Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #199662 > unrolled thread

Strange Network Problem

Started by"Stephen P. Molnar" <s.molnar@sbcglobal.net>
First post2018-08-31 22:00 +0200
Last post2018-09-01 10:10 +0200
Articles 14 — 5 participants

Back to article view | Back to linux.debian.user


Contents

  Strange Network Problem "Stephen P. Molnar" <s.molnar@sbcglobal.net> - 2018-08-31 22:00 +0200
    Re: Strange Network Problem Dan Purgert <dan@djph.net> - 2018-08-31 23:40 +0200
    Re: Strange Network Problem David Christensen <dpchrist@holgerdanske.com> - 2018-09-01 04:50 +0200
      Re: Strange Network Problem "Stephen P. Molnar" <s.molnar@sbcglobal.net> - 2018-09-01 13:10 +0200
        Re: Strange Network Problem rhkramer@gmail.com - 2018-09-01 14:30 +0200
          Re: Strange Network Problem "Stephen P. Molnar" <s.molnar@sbcglobal.net> - 2018-09-01 18:10 +0200
            Re: Strange Network Problem rhkramer@gmail.com - 2018-09-01 20:00 +0200
        Re: Strange Network Problem David Christensen <dpchrist@holgerdanske.com> - 2018-09-02 07:40 +0200
          Re: Strange Network Problem "Stephen P. Molnar" <s.molnar@sbcglobal.net> - 2018-09-02 14:20 +0200
            Re: Strange Network Problem mick crane <mick.crane@gmail.com> - 2018-09-02 14:50 +0200
              Re: Strange Network Problem David Christensen <dpchrist@holgerdanske.com> - 2018-09-02 20:40 +0200
                Re: Strange Network Problem mick crane <mick.crane@gmail.com> - 2018-09-03 00:30 +0200
                  Re: Strange Network Problem David Christensen <dpchrist@holgerdanske.com> - 2018-09-03 05:20 +0200
    Re: Strange Network Problem mick crane <mick.crane@gmail.com> - 2018-09-01 10:10 +0200

#199662 — Strange Network Problem

From"Stephen P. Molnar" <s.molnar@sbcglobal.net>
Date2018-08-31 22:00 +0200
SubjectStrange Network Problem
Message-ID<wsXKh-4DU-1@gated-at.bofh.it>
I am running Debian Stretch on my Linux platform.

I have noticed low internet traffic when I have not been doing anything 
outside of my LAN.  This has made me a tad suspicious.

Now:

root@AbNormal:/home/comp# ifconfig
enp2s0: flags=4163<UP,BROADCAST,RUNNING,MULTICAST>  mtu 1500
         inet 162.237.98.238  netmask 255.255.252.0  broadcast 
162.237.99.255
         ether bc:ee:7b:5e:83:36  txqueuelen 1000  (Ethernet)
         RX packets 796401  bytes 529829454 (505.2 MiB)
         RX errors 0  dropped 0  overruns 0  frame 0
         TX packets 236054  bytes 22520861 (21.4 MiB)
         TX errors 0  dropped 0 overruns 0  carrier 0  collisions 0

lo: flags=73<UP,LOOPBACK,RUNNING>  mtu 65536
         inet 127.0.0.1  netmask 255.0.0.0
         loop  txqueuelen 1  (Local Loopback)
         RX packets 399  bytes 42360 (41.3 KiB)
         RX errors 0  dropped 0  overruns 0  frame 0
         TX packets 399  bytes 42360 (41.3 KiB)
         TX errors 0  dropped 0 overruns 0  carrier 0  collisions 0


It turns out that this ISP, 162.237.98.238 is my ISP, AT&T here in 
Columbus, Ohio.

The other four nodes on my LAn all have IP's starting with 192.168.1 - 
which is what it's supposed to be.

Just what is going on here? I don't have a clue.

I dop have firewalls implemented on both the modem and the computers.

Any insights will be much appreciated.

Thanks in advance.

-- 
Stephen P. Molnar, Ph.D.
Consultant
www.molecular-modeling.net
(614)312-7528 (c)
Skype: smolnar1

[toc] | [next] | [standalone]


#199668

FromDan Purgert <dan@djph.net>
Date2018-08-31 23:40 +0200
Message-ID<wsZj3-5DY-1@gated-at.bofh.it>
In reply to#199662
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Stephen P. Molnar wrote:
> I am running Debian Stretch on my Linux platform.
>
> I have noticed low internet traffic when I have not been doing
> anything outside of my LAN.  This has made me a tad suspicious.
>
>
> It turns out that this ISP, 162.237.98.238 is my ISP, AT&T here in 
> Columbus, Ohio.

Is this pc perhaps set up to be in the dmz?


