Does v3.2.1 have the `traceroute` bug?  It's a requirement that I can 
traceroute to another system through the GnatBOX and get reliable timings.

Second, the log is showing that outbound filter 35 is blocking the attempt 
and filter 35 is the deny all nearly at the end of the list.  If there was 
a filter between 1-14 then that would show as blocking the attempt and I 
would have never posted my query.

I have since very carefully checked filter 1 to 14 inclusive as if I would 
single step a program I'm writing and can confirm that none of those 
filters are blocking the outbound connection.  Again, if that was truly the 
case then the number in the bracket after `OBF` would be 14 or less.

(There is actually a reason, of which I can not divulge, why I can not just 
list every filter from the GnatBOX configuration, but I've played with this 
GB-1000 beast now long enough to understand the why's and what-for without 
having to give a second glance.)

I think what I may do is reboot the GnatBOX, which I have done by remote 
several weeks ago at the advice of GTA technical, but I'm not that trusting 
and would like to be present by the box when I reboot it.  Just in case a 
reboot don't work and I need to fiddle with it to get it working.

What I have done is written back the entire GnatBOX configuration to the 
box.  Maybe that'll do the trick.

One problem with the version I'm using is that on the odd and rare 
occasion, it can start transmitting to the Internet using the wrong public 
source IP address.  That's what the reboot was about.

Do, does anyone know if this `trace route` and `ping` problem is fixed?



At 19/11/2001 09:31 pm , <[EMAIL PROTECTED]> wrote:
>I would have to say that you're not going to get
>a useful answer unless you show us what filters
>1-14 look like.  If there are any "Deny" filters
>ahead of filter 15, then I'd take a close look
>at them.
>
>Also, 3.2.1 is a free upgrade from the version
>that you have.
>
>Mike Burden
>Lynk Systems
>http://www.lynk.com
>(616)532-4985
>[EMAIL PROTECTED]
>
>
>
> > -----Original Message-----
> > From: Myron Szymanskyj [mailto:[EMAIL PROTECTED]]
> > Sent: Sunday, November 19, 2000 3:01 PM
> > To: [EMAIL PROTECTED]
> > Subject: Have I found an annoying bug on the GnatBOX?
> >
> >
> > Can someone please advise on the below.
> >
> > GNAT Box GB-1000 Version: 3.2.0s
> >
> > Incorrectly denied outbound connections:
> >    16:06:19 FILTER: OBF (35) block - UDP
> > [172.16.200.15126]->[132.163.4.101/123] fxp0 l=48
> >    Nov 17 16:06:14 FILTER: OBF (35) block - UDP
> > [172.16.200.1/5126]->[132.163.4.101/123] fxp0 l=48
> >    Nov 17 16:06:09 FILTER: OBF (35) block - UDP
> > [172.16.200.1/5126]->[132.163.4.101/123] fxp0 l=48
> >
> > Objects:
> >      21     Time servers - Location of Internet time servers
> >                Index  Type   Beginning        Ending
> >                -----  -----  ---------------  ---------------
> >                1      object  UMIST
> >                2      host   192.5.41.209
> >                3      host   192.5.41.41
> >                4      host   194.72.17.13
> >                5      range  132.163.4.101    132.163.4.106
> >      23     UMIST - University of Manchester/UMIST local area network
> >                Index  Type   Beginning        Ending
> >                -----  -----  ---------------  ---------------
> >                1      range  130.88.0.0       130.88.255.255
> >
> > Outbound filters:
> >      15 #Allow access to time servers. (UDP)
> >         Accept ANY UDP  log
> >            from "ANY_IP"
> >              to "Time servers" 13 37 123
> >
> >      16 #Allow access to time servers. (TCP)
> >         Accept ANY TCP  log
> >            from "ANY_IP"
> >              to "Time servers" 13 37
> >
> >
> > I'm wondering if GTA is delaying the release of the fixes until the
> > majority of the maintenance contracts are due for renewal, or
> > wait long enough for this event to occur.


Reply via email to