in but periodically loose their connections. ...
    (microsoft.public.windows.server.sbs)
  • Re: read() returns ETIMEDOUT on steady TCP connection
    ... I'am also meet this problem in my mss server(missey streaming server). ... What is unusual is that this is happening right in the middle of sending a steady stream of data with no network congestion. ... The likelihood of this happening seems to increase as the number of audience connections increases. ... all packets received are delivered to the upper layer. ...
    (freebsd-net)