[ale] OT: dumb question

jc.lightner at comcast.net jc.lightner at comcast.net
Mon Nov 18 21:57:24 EST 2024


Funny that.  We once ran into an issue suddenly on a server.  When we tracked it down it was found we had the wrong netmask for the VLAN on our affected server.

The odd thing was when I found it I could see it had been incorrect ever since we’d moved to a new data center months earlier (and presumably was at the old data center).   Though changing it resolved the issue no one could ever explain why it had “suddenly” become a problem given that it had run misconfigured for so long.   I suspect the network or security admins made a tweak of some sort on discovering a misconfiguration on their end.   Doing that would be OK but should have been done via a change control.   Almost always, finding the solution to a problem starts with the question:  “What changed?”

Of course we immediately checked our other servers to be sure none were configured with incorrect netmasks or gateways.

 

From: Boris Borisov <bugyatl at gmail.com> 
Sent: Monday, November 18, 2024 12:44 PM
To: Atlanta Linux Enthusiasts <ale at ale.org>
Cc: JEFFREY LIGHTNER <jc.lightner at comcast.net>
Subject: Re: [ale] OT: dumb question

 

Turns out the switch port was pass-through to the wrong VLAN.

Likely for me I've got the proper guy on the phone today.

 

On Fri, Nov 15, 2024, 18:44 Jeff Lightner via Ale <ale at ale.org <mailto:ale at ale.org> > wrote:

Often ping is disabled on gateways to prevent DoS attacks.   If you need to
ping it for monitoring purposes you might be able to get the admin to
whitelist the IP from which you're attempting the ping.

-----Original Message-----
From: Ale <ale-bounces at ale.org <mailto:ale-bounces at ale.org> > On Behalf Of Derek Atkins via Ale
Sent: Friday, November 15, 2024 2:58 PM
To: Atlanta Linux Enthusiasts <ale at ale.org <mailto:ale at ale.org> >
Cc: Derek Atkins <derek at ihtfp.com <mailto:derek at ihtfp.com> >
Subject: Re: [ale] OT: dumb question

Yeah, some gateways do not respond to a ping.
Do you get an IP Address?  A Route?
Try ping (or better yet, mtr) to 8.8.8.8

-derek

On Fri, November 15, 2024 2:38 pm, Boris Borisov via Ale wrote:
> I never dealt with network switches so there.
>
> I have a device set on small network segment connected to a switch 
> that I don't have control to.
>
> I cannot ping the gateway on that segment.
>
> Is there any reason/possibility gateway to not respond on ping?
> _______________________________________________
> Ale mailing list
> Ale at ale.org <mailto:Ale at ale.org> 
> https://mail.ale.org/mailman/listinfo/ale
> See JOBS, ANNOUNCE and SCHOOLS lists at 
> http://mail.ale.org/mailman/listinfo
>


-- 
       Derek Atkins                 617-623-3745
       derek at ihtfp.com <mailto:derek at ihtfp.com>              www.ihtfp.com <http://www.ihtfp.com> 
       Computer and Internet Security Consultant

_______________________________________________
Ale mailing list
Ale at ale.org <mailto:Ale at ale.org> 
https://mail.ale.org/mailman/listinfo/ale
See JOBS, ANNOUNCE and SCHOOLS lists at
http://mail.ale.org/mailman/listinfo

_______________________________________________
Ale mailing list
Ale at ale.org <mailto:Ale at ale.org> 
https://mail.ale.org/mailman/listinfo/ale
See JOBS, ANNOUNCE and SCHOOLS lists at
http://mail.ale.org/mailman/listinfo

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://mail.ale.org/pipermail/ale/attachments/20241118/12ab8a52/attachment.htm>


More information about the Ale mailing list