Hi astaro fellows,
could you please hit me? I noticed a damn weird behavior today.
First of all - a little overview:
. . . . . . . . . Firewall[Net1] (got static route to Net2 over Router)
. . . . . . . . . . |
Server[Net1]--------------[Net1]Router[Net2]--------------Client [Net2]
ASL V6.101
Ok - here the problem:
Server got only one gateway - the default over Firewall. No packetfilter rules for Server->Client or the other way. The bottom rule is a "reject everything from anywhere to anywhere".
This was a productive system running fine for 2-3 month with Server beeing able to connect to Client every day - communication did work perfectly.
But sometimes we had a problem we couldn't locate in the beginning. Once or twice a month, the Server could not connect to the Client. We looked here and there, didn't do anything at all - and a few minutes later - it worked again.
Today it did not work for 2 hours, so i rechecked everything i could think about. When i saw that Server doesn't have a chance to see Client at all - because there was no route set, i was pretty shocked.
I searched through packetfilter-logs on the firewall and again - i can't understand..
Whenever the connection did work, no Client IP was found in those days logfile.
On every day with problems with the connection - the packets hit the REJECT rule.. but just for a few minutes - then no appearance of the Client IP anymore.
How the f*ck did it work? Is it a bug in ASL? Could the Server detect the route over Router itself? Both seems pretty improbably if not impossible..
Any ideas?
Greetings,
a really baffled Sebastian
This thread was automatically locked due to age.