Hey all, Anybody noticed if XTRA is having problems??? ~benm noc% traceroute www.nbnz.co.nz traceroute to www.nbnz.co.nz (210.55.168.70), 30 hops max, 40 byte packets 1 cs-red-vrrp.auckland.clix.net.nz (203.167.224.53) 0.681 ms 0.605 ms 0.620 ms 2 cs2-e4-4-acld.auckland.clix.net.nz (203.167.224.55) 1.295 ms 0.618 ms 0.616 ms 3 ba2-fe0-1-0-acld.auckland.clix.net.nz (203.97.9.177) 1.695 ms 1.342 ms 0.994 ms 4 xtra.ape.net.nz (192.203.154.60) 2.068 ms 3.037 ms 2.400 ms 5 202-37-237-229.dds.xtra.co.nz (202.37.237.229) 11.157 ms 14.180 ms 12.818 ms ^C noc% traceroute www.nbnz.co.nz traceroute to www.nbnz.co.nz (202.49.143.70), 30 hops max, 40 byte packets 1 cs-red-vrrp.auckland.clix.net.nz (203.167.224.53) 1.027 ms 0.643 ms 0.591 ms 2 core1-fe6-1-0-acld.auckland.clix.net.nz (203.97.2.241) 0.828 ms 0.832 ms 0.748 ms 3 b1-atm2-0-1-wcms.sydney.clix.net.nz (203.97.83.222) 24.861 ms 24.981 ms 24.879 ms 4 500.Serial0-1-1.GW2.SYD2.ALTER.NET (203.166.90.77) 25.304 ms 25.446 ms 25.532 ms 5 422.at-6-0-0.XR1.SYD2.Alter.Net (210.80.3.93) 25.821 ms 26.227 ms 26.369 ms 6 0.SO-5-0-0.XR1.SYD4.ALTER.NET (210.80.33.222) 26.798 ms 26.203 ms 26.783 ms 7 0.SO-0-0-1.XR2.SYD3.ALTER.NET (210.80.33.10) 26.120 ms 26.265 ms 26.196 ms 8 412.ATM8-0-0.GW1.SYD3.Alter.Net (210.80.3.158) 26.766 ms 27.052 ms 27.655 ms 9 500.ATM1-0.BORDER3.SYD.OZEMAIL.NET.AU (203.166.16.38) 29.680 ms 28.339 ms 27.345 ms 10 border1-fe0-0.syd.ozemail.net.au (203.108.190.150) 29.397 ms 27.699 ms 28.171 ms 11 203.108.1.237 (203.108.1.237) 125.545 ms 44.672 ms 47.893 ms 12 atm0-1-0-2.bdr1.hay.connect.com.au (210.8.219.234) 32.714 ms 41.311 ms 50.258 ms 13 f4-0-0-2.sybr1.netgate.net.nz (202.50.116.113) 59.829 ms 36.707 ms 35.536 ms 14 * * * 15 * * * 16 * * * 17 * * * 18 * * * 19 * * * 20 * * * 21 * * * 22 * * * 23 * * * 24 * * * 25 * * * 26 * * * 27 * * * 28 * * * 29 * * * 30 * * * noc% traceroute www.nbnz.co.nz traceroute to www.nbnz.co.nz (202.49.143.70), 30 hops max, 40 byte packets 1 cs-red-vrrp.auckland.clix.net.nz (203.167.224.53) 0.804 ms 0.591 ms 0.574 ms 2 core1-fe6-1-0-acld.auckland.clix.net.nz (203.97.2.241) 0.868 ms 1.181 ms 0.835 ms 3 b1-atm2-0-1-wcms.sydney.clix.net.nz (203.97.83.222) 26.398 ms 24.848 ms 25.311 ms 4 500.Serial0-1-1.GW2.SYD2.ALTER.NET (203.166.90.77) 25.351 ms 25.321 ms 25.193 ms 5 422.at-6-0-0.XR1.SYD2.Alter.Net (210.80.3.93) 26.074 ms 25.617 ms 25.889 ms 6 0.SO-5-0-0.XR1.SYD4.ALTER.NET (210.80.33.222) 26.125 ms 26.219 ms 26.750 ms 7 0.SO-0-0-1.XR2.SYD3.ALTER.NET (210.80.33.10) 26.163 ms 26.097 ms 26.047 ms 8 412.ATM8-0-0.GW1.SYD3.Alter.Net (210.80.3.158) 27.231 ms 27.047 ms 27.093 ms 9 500.ATM1-0.BORDER3.SYD.OZEMAIL.NET.AU (203.166.16.38) 27.965 ms 27.783 ms 28.140 ms 10 border1-fe0-0.syd.ozemail.net.au (203.108.190.150) 