-----BEGIN PGP SIGNATURE-----

iQEzBAEBCAAdFiEEBcqaUD8uEzVNxUrujhHd8xJ5ooEFAluJst4ACgkQjhHd8xJ5
ooFfegf/UD2Fcat+GG27VWk8w9FdCDmrNwWLHX0jHXa6/0HNQYVKRBYK6x2CXvtk
98XaXDbKAp/cPrMquK9az0po9bC/M97/Ou+/ul1CiTeL9qKN065x+LuLGkEC5Ow/
f4hhqhVCzawQi4A5NcqF14asM2S3FcDQGfSpPIsP1RsA8cSO6ZykQfyLR+s0cs6K
mVfhE/1/+OdJms4Fa2tbRzgP2O7nnvKTrnZjLVTSkhVsaonL7K7USpH8bQ6jYW+N
t/o6kd4R3LLT/cpw0c6oX7835MRT4SPpmBFCbQfRxSjW4UMxpo6yZav6NwQhNEbN
owdR+fRHrLkYanSaKz4k8m3tesLgJQ==
=DK7D
-----END PGP SIGNATURE-----

-- 
|_|O|_| Registered Linux user #585947
|_|_|O| Github: https://github.com/dpurgert
|O|O|O| PGP: 05CA 9A50 3F2E 1335 4DC5  4AEE 8E11 DDF3 1279 A281

[toc] | [prev] | [next] | [standalone]


#199675

FromDavid Christensen <dpchrist@holgerdanske.com>
Date2018-09-01 04:50 +0200
Message-ID<wt493-8tA-1@gated-at.bofh.it>
In reply to#199662
On 08/31/2018 12:50 PM, Stephen P. Molnar wrote:
> I am running Debian Stretch on my Linux platform.
> 
> I have noticed low internet traffic when I have not been doing anything 
> outside of my LAN.  This has made me a tad suspicious.
> 
> Now:
> 
> root@AbNormal:/home/comp# ifconfig
> enp2s0: flags=4163<UP,BROADCAST,RUNNING,MULTICAST>  mtu 1500
>          inet 162.237.98.238  netmask 255.255.252.0  broadcast 
> 162.237.99.255
>          ether bc:ee:7b:5e:83:36  txqueuelen 1000  (Ethernet)
>          RX packets 796401  bytes 529829454 (505.2 MiB)
>          RX errors 0  dropped 0  overruns 0  frame 0
>          TX packets 236054  bytes 22520861 (21.4 MiB)
>          TX errors 0  dropped 0 overruns 0  carrier 0  collisions 0
> 
> lo: flags=73<UP,LOOPBACK,RUNNING>  mtu 65536
>          inet 127.0.0.1  netmask 255.0.0.0
>          loop  txqueuelen 1  (Local Loopback)
>          RX packets 399  bytes 42360 (41.3 KiB)
>          RX errors 0  dropped 0  overruns 0  frame 0
>          TX packets 399  bytes 42360 (41.3 KiB)
>          TX errors 0  dropped 0 overruns 0  carrier 0  collisions 0
> 
> 
> It turns out that this ISP, 162.237.98.238 is my ISP, AT&T here in 
> Columbus, Ohio.
> 
> The other four nodes on my LAn all have IP's starting with 192.168.1 - 
> which is what it's supposed to be.
> 
> Just what is going on here? I don't have a clue.
> 
> I dop have firewalls implemented on both the modem and the computers.
> 
> Any insights will be much appreciated.
> 
> Thanks in advance.
> 

Running nslookup(1):

     2018-08-31 18:53:21 dpchrist@vstretch ~
     $ nslookup 162.237.98.238
     Server:		192.168.5.1
     Address:	192.168.5.1#53

     Non-authoritative answer:
     238.98.237.162.in-addr.arpa	name = 
162-237-98-238.lightspeed.clmboh.sbcglobal.net.

     Authoritative answers can be found from:


Running host(1):

     2018-08-31 18:58:15 dpchrist@vstretch ~
     $ host 162.237.98.238
     238.98.237.162.in-addr.arpa domain name pointer 
162-237-98-238.lightspeed.clmboh.sbcglobal.net.


162.237.98.238 appears to be a valid IPv4 public Internet address.


You should have a device provided by your Internet service provider 
(ISP) between their wiring (e.g. telephone service) and your wiring 
(e.g. Ethernet local area network/LAN).  What is the make and model of 
the ISP device?  Please provide a URL to the product support page.


What are the "other four nodes"?


How is everything interconnected?


