TechMonkey Posted January 30, 2015 Posted January 30, 2015 Ok, can anyone think of a reason I would be able to traceroute to an external address from one server but not from another? Both are DCs, both have firewall off. I have been playing around as I think there is something up with the DNS on one server but it can't be DNS related as if I try and traceroute an IP it fails as well. It fails on the second hop (our Smoothwall) stating Destination protocol unreachable. The other server runs the trace with no issues. I'd rather fix this or work out why it is happening so I know it isn't a symptom. Any ideas?
howartp Posted January 30, 2015 Posted January 30, 2015 Off the top of my head, Networking, Outgoing Ports - are both servers in a policy that allows ICMP outbound? 1
TechMonkey Posted January 31, 2015 Author Posted January 31, 2015 Thanks for the response. Firewall is off on both but all ICMP rules are set to allow.
bald_pig Posted January 31, 2015 Posted January 31, 2015 Try a third machine, is the working DC the exception or the norm? 1
DMcCoy Posted January 31, 2015 Posted January 31, 2015 surely the most reasonable answer is that smoothwall is blocking the traffic? 1
Jamo Posted January 31, 2015 Posted January 31, 2015 Or they are on different subnets and the smoothwall doesn't have a route back to the original host 1
TechMonkey Posted February 2, 2015 Author Posted February 2, 2015 But why would Smoothwall block one server but not the other? I can't find any rules mentioning either of the servers in Smoothwall and the network is flat so no different subnet. Well the good news is it seems to only be that one server. No idea why or if it is causing issues.
jinnantonnixx Posted February 2, 2015 Posted February 2, 2015 Check the routing tables on the servers. In Windows, 'route print' will print the routing tables. Compare the flaky machine with the working ones. 1
TechMonkey Posted February 2, 2015 Author Posted February 2, 2015 Route tables are the same between the DC's. This is doing my head in. I must be missing something very basic.
Duke5A Posted February 4, 2015 Posted February 4, 2015 Maybe a subnet mask is incorrect on your firewall rules on the Smoothwall and it's clipping the part of the internal network your second DC is on.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now