[lug] Connection problems from Europe

Jeff Schroeder jeff at neobox.net
Thu Mar 11 10:34:55 MST 2004

John wrote:

> Despite the traceroute failure (which may be misleading), it might be
> a good idea to somehow verify that you're not getting the packets on
> your outside interface before asking WilTel about it.

Heh, yeah, I always assume it's my fault before I go and scream at 
someone else. :)

The outside interface is an aliased IP address on the firewall.  The 
"main" (eth0) address is, and then I have various 
aliases to support the clients I host-- in this case, one of the 
aliases is

Connections to the .190 address work fine, as do connections to several 
others on the subnet.  But .166 fails, with the routing information I 
gave previously.  Thus, it seems the packets can get to the firewall-- 
and then to the web server-- without any problem, but in the case of 
pesky .166 (and a few others) they never get to the firewall at all.

It's all very strange, and something I haven't seen before.  I don't 
really know what to debug-- I feel like I'm shooting in the dark. :)

Thanks for the suggestions; I'll keep plugging at it.