28.064 ms 28.494 ms 28.159 ms 11 203.108.1.237 (203.108.1.237) 38.559 ms 29.714 ms 35.737 ms 12 atm0-1-0-2.bdr1.hay.connect.com.au (210.8.219.234) 36.318 ms 34.299 ms 32.086 ms 13 f4-0-0-2.sybr1.netgate.net.nz (202.50.116.113) 32.040 ms 31.104 ms 30.982 ms 14 * * * 15 * *^C noc% traceroute www.nbnz.co.nz traceroute to www.nbnz.co.nz (210.55.168.70), 30 hops max, 40 byte packets 1 cs-red-vrrp.auckland.clix.net.nz (203.167.224.53) 0.663 ms 0.619 ms 0.612 ms 2 cs2-e4-4-acld.auckland.clix.net.nz (203.167.224.55) 0.698 ms 0.654 ms 1.278 ms 3 ba2-fe0-1-0-acld.auckland.clix.net.nz (203.97.9.177) 0.899 ms 1.329 ms 0.946 ms 4 xtra.ape.net.nz (192.203.154.60) 1.588 ms 3.299 ms 2.391 ms 5 203.96.111.218 (203.96.111.218) 11.624 ms 11.308 ms 11.742 ms 6 * 202-37-237-133.dds.xtra.co.nz (202.37.237.133) 87.635 ms 106.486 ms ^C noc% traceroute www.nbnz.co.nz traceroute to www.nbnz.co.nz (210.55.168.70), 30 hops max, 40 byte packets 1 cs-red-vrrp.auckland.clix.net.nz (203.167.224.53) 0.678 ms 0.607 ms 0.834 ms 2 cs2-e4-4-acld.auckland.clix.net.nz (203.167.224.55) 0.776 ms 0.646 ms 0.613 ms 3 ba2-fe0-1-0-acld.auckland.clix.net.nz (203.97.9.177) 0.855 ms 1.131 ms 0.718 ms 4 xtra.ape.net.nz (192.203.154.60) 3.019 ms 2.365 ms 1.725 ms 5 203.96.111.218 (203.96.111.218) 42.603 ms 41.431 ms 47.360 ms 6 203.96.111.217 (203.96.111.217) 60.746 ms 66.191 ms 78.594 ms 7 203.96.111.218 (203.96.111.218) 154.869 ms 159.711 ms * ^C noc% traceroute www.nbnz.co.nz traceroute to www.nbnz.co.nz (210.55.168.70), 30 hops max, 40 byte packets 1 cs-red-vrrp.auckland.clix.net.nz (203.167.224.53) 0.672 ms 0.634 ms 1.264 ms 2 cs2-e4-4-acld.auckland.clix.net.nz (203.167.224.55) 0.895 ms 0.643 ms 0.652 ms 3 ba2-fe0-1-0-acld.auckland.clix.net.nz (203.97.9.177) 1.304 ms 1.809 ms 1.085 ms 4 xtra.ape.net.nz (192.203.154.60) 2.856 ms 2.155 ms 1.760 ms 5 202-37-237-229.dds.xtra.co.nz (202.37.237.229) 70.480 ms 57.187 ms 36.798 ms 6 *^C noc% ~ben =~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~ Ben Martel Ph: +64 9 9124067 CLEAR Net Development Fax:+64 9 9125008 Mob:+64 21 541202 =~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~ --------- To unsubscribe from nznog, send email to majordomo(a)list.waikato.ac.nz where the body of your message reads: unsubscribe nznog
Site is up. All ICMP is blocked at the border router, instead of just filtering out undesirable ICMP traffic... Regards, Gordon Smith Network Operations Manager MoreNet Ltd. Fingerprint: 4093 91BC 0055 46B9 1B1A EDBA 45AD 2381 7B1D E4BE
-----Original Message----- From: owner-nznog(a)list.waikato.ac.nz [mailto:owner-nznog(a)list.waikato.ac.nz]On Behalf Of Ben Martel Sent: Wednesday, 22 August 2001 11:28 To: nznog(a)list.waikato.ac.nz Subject: XTRA network having problems?
