connectivity issues with Linux firewall/gateway

plastick

Golden Member
Sep 29, 2003
1,400
1
81
So I have a Debian 5 Linux Gateway/Firewall system that I've been configuring and I have it all working well. Internal LAN is on eth1 which serves DHCP: 172.16.0.0 network through a 24 port switch and the external LAN is on eth0 which acquires a 192.168.0.0 ip from my Linksys router, which then lets both 172.16.0.0 and 192.168.0.0 networks access to the internet (obviously). I have ip_forwarding enabled in the kernel and clients on my 172.16.0.0 network can access the internet just fine and I have an iptables firewall script on the Linux system which currently seems 100% functional. Nothing is wrong at this point.

This is the problem:
When I remove my Linksys router from the equation and connect the Linux gateway computer directly to my cable modem, I seem to lose internet functionality -- but not all the way. It seems I am able to ping external hosts such as google.com from the Linux system and get 100% replies. I also ping google.com from one of my Windows client machines and I am able to get replies. So it is connected to the internet. However when I run the browser and try to go to any sites, it just sits there and wont connect. Note: I have rebooted my modem, the Linux system, and my clients, as well as issued dhcp releases and renewals several times. I have even restarted my switch to clear the ARP tables.

Also, I have a DNS/Bind9 server installed. I am able to reach my gateway by typing in my server's domain name (mynetwork.com), and I get the apache2 webpage I set up. I am also able to visit any other websites out on the internet. So DNS seems to be set up correctly, unless something is getting messed up when I remove the Linksys. I guess the problem might be with my zone files, but why would everything work with the Linsys but not without it??


So to reiterate, the only difference with my network setup when it is working and when it is not is simply the removal of my Linksys router. HTTP requests and everything else work 100% when I have the router connected between my internal network server and my cable modem. They stop working when I remove the router from the network. Also, yes, I restart my cable modem, and I am able to get a public ip address assigned to my external network card on my Linux server. Also, from a client machine, I am able to ping hosts such as google.com or anandtech.com and I get 100% replies. But when I open the browser on the client machine, it just hangs forever while trying to load.

I have also considered that maybe I need a cat5 crossover cable to connect between my modem and my Linux server nic... however, could that even be a possibility considering that I can ping external hosts when connected that way?

I am stumped.
 
Last edited:

bobdole369

Diamond Member
Dec 15, 2004
4,504
2
0
something is getting messed up when I remove the Linksys.

In the situation (No Linksys Router)
What does the clients ipconfig /all look like?

No need for a crossover cable, however another possibility is that the MAC address of your debian system needs to be supplied to the cable company. In our ISP (a major one in the Caribbean, we allow a certain number of "CPE" devices - that is customer purchased equipment.) If the wrong CPE is connected to the cable modem they are routed to a walled garden. All pings from that "rogue device" are returned as ICMP replies, but you'll see something like this:

ping google.com
pinging 39.111.23.245
Reply from 10.134.133.133
Reply from 10.134.133.133

Give the cable company a call and supply the new MAC address now connected to the cable modem.
 
Last edited:

kornphlake

Golden Member
Dec 30, 2003
1,567
9
81
Might need to reboot the modem, my cable modem is kind of fussy about how and when I powercycle the different devices. AFAIK cable providers in the US no longer assign a MAC address of a PC or router to an account, but the modem will only allow internet access to the first MAC address connected after a power cycle.
 
Last edited:

plastick

Golden Member
Sep 29, 2003
1,400
1
81
I just checked with my ISP and they said I only need to register a mac address if I change out the modem, which I already knew. I can switch routers and pc's all I want.

I also reboot the modem each time I switch out the router for the Linux system, and if I am able to ping and get replies, at least I know I am successfully connected to my ISP... it's obvious anyway since my eth0 device obtains a public ip address. Even if I am getting "fake" replies from google.com, I am still getting replies.

So what the hell??
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |