Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Weird IP showing in traceroute

Hi there,

I've a weird problem.

I was troubleshooting my vlans and I've noticed something weird.

When I run traceroute to any website or even internal vlan IP, 1st hop is always my UTM gateway IP 10.0.0.1 address but next hop is 10.96.180.1 which I don't recognise. It's not ISP nor one of my internal IPs.

I've country blocking enabled to block traffic from all countries except UK, and allow all outgoig traffic to everywhere.

I've looked up this ip ,10.96.180.1, on who is and it said it's in Durham USA (weird!) Strange thing is that when I block traffic to USA, I no longer can ping, traceroute or browse internet!

I've checked static routes, logs etc. and I can't figure out where this IP comes from.

Any ideas? It's all new to me!

Thanks

K



This thread was automatically locked due to age.
Parents
  • Have you talked to your ISP about this? Once the traffic leaves the UTM it's sort of out of your hands.

  • Hang on..... so if you traceroute to another vlan on your UTM, it traverses that address? The UTM would only show it's address unless the traffic is leaving the UTM at which point, the next address is the next hop or gateway.

     

    Try a traceroute to:

    8.8.8.8 (google dns)

    x.x.x.x (one of your other subnets local to your UTM)

    post the results omitting any public ip of your UTM etc

Reply
  • Hang on..... so if you traceroute to another vlan on your UTM, it traverses that address? The UTM would only show it's address unless the traffic is leaving the UTM at which point, the next address is the next hop or gateway.

     

    Try a traceroute to:

    8.8.8.8 (google dns)

    x.x.x.x (one of your other subnets local to your UTM)

    post the results omitting any public ip of your UTM etc

Children
No Data