Hey all,
Anybody noticed if XTRA is having problems???
~benm
--------- To unsubscribe from nznog, send email to majordomo(a)list.waikato.ac.nz where the body of your message reads: unsubscribe nznog
"Gordon Smith"
Site is up. All ICMP is blocked at the border router, instead of just filtering out undesirable ICMP traffic...
If you're really filtering *all* ICMP traffic, you've broken it. Path MTU discovery relies on ICMP fragmentation-required messages getting through, and *lots* of TCP implementations rely on MTU path discovery. It works fine as long as the MTUs are all the same, but when they aren't, or if encapsulation such as ESP or GRE are in use, it doesn't. ICMP is there for a reason. If you don't know what you're doing, don't touch it. -- don --------- To unsubscribe from nznog, send email to majordomo(a)list.waikato.ac.nz where the body of your message reads: unsubscribe nznog
Err... *I'm* not filtering ICMP, they are... At a minimum, they *should* allow type 3 The original poster was questioning whether the site was up, since it was unreachable with ICMP. By blocking all ICMP, such things as MTU path discovery are also broken - just like Hotmail.
-----Original Message----- From: owner-nznog(a)list.waikato.ac.nz [mailto:owner-nznog(a)list.waikato.ac.nz]On Behalf Of Don Stokes Sent: Wednesday, 22 August 2001 12:17 To: nznog(a)list.waikato.ac.nz Subject: Re: XTRA network having problems?
"Gordon Smith"
wrote: Site is up. All ICMP is blocked at the border router, instead of just filtering out undesirable ICMP traffic...
If you're really filtering *all* ICMP traffic, you've broken it. Path MTU discovery relies on ICMP fragmentation-required messages getting through, and *lots* of TCP implementations rely on MTU path discovery. It works fine as long as the MTUs are all the same, but when they aren't, or if encapsulation such as ESP or GRE are in use, it doesn't.
ICMP is there for a reason. If you don't know what you're doing, don't touch it.
-- don --------- To unsubscribe from nznog, send email to majordomo(a)list.waikato.ac.nz where the body of your message reads: unsubscribe nznog
--------- To unsubscribe from nznog, send email to majordomo(a)list.waikato.ac.nz where the body of your message reads: unsubscribe nznog
Yes. blocking all ICMP breaks things ( The ASB's Web Site is a good example
that breaks through GRE Tunnels because of MTU Discovery not working right)
Thanks
Craig Whitmore
Orcon Internet
http://www.orcon.net.nz
----- Original Message -----
From: "Don Stokes"
"Gordon Smith"
wrote: Site is up. All ICMP is blocked at the border router, instead of just filtering out undesirable ICMP traffic...
If you're really filtering *all* ICMP traffic, you've broken it. Path MTU discovery relies on ICMP fragmentation-required messages getting through, and *lots* of TCP implementations rely on MTU path discovery. It works fine as long as the MTUs are all the same, but when they aren't, or if encapsulation such as ESP or GRE are in use, it doesn't.
ICMP is there for a reason. If you don't know what you're doing, don't touch it.
-- don --------- To unsubscribe from nznog, send email to majordomo(a)list.waikato.ac.nz where the body of your message reads: unsubscribe nznog
--------- To unsubscribe from nznog, send email to majordomo(a)list.waikato.ac.nz where the body of your message reads: unsubscribe nznog
Damn it You mentioned the most hated words for anyone who has worked with GRE MTU path discovery. pre-frag, post-frag, aarrggghhh Damn it - now I have to go back to therapy =) On Wed, Aug 22, 2001 at 12:41:13PM +1200, Craig Whitmore wrote:
Yes. blocking all ICMP breaks things ( The ASB's Web Site is a good example that breaks through GRE Tunnels because of MTU Discovery not working right)
Thanks Craig Whitmore Orcon Internet http://www.orcon.net.nz
To unsubscribe from nznog, send email to majordomo(a)list.waikato.ac.nz where the body of your message reads: unsubscribe nznog
Now correct me if I'm wrong. But hasn't xtra/telecom always filtered out ICMP? Dean On Wed, Aug 22, 2001 at 12:16:53PM +1200, Don Stokes wrote:
"Gordon Smith"
wrote: Site is up. All ICMP is blocked at the border router, instead of just filtering out undesirable ICMP traffic...