David

[toc] | [prev] | [next] | [standalone]


#199682

From"Stephen P. Molnar" <s.molnar@sbcglobal.net>
Date2018-09-01 13:10 +0200
Message-ID<wtbWW-4Ln-7@gated-at.bofh.it>
In reply to#199675

On 08/31/2018 10:41 PM, David Christensen wrote:
> On 08/31/2018 12:50 PM, Stephen P. Molnar wrote:
>> I am running Debian Stretch on my Linux platform.
>>
>> I have noticed low internet traffic when I have not been doing 
>> anything outside of my LAN.  This has made me a tad suspicious.
>>
>> Now:
>>
>> root@AbNormal:/home/comp# ifconfig
>> enp2s0: flags=4163<UP,BROADCAST,RUNNING,MULTICAST>  mtu 1500
>>          inet 162.237.98.238  netmask 255.255.252.0  broadcast 
>> 162.237.99.255
>>          ether bc:ee:7b:5e:83:36  txqueuelen 1000  (Ethernet)
>>          RX packets 796401  bytes 529829454 (505.2 MiB)
>>          RX errors 0  dropped 0  overruns 0  frame 0
>>          TX packets 236054  bytes 22520861 (21.4 MiB)
>>          TX errors 0  dropped 0 overruns 0  carrier 0 collisions 0
>>
>> lo: flags=73<UP,LOOPBACK,RUNNING>  mtu 65536
>>          inet 127.0.0.1  netmask 255.0.0.0
>>          loop  txqueuelen 1  (Local Loopback)
>>          RX packets 399  bytes 42360 (41.3 KiB)
>>          RX errors 0  dropped 0  overruns 0  frame 0
>>          TX packets 399  bytes 42360 (41.3 KiB)
>>          TX errors 0  dropped 0 overruns 0  carrier 0 collisions 0
>>
>>
>> It turns out that this ISP, 162.237.98.238 is my ISP, AT&T here in 
>> Columbus, Ohio.
>>
>> The other four nodes on my LAn all have IP's starting with 192.168.1 
>> - which is what it's supposed to be.
>>
>> Just what is going on here? I don't have a clue.
>>
>> I dop have firewalls implemented on both the modem and the computers.
>>
>> Any insights will be much appreciated.
>>
>> Thanks in advance.
>>
>
> Running nslookup(1):
>
>     2018-08-31 18:53:21 dpchrist@vstretch ~
>     $ nslookup 162.237.98.238
>     Server:        192.168.5.1
>     Address:    192.168.5.1#53
>
>     Non-authoritative answer:
>     238.98.237.162.in-addr.arpa    name = 
> 162-237-98-238.lightspeed.clmboh.sbcglobal.net.
>
>     Authoritative answers can be found from:
>
>
> Running host(1):
>
>     2018-08-31 18:58:15 dpchrist@vstretch ~
>     $ host 162.237.98.238
>     238.98.237.162.in-addr.arpa domain name pointer 
> 162-237-98-238.lightspeed.clmboh.sbcglobal.net.
>
>
> 162.237.98.238 appears to be a valid IPv4 public Internet address.
>
>
> You should have a device provided by your Internet service provider 
> (ISP) between their wiring (e.g. telephone service) and your wiring 
> (e.g. Ethernet local area network/LAN).  What is the make and model of 
> the ISP device?  Please provide a URL to the product support page.
>
>
> What are the "other four nodes"?
>
>
> How is everything interconnected?
>
>
> David
>
>
Thanks for your reply.

ISO device is an Arris BGE210-700 Broadband Gateway Release 1.0 from 
AT&T (http://www.arris.com/Search/?q=Arris+BGE210-700+Broadband+Gateway)

Wired Connections:  2 Desktops,  printer and VOIP telephone

Wireless Connections:  Laptop and two Android Smartphones

root@AbNormal:/home/comp# nslookup
 > nslookup -a
Server:        192.168.1.254
Address:    192.168.1.254#53

Non-authoritative answer:
Name:    nslookup
Address: 198.105.244.130
Name:    nslookup
Address: 104.239.207.44
 >
 > host
Server:        192.168.1.254
Address:    192.168.1.254#53

Non-authoritative answer:
*** Can't find host: No answer
 >

-- 
Stephen P. Molnar, Ph.D.
Consultant
www.molecular-modeling.net
(614)312-7528 (c)
Skype: smolnar1

[toc] | [prev] | [next] | [standalone]


#199683

Fromrhkramer@gmail.com
Date2018-09-01 14:30 +0200
Message-ID<wtdcl-5om-5@gated-at.bofh.it>
In reply to#199682
On Saturday, September 01, 2018 07:05:55 AM Stephen P. Molnar wrote:
> On 08/31/2018 10:41 PM, David Christensen wrote:
> > On 08/31/2018 12:50 PM, Stephen P. Molnar wrote:
> >> I am running Debian Stretch on my Linux platform.
> >> 
> >> I have noticed low internet traffic when I have not been doing
> >> anything outside of my LAN.  This has made me a tad suspicious.
> >> 

> Wired Connections:  2 Desktops,  printer and VOIP telephone
> 
> Wireless Connections:  Laptop and two Android Smartphones

Out of curiosity, who is your VOIP service provider?

I use ObiHai, and find that it exchanges traffic with its "server" continuously.

I've not recently attempted to check how much, and don't remember any figures, 
but it wouldn't surprise me if that accounts for some, most, all of the traffic 
you report.

And, maybe Android smartphones do something similar, especially if they are 
setup for VOIP or some similar service.

[toc] | [prev] | [next] | [standalone]


#199686

From"Stephen P. Molnar" <s.molnar@sbcglobal.net>
Date2018-09-01 18:10 +0200
Message-ID<wtgDf-7t2-5@gated-at.bofh.it>
In reply to#199683

On 09/01/2018 08:26 AM, rhkramer@gmail.com wrote:
> On Saturday, September 01, 2018 07:05:55 AM Stephen P. Molnar wrote:
>> On 08/31/2018 10:41 PM, David Christensen wrote:
>>> On 08/31/2018 12:50 PM, Stephen P. Molnar wrote:
>>>> I am running Debian Stretch on my Linux platform.
>>>>
>>>> I have noticed low internet traffic when I have not been doing
>>>> anything outside of my LAN.  This has made me a tad suspicious.
>>>>
>> Wired Connections:  2 Desktops,  printer and VOIP telephone
>>
>> Wireless Connections:  Laptop and two Android Smartphones
> Out of curiosity, who is your VOIP service provider?
>
> I use ObiHai, and find that it exchanges traffic with its "server" continuously.
>
> I've not recently attempted to check how much, and don't remember any figures,
> but it wouldn't surprise me if that accounts for some, most, all of the traffic
> you report.
>
> And, maybe Android smartphones do something similar, especially if they are
> setup for VOIP or some similar service.
>
>
AT&T

-- 
Stephen P. Molnar, Ph.D.
Consultant
www.molecular-modeling.net
(614)312-7528 (c)
Skype: smolnar1

[toc] | [prev] | [next] | [standalone]


#199687

Fromrhkramer@gmail.com
Date2018-09-01 20:00 +0200
Message-ID<wtilH-8fd-5@gated-at.bofh.it>
In reply to#199686
On Saturday, September 01, 2018 11:59:27 AM Stephen P. Molnar wrote:
> On 09/01/2018 08:26 AM, rhkramer@gmail.com wrote:
> > On Saturday, September 01, 2018 07:05:55 AM Stephen P. Molnar wrote:
> >> On 08/31/2018 10:41 PM, David Christensen wrote:
> >>> On 08/31/2018 12:50 PM, Stephen P. Molnar wrote:
> >>>> I am running Debian Stretch on my Linux platform.
> >>>> 
> >>>> I have noticed low internet traffic when I have not been doing
> >>>> anything outside of my LAN.  This has made me a tad suspicious.
> >> 
> >> Wired Connections:  2 Desktops,  printer and VOIP telephone
> >> 
> >> Wireless Connections:  Laptop and two Android Smartphones
> > 
> > Out of curiosity, who is your VOIP service provider?
> > 
> > I use ObiHai, and find that it exchanges traffic with its "server"
> > continuously.
> > 
> > I've not recently attempted to check how much, and don't remember any
> > figures, but it wouldn't surprise me if that accounts for some, most,
> > all of the traffic you report.
> > 
> > And, maybe Android smartphones do something similar, especially if they
> > are setup for VOIP or some similar service.
> 
> AT&T

Hmm, Ok, I don't have any experience with AT&T VOIP, but, I still suspect that 
is the source of at least some of the traffic you notice when you are not doing 
anything outside your LAN.

[toc] | [prev] | [next] | [standalone]


#199693

FromDavid Christensen <dpchrist@holgerdanske.com>
Date2018-09-02 07:40 +0200
Message-ID<wtth7-6hl-1@gated-at.bofh.it>
In reply to#199682
On 09/01/2018 04:05 AM, Stephen P. Molnar wrote:
> 
> 
> On 08/31/2018 10:41 PM, David Christensen wrote:
>> On 08/31/2018 12:50 PM, Stephen P. Molnar wrote:
>>> I am running Debian Stretch on my Linux platform.
>>>
>>> I have noticed low internet traffic when I have not been doing 
>>> anything outside of my LAN.  This has made me a tad suspicious.
>>>
>>> Now:
>>>
>>> root@AbNormal:/home/comp# ifconfig
>>> enp2s0: flags=4163<UP,BROADCAST,RUNNING,MULTICAST>  mtu 1500
>>>          inet 162.237.98.238  netmask 255.255.252.0  broadcast 
>>> 162.237.99.255
>>>          ether bc:ee:7b:5e:83:36  txqueuelen 1000  (Ethernet)
>>>          RX packets 796401  bytes 529829454 (505.2 MiB)
>>>          RX errors 0  dropped 0  overruns 0  frame 0
>>>          TX packets 236054  bytes 22520861 (21.4 MiB)
>>>          TX errors 0  dropped 0 overruns 0  carrier 0 collisions 0
>>>
>>> lo: flags=73<UP,LOOPBACK,RUNNING>  mtu 65536
>>>          inet 127.0.0.1  netmask 255.0.0.0
>>>          loop  txqueuelen 1  (Local Loopback)
>>>          RX packets 399  bytes 42360 (41.3 KiB)
>>>          RX errors 0  dropped 0  overruns 0  frame 0
>>>          TX packets 399  bytes 42360 (41.3 KiB)
>>>          TX errors 0  dropped 0 overruns 0  carrier 0 collisions 0
>>>
>>>
>>> It turns out that this ISP, 162.237.98.238 is my ISP, AT&T here in 
>>> Columbus, Ohio.
>>>
>>> The other four nodes on my LAn all have IP's starting with 192.168.1 
>>> - which is what it's supposed to be.
>>>
>>> Just what is going on here? I don't have a clue.
>>>
>>> I dop have firewalls implemented on both the modem and the computers.
>>>
>>> Any insights will be much appreciated.
>>>
>>> Thanks in advance.
>>>
>>
>> Running nslookup(1):
>>
>>     2018-08-31 18:53:21 dpchrist@vstretch ~
>>     $ nslookup 162.237.98.238
>>     Server:        192.168.5.1
>>     Address:    192.168.5.1#53
>>
>>     Non-authoritative answer:
>>     238.98.237.162.in-addr.arpa    name = 
>> 162-237-98-238.lightspeed.clmboh.sbcglobal.net.
>>
>>     Authoritative answers can be found from:
>>
>>
>> Running host(1):
>>
>>     2018-08-31 18:58:15 dpchrist@vstretch ~
>>     $ host 162.237.98.238
>>     238.98.237.162.in-addr.arpa domain name pointer 
>> 162-237-98-238.lightspeed.clmboh.sbcglobal.net.
>>
>>
>> 162.237.98.238 appears to be a valid IPv4 public Internet address.
>>
>>
>> You should have a device provided by your Internet service provider 
>> (ISP) between their wiring (e.g. telephone service) and your wiring 
>> (e.g. Ethernet local area network/LAN).  What is the make and model of 
>> the ISP device?  Please provide a URL to the product support page.
>>
>>
>> What are the "other four nodes"?
>>
>>
>> How is everything interconnected?
>>
>>
>> David
>>
>>
> Thanks for your reply.
> 
> ISO device is an Arris BGE210-700 Broadband Gateway Release 1.0 from 
> AT&T (http://www.arris.com/Search/?q=Arris+BGE210-700+Broadband+Gateway)
> 
> Wired Connections:  2 Desktops,  printer and VOIP telephone
> 
> Wireless Connections:  Laptop and two Android Smartphones
> 
> root@AbNormal:/home/comp# nslookup
>  > nslookup -a
> Server:        192.168.1.254
> Address:    192.168.1.254#53
> 
> Non-authoritative answer:
> Name:    nslookup
> Address: 198.105.244.130
> Name:    nslookup
> Address: 104.239.207.44
>  >
>  > host
> Server:        192.168.1.254
> Address:    192.168.1.254#53
> 
> Non-authoritative answer:
> *** Can't find host: No answer
>  >
> 

It appears that your ISP gateway device is configured to pass through 
it's Internet address (and all incoming packets) to the computer in 
question.  This is a feature that allows a server behind the gateway to 
be visible on the Internet.


Enabling or disabling gateway features is a matter of browsing to the 
gateway's IP address (192.168.1.254?) and operatingthe web control panel.


I have a Pace Plc Model 5268AC, also through AT&T.  The relevant control 
panel page for putting a server on the Internet would seem to be 
Settings -> Firewall -> Applications, Pinholes and DMZ.  I would pick a 
computer and then select "Allow all applications (DMZplus mode)" to turn 
the feature on.  The feature is currently off, so I don't know how I 
would turn it off.


If you can't figure out the control panel for your gateway, contact your 
ISP.


