[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cobalt-users] Strange HTTP Problem



INRE RE: [cobalt-users] Strange HTTP Problem:
> I obtained a dial-up connection a while back from the ISP, and it seems
> that all HTTP sites on our RaQ3 server time out through this connection.
> The server has no active HTTPS sites running on it, although there is an
> SSL enabled site, that's not used at the moment, so I don't think that's
> the problem. Unfortunately, I no longer have this ISP's dial-up connection
> available to me.
>
> All sites on the RaQ3 time out through the Enterprise.net connection, not
> just one or two.
>

Simon,

  Saw a similar problem here not too long back when working on a problem with 
a customer.  They could "surf" etc, do anything, but three (3) particular 
sites would not load on their browser. (Internal network of about 10 machines 
and none worked for these sites)....

  After much testing and getting with the remote Admin, we found that one of 
the routers in the link was putting the DF (don't fragment) bit set to "on" 
in all the tcp packets from this site(s).  The header information and such 
was making it through, but the "body" of the http request was not.  
Contributing factor was that the site was also blocking "icmp" so they never 
saw the packets from our client saying "packet is too big and you said don't 
fragment, send me smaller packets" (paraphrasing mine)......

  In this case we could not convince the remote site that the "problem" was 
theirs - so we ended up modifying the router at our customers and simply 
removing the DF bit on all packets from "that" network (since we know them to 
be bogus).......

  Might be "way" off base, but sure sounds "similar".

Larry Smith
SysAd ECSIS.NET
sysad@xxxxxxxxx