If you're really filtering *all* ICMP traffic, you've broken it. Path MTU discovery relies on ICMP fragmentation-required messages getting through, and *lots* of TCP implementations rely on MTU path discovery. It works fine as long as the MTUs are all the same, but when they aren't, or if encapsulation such as ESP or GRE are in use, it doesn't.
ICMP is there for a reason. If you don't know what you're doing, don't touch it.
-- don --------- To unsubscribe from nznog, send email to majordomo(a)list.waikato.ac.nz where the body of your message reads: unsubscribe nznog
--------- To unsubscribe from nznog, send email to majordomo(a)list.waikato.ac.nz where the body of your message reads: unsubscribe nznog
I can't trace past their ape connection... Can't recall having ever being able to do so.
-----Original Message----- From: owner-nznog(a)list.waikato.ac.nz [mailto:owner-nznog(a)list.waikato.ac.nz]On Behalf Of Dean Pemberton Sent: Wednesday, 22 August 2001 13:02 To: Don Stokes Cc: nznog(a)list.waikato.ac.nz Subject: Re: XTRA network having problems?
Now correct me if I'm wrong. But hasn't xtra/telecom always filtered out ICMP?
Dean
--------- To unsubscribe from nznog, send email to majordomo(a)list.waikato.ac.nz where the body of your message reads: unsubscribe nznog
On Wed, Aug 22, 2001 at 01:32:01PM +1200, Gordon Smith wrote:
I can't trace past their ape connection...
Can't recall having ever being able to do so.
Short memory :) On Tue, Aug 21, 2001 at 08:24:57PM -0400, Joe Abley wrote:
http://maggie.automagic.org/cgi-bin/mtr.cgi?p=4&c=5&t=202.49.143.70
maggie$ mtr -4 --report --report-cycles 1 "202.49.143.70" HOST LOSS RCVD SENT BEST AVG WORST gateway1-acc-skyt.qsi.net.nz 0% 1 1 1.60 1.60 1.60 xtra.ape.net.nz 0% 1 1 3.39 3.39 3.39 100% 0 1 0.00 0.00 0.00 maggie$ --------- To unsubscribe from nznog, send email to majordomo(a)list.waikato.ac.nz where the body of your message reads: unsubscribe nznog
I have no idea.. but if someone is filtering out All ICMP on Public Routable
Addresses then they are "Breaking the NET" for a large number of users.. A
little anoying yes. Also still a large number of routers still break ECN
:-(
Thanks
Craig Whitmore
Orcon Internet
http://www.orcon.net.nz
----- Original Message -----
From: "Dean Pemberton"
Now correct me if I'm wrong. But hasn't xtra/telecom always filtered out
ICMP?
Dean
On Wed, Aug 22, 2001 at 12:16:53PM +1200, Don Stokes wrote:
"Gordon Smith"
wrote: Site is up. All ICMP is blocked at the border router, instead of just filtering out undesirable ICMP traffic...
If you're really filtering *all* ICMP traffic, you've broken it. Path MTU discovery relies on ICMP fragmentation-required messages getting through, and *lots* of TCP implementations rely on MTU path discovery. It works fine as long as the MTUs are all the same, but when they aren't, or if encapsulation such as ESP or GRE are in use, it doesn't.
ICMP is there for a reason. If you don't know what you're doing, don't touch it.
-- don --------- To unsubscribe from nznog, send email to majordomo(a)list.waikato.ac.nz where the body of your message reads: unsubscribe nznog
--------- To unsubscribe from nznog, send email to majordomo(a)list.waikato.ac.nz where the body of your message reads: unsubscribe nznog
--------- To unsubscribe from nznog, send email to majordomo(a)list.waikato.ac.nz where the body of your message reads: unsubscribe nznog
Before anyone goes accusing people of "Breaking the Net" we should probably ask someone at Xtra what their policy actually is. Is there anyone on the list from Xtra who wants to comment on which ICMP they actually block (if any) Dean On Wed, Aug 22, 2001 at 01:46:37PM +1200, Craig Whitmore wrote:
I have no idea.. but if someone is filtering out All ICMP on Public Routable Addresses then they are "Breaking the NET" for a large number of users.. A little anoying yes. Also still a large number of routers still break ECN :-(
Thanks Craig Whitmore Orcon Internet http://www.orcon.net.nz
----- Original Message ----- From: "Dean Pemberton"
To: "Don Stokes" Cc: Sent: Wednesday, August 22, 2001 1:02 PM Subject: Re: XTRA network having problems? Now correct me if I'm wrong. But hasn't xtra/telecom always filtered out
ICMP?