David

[toc] | [prev] | [next] | [standalone]


#199697

From"Stephen P. Molnar" <s.molnar@sbcglobal.net>
Date2018-09-02 14:20 +0200
Message-ID<wtzwd-1tV-1@gated-at.bofh.it>
In reply to#199693

On 09/02/2018 01:37 AM, David Christensen wrote:
> On 09/01/2018 04:05 AM, Stephen P. Molnar wrote:
>>
>>
>> On 08/31/2018 10:41 PM, David Christensen wrote:
>>> On 08/31/2018 12:50 PM, Stephen P. Molnar wrote:
>>>> I am running Debian Stretch on my Linux platform.
>>>>
>>>> I have noticed low internet traffic when I have not been doing 
>>>> anything outside of my LAN.  This has made me a tad suspicious.
>>>>
>>>> Now:
>>>>
>>>> root@AbNormal:/home/comp# ifconfig
>>>> enp2s0: flags=4163<UP,BROADCAST,RUNNING,MULTICAST> mtu 1500
>>>>          inet 162.237.98.238  netmask 255.255.252.0 broadcast 
>>>> 162.237.99.255
>>>>          ether bc:ee:7b:5e:83:36  txqueuelen 1000 (Ethernet)
>>>>          RX packets 796401  bytes 529829454 (505.2 MiB)
>>>>          RX errors 0  dropped 0  overruns 0  frame 0
>>>>          TX packets 236054  bytes 22520861 (21.4 MiB)
>>>>          TX errors 0  dropped 0 overruns 0  carrier 0 collisions 0
>>>>
>>>> lo: flags=73<UP,LOOPBACK,RUNNING>  mtu 65536
>>>>          inet 127.0.0.1  netmask 255.0.0.0
>>>>          loop  txqueuelen 1  (Local Loopback)
>>>>          RX packets 399  bytes 42360 (41.3 KiB)
>>>>          RX errors 0  dropped 0  overruns 0  frame 0
>>>>          TX packets 399  bytes 42360 (41.3 KiB)
>>>>          TX errors 0  dropped 0 overruns 0  carrier 0 collisions 0
>>>>
>>>>
>>>> It turns out that this ISP, 162.237.98.238 is my ISP, AT&T here in 
>>>> Columbus, Ohio.
>>>>
>>>> The other four nodes on my LAn all have IP's starting with 
>>>> 192.168.1 - which is what it's supposed to be.
>>>>
>>>> Just what is going on here? I don't have a clue.
>>>>
>>>> I dop have firewalls implemented on both the modem and the computers.
>>>>
>>>> Any insights will be much appreciated.
>>>>
>>>> Thanks in advance.
>>>>
>>>
>>> Running nslookup(1):
>>>
>>>     2018-08-31 18:53:21 dpchrist@vstretch ~
>>>     $ nslookup 162.237.98.238
>>>     Server:        192.168.5.1
>>>     Address:    192.168.5.1#53
>>>
>>>     Non-authoritative answer:
>>>     238.98.237.162.in-addr.arpa    name = 
>>> 162-237-98-238.lightspeed.clmboh.sbcglobal.net.
>>>
>>>     Authoritative answers can be found from:
>>>
>>>
>>> Running host(1):
>>>
>>>     2018-08-31 18:58:15 dpchrist@vstretch ~
>>>     $ host 162.237.98.238
>>>     238.98.237.162.in-addr.arpa domain name pointer 
>>> 162-237-98-238.lightspeed.clmboh.sbcglobal.net.
>>>
>>>
>>> 162.237.98.238 appears to be a valid IPv4 public Internet address.
>>>
>>>
>>> You should have a device provided by your Internet service provider 
>>> (ISP) between their wiring (e.g. telephone service) and your wiring 
>>> (e.g. Ethernet local area network/LAN).  What is the make and model 
>>> of the ISP device?  Please provide a URL to the product support page.
>>>
>>>
>>> What are the "other four nodes"?
>>>
>>>
>>> How is everything interconnected?
>>>
>>>
>>> David
>>>
>>>
>> Thanks for your reply.
>>
>> ISO device is an Arris BGE210-700 Broadband Gateway Release 1.0 from 
>> AT&T (http://www.arris.com/Search/?q=Arris+BGE210-700+Broadband+Gateway)
>>
>> Wired Connections:  2 Desktops,  printer and VOIP telephone
>>
>> Wireless Connections:  Laptop and two Android Smartphones
>>
>> root@AbNormal:/home/comp# nslookup
>>  > nslookup -a
>> Server:        192.168.1.254
>> Address:    192.168.1.254#53
>>
>> Non-authoritative answer:
>> Name:    nslookup
>> Address: 198.105.244.130
>> Name:    nslookup
>> Address: 104.239.207.44
>>  >
>>  > host
>> Server:        192.168.1.254
>> Address:    192.168.1.254#53
>>
>> Non-authoritative answer:
>> *** Can't find host: No answer
>>  >
>>
>
> It appears that your ISP gateway device is configured to pass through 
> it's Internet address (and all incoming packets) to the computer in 
> question.  This is a feature that allows a server behind the gateway 
> to be visible on the Internet.
>
>
> Enabling or disabling gateway features is a matter of browsing to the 
> gateway's IP address (192.168.1.254?) and operatingthe web control panel.
>
>
> I have a Pace Plc Model 5268AC, also through AT&T.  The relevant 
> control panel page for putting a server on the Internet would seem to 
> be Settings -> Firewall -> Applications, Pinholes and DMZ.  I would 
> pick a computer and then select "Allow all applications (DMZplus 
> mode)" to turn the feature on.  The feature is currently off, so I 
> don't know how I would turn it off.
>
>
> If you can't figure out the control panel for your gateway, contact 
> your ISP.
>
>
> David
>
>
Thanks for your reply.

