Re: Masquerading problems: squeeze via lenny

2010-01-07 Thread Osamu Aoki
Hi, You already solved this problem but ... But this explain where is the disconnect. On Tue, Jan 05, 2010 at 12:19:09AM +0200, Andrei Popescu wrote: > On Mon,04.Jan.10, 16:32:42, Osamu Aoki wrote: > > Hi, > > > > On Sun, Jan 03, 2010 at 07:45:07PM +0100, Marc Schröder wrote: > > > its better t

[Solved] Re: Masquerading problems: squeeze via lenny

2010-01-05 Thread Andrei Popescu
On Sun,03.Jan.10, 10:30:18, Andrei Popescu wrote: [...] > The problem is that some websites work flawlessly from the squeeze box > and some stall. The same sites are ok from the lenny box. Here are Turned out it was a problem with Path MTU Discovery[1] and setting CLAMPMSS=YES in shorewall

Re: Masquerading problems: squeeze via lenny

2010-01-05 Thread Antonio Perez
Antonio Perez wrote: > which both work on port 80, filter the destination port 80 and compare. > hint: tcp.dstport==80 also you may add the dest IP or any other relevant factor to reduce noise: for wget http://www.google.com : tcp.dstport==80 and ip.addr==74.125.159.1/24 for http://www.

Re: Masquerading problems: squeeze via lenny

2010-01-05 Thread Antonio Perez
Andrei Popescu wrote: > On Tue,05.Jan.10, 03:53:22, Antonio Perez wrote: > >> You could start a Wireshark capture on both the LAN and the PPP before >> performing the wget command and compare both. > > I installed tshark (I only have ssh access as both machines are in a > different city) on the

Re: Masquerading problems: squeeze via lenny

2010-01-05 Thread Andrei Popescu
On Tue,05.Jan.10, 03:53:22, Antonio Perez wrote: > You could start a Wireshark capture on both the LAN and the PPP before > performing the wget command and compare both. I installed tshark (I only have ssh access as both machines are in a different city) on the gateway, but unfortunately I can'

Re: Masquerading problems: squeeze via lenny

2010-01-05 Thread Antonio Perez
Andrei Popescu wrote: > on the gateway in /etc/ppp/peers/provider and ifconfig ppp0 correctly > shows the new setting, but no change. Thanks for the hint though. Hi: You could start a Wireshark capture on both the LAN and the PPP before performing the wget command and compare both. -- Antonio

Re: Masquerading problems: squeeze via lenny

2010-01-04 Thread Andrei Popescu
On Sun,03.Jan.10, 12:14:37, Andrei Popescu wrote: > > > Have you checked IPV6 issues discussed recently on debian-devel? > > I just tried commenting out > > net.ipv6.bindv6only = 1 > > in /etc/sysctl.d/bindv6only.conf but no change. The Lenny box also has > IPV6_DISABLED=yes set in shorewall.c

Re: Masquerading problems: squeeze via lenny

2010-01-04 Thread Andrei Popescu
On Mon,04.Jan.10, 16:32:42, Osamu Aoki wrote: > Hi, > > On Sun, Jan 03, 2010 at 07:45:07PM +0100, Marc Schröder wrote: > > its better to setup a propper mtu size on the gateway. then all > > clients behind will work without extra modifications. > > Yes, if the problem is caused by a gateway you c

Re: Masquerading problems: squeeze via lenny

2010-01-03 Thread Osamu Aoki
Hi, On Sun, Jan 03, 2010 at 07:45:07PM +0100, Marc Schröder wrote: > its better to setup a propper mtu size on the gateway. then all > clients behind will work without extra modifications. Yes, if the problem is caused by a gateway you control, this is the root cause fix. This is done, as I und

Re: Masquerading problems: squeeze via lenny

2010-01-03 Thread Marc Schröder
its better to setup a propper mtu size on the gateway. then all clients behind will work without extra modifications. marc Am Sonntag 03 Januar 2010 13:02:54 schrieb Osamu Aoki: > On Sun, Jan 03, 2010 at 12:03:34PM +0100, Marc Schröder wrote: > > i think your problem is mtu fragmentation. > > >

Re: Masquerading problems: squeeze via lenny

2010-01-03 Thread Osamu Aoki
On Sun, Jan 03, 2010 at 12:03:34PM +0100, Marc Schröder wrote: > i think your problem is mtu fragmentation. > > try on the squeeze the following as root: > > ifconfig eth0 mtu 1300 > > and try that wget again > marc yah... behing choking pppoe connection ... You can add iface eth0 inet dhcp

Re: Masquerading problems: squeeze via lenny

2010-01-03 Thread Marc Schröder
i think your problem is mtu fragmentation. try on the squeeze the following as root: ifconfig eth0 mtu 1300 and try that wget again marc Am Sonntag 03 Januar 2010 09:30:18 schrieb Andrei Popescu: > Hi everybody, > > I'm banging my head against the wall with this one and could appreciate >

Re: Masquerading problems: squeeze via lenny

2010-01-03 Thread Andrei Popescu
On Sun,03.Jan.10, 03:22:29, Stan Hoeppner wrote: > Andrei Popescu put forth on 1/3/2010 2:30 AM: > > > I have no idea what to try so any hints are welcome. > > Try looking at your logs. This is exactly why logs exist, for > troubleshooting. > Start with the Lenny host's log files such as syslo

Re: Masquerading problems: squeeze via lenny

2010-01-03 Thread Andrei Popescu
On Sun,03.Jan.10, 18:10:48, Osamu Aoki wrote: > On Sun, Jan 03, 2010 at 10:30:18AM +0200, Andrei Popescu wrote: > > Hi everybody, > > The problem is that some websites work flawlessly from the squeeze box > > and some stall. The same sites are ok from the lenny box. Here are > > example sessions

Re: Masquerading problems: squeeze via lenny

2010-01-03 Thread Osamu Aoki
On Sun, Jan 03, 2010 at 10:30:18AM +0200, Andrei Popescu wrote: > Hi everybody, > The problem is that some websites work flawlessly from the squeeze box > and some stall. The same sites are ok from the lenny box. Here are > example sessions with wget: Have you tried runing lenny box inside your

Re: Masquerading problems: squeeze via lenny

2010-01-03 Thread Stan Hoeppner
Andrei Popescu put forth on 1/3/2010 2:30 AM: > I have no idea what to try so any hints are welcome. Try looking at your logs. This is exactly why logs exist, for troubleshooting. Start with the Lenny host's log files such as syslog and messages and any/all custom log files you or your firewall