Dean
On Wed, Aug 22, 2001 at 12:16:53PM +1200, Don Stokes wrote:
"Gordon Smith"
wrote: Site is up. All ICMP is blocked at the border router, instead of just filtering out undesirable ICMP traffic...
If you're really filtering *all* ICMP traffic, you've broken it. Path MTU discovery relies on ICMP fragmentation-required messages getting through, and *lots* of TCP implementations rely on MTU path discovery. It works fine as long as the MTUs are all the same, but when they aren't, or if encapsulation such as ESP or GRE are in use, it doesn't.
ICMP is there for a reason. If you don't know what you're doing, don't touch it.
-- don --------- To unsubscribe from nznog, send email to majordomo(a)list.waikato.ac.nz where the body of your message reads: unsubscribe nznog
--------- To unsubscribe from nznog, send email to majordomo(a)list.waikato.ac.nz where the body of your message reads: unsubscribe nznog
--------- To unsubscribe from nznog, send email to majordomo(a)list.waikato.ac.nz where the body of your message reads: unsubscribe nznog
On Wed, Aug 22, 2001 at 11:57:56AM +1200, Gordon Smith wrote:
Site is up. All ICMP is blocked at the border router, instead of just filtering out undesirable ICMP traffic...
To which address? www.nbnz.co.nz A 202.49.143.70 www.nbnz.co.nz A 210.55.168.70 They both behave differently from where I'm looking. http://maggie.automagic.org/cgi-bin/mtr.cgi?p=4&c=5&t=202.49.143.70 http://maggie.automagic.org/cgi-bin/mtr.cgi?p=4&c=5&t=210.55.168.70 jabley(a)maggie[134]$ telnet 202.49.143.70 80 Trying 202.49.143.70... Connected to 202.49.143.70. Escape character is '^]'. ^] telnet> quit Connection closed. jabley(a)maggie[135]$ telnet 210.55.168.70 Trying 210.55.168.70... ^C jabley(a)maggie[136]$ --------- To unsubscribe from nznog, send email to majordomo(a)list.waikato.ac.nz where the body of your message reads: unsubscribe nznog
Both work for me, using Lynx. Both set cookies, first site gets trailing dots removed...
-----Original Message----- From: Joe Abley [mailto:jabley(a)automagic.org] Sent: Wednesday, 22 August 2001 12:25 To: Gordon Smith Cc: Ben Martel; nznog(a)list.waikato.ac.nz Subject: Re: XTRA network having problems?
On Wed, Aug 22, 2001 at 11:57:56AM +1200, Gordon Smith wrote:
Site is up. All ICMP is blocked at the border router, instead of just filtering out undesirable ICMP traffic...
To which address?
www.nbnz.co.nz A 202.49.143.70 www.nbnz.co.nz A 210.55.168.70
They both behave differently from where I'm looking.
http://maggie.automagic.org/cgi-bin/mtr.cgi?p=4&c=5&t=202.49.143.70 http://maggie.automagic.org/cgi-bin/mtr.cgi?p=4&c=5&t=210.55.168.70
jabley(a)maggie[134]$ telnet 202.49.143.70 80 Trying 202.49.143.70... Connected to 202.49.143.70. Escape character is '^]'. ^] telnet> quit Connection closed. jabley(a)maggie[135]$ telnet 210.55.168.70 Trying 210.55.168.70... ^C jabley(a)maggie[136]$
--------- To unsubscribe from nznog, send email to majordomo(a)list.waikato.ac.nz where the body of your message reads: unsubscribe nznog
participants (6)
-
Ben Martel
-
Craig Whitmore
-
Dean Pemberton
-
Don Stokes
-
Gordon Smith
-
Joe Abley