The Firewall Passthrough is set to Allocation Mode set to 'Passthrough 
with the Passthrough Mode set to 'DHCPS-dynamic '.

It's my intention to change the Allocation Mode to 'Off', as soon as I 
talk to AT&T Tech Support to make sure that doesn't mess things up.

-- 
Stephen P. Molnar, Ph.D.
Consultant
www.molecular-modeling.net
(614)312-7528 (c)
Skype: smolnar1

[toc] | [prev] | [next] | [standalone]


#199698

Frommick crane <mick.crane@gmail.com>
Date2018-09-02 14:50 +0200
Message-ID<wtzZf-1CH-1@gated-at.bofh.it>
In reply to#199697
On 2018-09-02 13:16, Stephen P. Molnar wrote:
<snippped>
> The Firewall Passthrough is set to Allocation Mode set to 'Passthrough
> with the Passthrough Mode set to 'DHCPS-dynamic '.
> 
> It's my intention to change the Allocation Mode to 'Off', as soon as I
> talk to AT&T Tech Support to make sure that doesn't mess things up.

I'm not quite understanding how one PC is going straight through the 
router to the ISP's network whereas you have other PCs with private 
addresses.

In my case as I understand it the ISP's router redirects from its 
external network to internal private.
PC with say 2 NICS one to the router and one to a switch whereby connect 
the local machines using PC with 2 NICS as gateway doing DHCP, firewall 
and all that.

mick




-- 
Key ID    4BFEBB31

[toc] | [prev] | [next] | [standalone]


#199712

FromDavid Christensen <dpchrist@holgerdanske.com>
Date2018-09-02 20:40 +0200
Message-ID<wtFrX-4Rm-3@gated-at.bofh.it>
In reply to#199698
On 09/02/2018 05:48 AM, mick crane wrote:
> On 2018-09-02 13:16, Stephen P. Molnar wrote:
> <snippped>
>> The Firewall Passthrough is set to Allocation Mode set to 'Passthrough
>> with the Passthrough Mode set to 'DHCPS-dynamic '.
>>
>> It's my intention to change the Allocation Mode to 'Off', as soon as I
>> talk to AT&T Tech Support to make sure that doesn't mess things up.
> 
> I'm not quite understanding how one PC is going straight through the 
> router to the ISP's network whereas you have other PCs with private 
> addresses.
> 
> In my case as I understand it the ISP's router redirects from its 
> external network to internal private.
> PC with say 2 NICS one to the router and one to a switch whereby connect 
> the local machines using PC with 2 NICS as gateway doing DHCP, firewall 
> and all that.
> 
> mick


https://en.wikipedia.org/wiki/Firewall_pinhole

https://en.wikipedia.org/wiki/DMZ_(computing)

https://en.wikipedia.org/wiki/DMZ_(computing)#DMZ_host


The OP appears to have the third option enabled on his gateway.


David

[toc] | [prev] | [next] | [standalone]


#199713

Frommick crane <mick.crane@gmail.com>
Date2018-09-03 00:30 +0200
Message-ID<wtJ2x-76K-1@gated-at.bofh.it>
In reply to#199712
On 2018-09-02 19:39, David Christensen wrote:
> On 09/02/2018 05:48 AM, mick crane wrote:
>> On 2018-09-02 13:16, Stephen P. Molnar wrote:
>> <snippped>
>>> The Firewall Passthrough is set to Allocation Mode set to 
>>> 'Passthrough
>>> with the Passthrough Mode set to 'DHCPS-dynamic '.
>>> 
>>> It's my intention to change the Allocation Mode to 'Off', as soon as 
>>> I
>>> talk to AT&T Tech Support to make sure that doesn't mess things up.
>> 
>> I'm not quite understanding how one PC is going straight through the 
>> router to the ISP's network whereas you have other PCs with private 
>> addresses.
>> 
>> In my case as I understand it the ISP's router redirects from its 
>> external network to internal private.
>> PC with say 2 NICS one to the router and one to a switch whereby 
>> connect the local machines using PC with 2 NICS as gateway doing DHCP, 
>> firewall and all that.
>> 
>> mick
> 
> 
> https://en.wikipedia.org/wiki/Firewall_pinhole
> 
> https://en.wikipedia.org/wiki/DMZ_(computing)
> 
> https://en.wikipedia.org/wiki/DMZ_(computing)#DMZ_host
> 
> 
> The OP appears to have the third option enabled on his gateway.

