• February 24, 2025, 07:01:39 PM
  • Welcome, Guest
Please login or register.

Login with username, password and session length
Advanced search  

News:

This Forum Beta is ONLY for registered owners of D-Link products in the USA for which we have created boards at this time.

Author Topic: Trouble accesing specific site  (Read 8285 times)

disciplefk

  • Level 1 Member
  • *
  • Posts: 6
Trouble accesing specific site
« on: January 27, 2010, 07:13:19 AM »

Hi There,

I have a dlink DFL-700 that cannot access or ping one specific site, thomasnet.com.  All other sites I visit work fine.  If I bypass the router or use a different brand, I can access the site.  I tried disabling all global policies and and firewall rules, but still cannot ping or access site.  Any suggestions?  Other than not visiting  that site ;)

Firmware version: 1.34.00
Logged

Fatman

  • Level 9 Member
  • ****
  • Posts: 1675
Re: Trouble accesing specific site
« Reply #1 on: January 27, 2010, 08:09:49 AM »

Do you have any meaningful logs?

What type of WAN do you use?

What is your WAN MTU?

Does your Policy for outbound traffic to this site include any ALGs?
Logged
non progredi est regredi

disciplefk

  • Level 1 Member
  • *
  • Posts: 6
Re: Trouble accesing specific site
« Reply #2 on: January 27, 2010, 08:38:49 AM »

My logs have entries repeating :     [
2010-01-27 11:27:10] <5>EFW: DROP: prio=2 rule=dropall-final action=drop recvif=WAN srcip=*outside ips* destip=**our ip address* ipproto=UDP ipdatalen=11 srcport=26070 destport=8780 udptotlen=11

We have a static ip address and MTU is set to maximum 1500.  I disabled all our custom policies and content filtering, so none of those should be the cause.
Logged

Fatman

  • Level 9 Member
  • ****
  • Posts: 1675
Re: Trouble accesing specific site
« Reply #3 on: January 27, 2010, 08:55:43 AM »

is *outside IPs* the IP that resolved for that domain name, or tied to attempts to visit that site in any way?  This is UDP traffic, so I doubt it is connected.

Do you have DSL, Cable, Telco, Satellite, or something else?  The reason I ask is because PPPoE encapsulation would make your MTU for DSL 1492 at most which has been known to cause problems like this.
Logged
non progredi est regredi

disciplefk

  • Level 1 Member
  • *
  • Posts: 6
Re: Trouble accesing specific site
« Reply #4 on: January 27, 2010, 09:04:22 AM »

No, you are correct, the outside IPs are not associated with the problem site.

We have cable here, no PPPoE.  I do have VPN IPsec tunnel MTU set lower, but that should not effect our LAN users here right?

Thanks for helping me with this.
Logged

Fatman

  • Level 9 Member
  • ****
  • Posts: 1675
Re: Trouble accesing specific site
« Reply #5 on: January 27, 2010, 09:19:52 AM »

No, that shouldn't effect the LAN.

I hate to go back to square one, but if the firewall is dropping something we really should be seeing some logging of it, are we sure there is no relevant logging happening?

Can you resolve that DNS correctly from behind the DFL?
Logged
non progredi est regredi

disciplefk

  • Level 1 Member
  • *
  • Posts: 6
Re: Trouble accesing specific site
« Reply #6 on: January 27, 2010, 09:50:58 AM »

You would think it would show in the log, I cleared it and tried again, no entries.  The same error is reported over and over for other requests.  The outside ip changes, but that is all.  No entries for the problem ip.  If I ping the sitename, it resolves for the correct ip address, but times out, no response.  Again, if I remove the router and ping the site, returns same ip address and site is accessible.
Logged

disciplefk

  • Level 1 Member
  • *
  • Posts: 6
Re: Trouble accesing specific site
« Reply #7 on: January 27, 2010, 09:59:08 AM »

I dont know if this is useful or not, but we could access the site up until about a month or two ago.  I think they have done a re-design and thats when it went bad for us.  Could be coincidence?
Logged

Fatman

  • Level 9 Member
  • ****
  • Posts: 1675
Re: Trouble accesing specific site
« Reply #8 on: January 27, 2010, 10:07:14 AM »

I don't believe in coincidence, I would wish to know what they changed if I could.
Logged
non progredi est regredi

disciplefk

  • Level 1 Member
  • *
  • Posts: 6
Re: Trouble accesing specific site
« Reply #9 on: January 27, 2010, 10:13:39 AM »

I wish to =)  Unfortunately other than design, I do not know what specifically they have changed to cause this.  I do not frequent the site, and have never looked at the source until now.  I only received the complaint from the department that needs to use the site after the problem occurred.
Logged