the ISP router maybe has NAT ( that's what it's called isn't it ) on 
some of the ports that things with the private 192.168 block connect to 
but seems to have a DMZ on one of the ports.
I dunno

mick


-- 
Key ID    4BFEBB31

[toc] | [prev] | [next] | [standalone]


#199715

FromDavid Christensen <dpchrist@holgerdanske.com>
Date2018-09-03 05:20 +0200
Message-ID<wtNzb-1nI-1@gated-at.bofh.it>
In reply to#199713
On 09/02/2018 03:22 PM, mick crane wrote:
> On 2018-09-02 19:39, David Christensen wrote:
>> On 09/02/2018 05:48 AM, mick crane wrote:
>>> On 2018-09-02 13:16, Stephen P. Molnar wrote:
>>> <snippped>
>>>> The Firewall Passthrough is set to Allocation Mode set to 'Passthrough
>>>> with the Passthrough Mode set to 'DHCPS-dynamic '.
>>>>
>>>> It's my intention to change the Allocation Mode to 'Off', as soon as I
>>>> talk to AT&T Tech Support to make sure that doesn't mess things up.
>>>
>>> I'm not quite understanding how one PC is going straight through the 
>>> router to the ISP's network whereas you have other PCs with private 
>>> addresses.
>>>
>>> In my case as I understand it the ISP's router redirects from its 
>>> external network to internal private.
>>> PC with say 2 NICS one to the router and one to a switch whereby 
>>> connect the local machines using PC with 2 NICS as gateway doing 
>>> DHCP, firewall and all that.
>>>
>>> mick
>>
>>
>> https://en.wikipedia.org/wiki/Firewall_pinhole
>>
>> https://en.wikipedia.org/wiki/DMZ_(computing)
>>
>> https://en.wikipedia.org/wiki/DMZ_(computing)#DMZ_host
>>
>>
>> The OP appears to have the third option enabled on his gateway.
> 
> the ISP router maybe has NAT ( that's what it's called isn't it ) on 
> some of the ports that things with the private 192.168 block connect to 
> but seems to have a DMZ on one of the ports.
> I dunno
> 
> mick

https://en.wikipedia.org/wiki/Dynamic_Host_Configuration_Protocol

https://en.wikipedia.org/wiki/Network_address_translation


Internet gateways typically provide DHCP and NAT/IP masquerading to 
hosts on a private network (e.g. 192.168.1.0/24).  DMZ hosts are treated 
specially.


David

[toc] | [prev] | [next] | [standalone]


#199678

Frommick crane <mick.crane@gmail.com>
Date2018-09-01 10:10 +0200
Message-ID<wt98J-36i-7@gated-at.bofh.it>
In reply to#199662
On 2018-08-31 20:50, Stephen P. Molnar wrote:
> I am running Debian Stretch on my Linux platform.
> 
> I have noticed low internet traffic when I have not been doing
> anything outside of my LAN.  This has made me a tad suspicious.
> 
> Now:
> 
> root@AbNormal:/home/comp# ifconfig
> enp2s0: flags=4163<UP,BROADCAST,RUNNING,MULTICAST>  mtu 1500
>         inet 162.237.98.238  netmask 255.255.252.0  broadcast 
> 162.237.99.255
>         ether bc:ee:7b:5e:83:36  txqueuelen 1000  (Ethernet)
>         RX packets 796401  bytes 529829454 (505.2 MiB)
>         RX errors 0  dropped 0  overruns 0  frame 0
>         TX packets 236054  bytes 22520861 (21.4 MiB)
>         TX errors 0  dropped 0 overruns 0  carrier 0  collisions 0
> 
> lo: flags=73<UP,LOOPBACK,RUNNING>  mtu 65536
>         inet 127.0.0.1  netmask 255.0.0.0
>         loop  txqueuelen 1  (Local Loopback)
>         RX packets 399  bytes 42360 (41.3 KiB)
>         RX errors 0  dropped 0  overruns 0  frame 0
>         TX packets 399  bytes 42360 (41.3 KiB)
>         TX errors 0  dropped 0 overruns 0  carrier 0  collisions 0
> 
> 
> It turns out that this ISP, 162.237.98.238 is my ISP, AT&T here in
> Columbus, Ohio.
> 
> The other four nodes on my LAn all have IP's starting with 192.168.1 -
> which is what it's supposed to be.
> 
> Just what is going on here? I don't have a clue.
> 
> I dop have firewalls implemented on both the modem and the computers.
> 
> Any insights will be much appreciated.
> 
> Thanks in advance.

well ifconfig should report the internal private address of its NIC but 
seems to be showing the external address range of the router. Could this 
be anything to do with the router being in bridge mode which is 
something I'm not entirely clear about.

mick


-- 
Key ID    4BFEBB31

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web