RE: IPENCAP issue

2004-01-09 Thread tomt
I want to thank everyone for their replies to this.  When I first composed
this I was trying to get a handle on how to describe the problem let
alone fix it.  I apologize for not including more details.

Here is the layout
Wireless cloud network
192.168.0.0/27
192.168.0.1-192.168.0.30(usable addresses)

Building A network
10.114.252.0/22
10.114.252.1-10.114.255.254(usable addresses)

Building B network
10.114.96.0/24
10.114.96.1-10.114.111.254(usable addresses)


Client computer
I have been testing from this machine to the Internet via Mozilla Firebird
1.71
Running Mac OS X 10.3.2(also tried a Windows 2000 machine here)
IP: 10.114.96.253
DG: 10.114.96.1

Building B FreeBSD 5.1 router
LAN IP: 10.114.96.1
DG: 10.114.252.1
External IP: 192.168.0.6/27

Building A FreeBSD 5.1 router
External IP: 192.168.0.3/27
DG: 10.114.255.254
LAN IP: 10.114.252.1

Internet router(Cisco 2501)
IP: 10.114.255.254
DG: ISP provided

Here is my test, I configured the Mac OS X machine to connect to
the Building B FreeBSD router and access www.sears.com
The machine connects to the site and in the browser displays
the HTML title to the site but hangs forever waiting to connect
to the site.

Note: All these sites work from a machine connected to Building A
on the 10.114.252.0/22 network and going out the 10.114.255.254
gateway.

I have tried other sides and the sites that appear to work are ones
that contain a single A record for their webserver like freebsd.org,
ebay.com, cisco.com.  When a site has more that 1 A record I get
the same behavior as described above examples: sears.com,
drudgereport.com, microsoft.com and msnbc.com

Here are tcpdumps from 3 places within this test network, I do have
the raw files if anyone wants them email me offlist

Tcpdump from Building A
Description: This tcpdump was done on the FreeBSD router located
at 10.114.252.1/192.168.0.3

Frame 1 (62 bytes on wire, 62 bytes captured)
Ethernet II, Src: 00:04:75:e8:8b:51, Dst: 00:30:94:e5:bb:23
Internet Protocol, Src Addr: 10.114.96.253 (10.114.96.253), Dst Addr:
129.33.131.219 (129.33.131.219)
Transmission Control Protocol, Src Port: 1156 (1156), Dst Port: http (80),
Seq: 0, Ack: 0, Len: 0

Frame 2 (62 bytes on wire, 62 bytes captured)
Ethernet II, Src: 00:30:94:e5:bb:23, Dst: 00:04:75:e8:8b:51
Internet Protocol, Src Addr: 129.33.131.219 (129.33.131.219), Dst Addr:
10.114.96.253 (10.114.96.253)
Transmission Control Protocol, Src Port: http (80), Dst Port: 1156 (1156),
Seq: 0, Ack: 1, Len: 0

Frame 3 (54 bytes on wire, 54 bytes captured)
Ethernet II, Src: 00:04:75:e8:8b:51, Dst: 00:30:94:e5:bb:23
Internet Protocol, Src Addr: 10.114.96.253 (10.114.96.253), Dst Addr:
129.33.131.219 (129.33.131.219)
Transmission Control Protocol, Src Port: 1156 (1156), Dst Port: http (80),
Seq: 1, Ack: 1, Len: 0

Frame 4 (798 bytes on wire, 96 bytes captured)
Ethernet II, Src: 00:04:75:e8:8b:51, Dst: 00:30:94:e5:bb:23
Internet Protocol, Src Addr: 10.114.96.253 (10.114.96.253), Dst Addr:
129.33.131.219 (129.33.131.219)
Transmission Control Protocol, Src Port: 1156 (1156), Dst Port: http (80),
Seq: 1, Ack: 1, Len: 744
Hypertext Transfer Protocol

Frame 5 (60 bytes on wire, 60 bytes captured)
Ethernet II, Src: 00:30:94:e5:bb:23, Dst: 00:04:75:e8:8b:51
Internet Protocol, Src Addr: 129.33.131.219 (129.33.131.219), Dst Addr:
10.114.96.253 (10.114.96.253)
Transmission Control Protocol, Src Port: http (80), Dst Port: 1156 (1156),
Seq: 1, Ack: 745, Len: 0

Frame 6 (646 bytes on wire, 96 bytes captured)
Ethernet II, Src: 00:30:94:e5:bb:23, Dst: 00:04:75:e8:8b:51
Internet Protocol, Src Addr: 129.33.131.219 (129.33.131.219), Dst Addr:
10.114.96.253 (10.114.96.253)
Transmission Control Protocol, Src Port: http (80), Dst Port: 1156 (1156),
Seq: 1, Ack: 745, Len: 592
Hypertext Transfer Protocol

Frame 7 (255 bytes on wire, 96 bytes captured)
Ethernet II, Src: 00:30:94:e5:bb:23, Dst: 00:04:75:e8:8b:51
Internet Protocol, Src Addr: 129.33.131.219 (129.33.131.219), Dst Addr:
10.114.96.253 (10.114.96.253)
Transmission Control Protocol, Src Port: http (80), Dst Port: 1156 (1156),
Seq: 593, Ack: 745, Len: 201
Hypertext Transfer Protocol

Frame 8 (60 bytes on wire, 60 bytes captured)
Ethernet II, Src: 00:30:94:e5:bb:23, Dst: 00:04:75:e8:8b:51
Internet Protocol, Src Addr: 129.33.131.219 (129.33.131.219), Dst Addr:
10.114.96.253 (10.114.96.253)
Transmission Control Protocol, Src Port: http (80), Dst Port: 1156 (1156),
Seq: 794, Ack: 745, Len: 0

Frame 9 (54 bytes on wire, 54 bytes captured)
Ethernet II, Src: 00:04:75:e8:8b:51, Dst: 00:30:94:e5:bb:23
Internet Protocol, Src Addr: 10.114.96.253 (10.114.96.253), Dst Addr:
129.33.131.219 (129.33.131.219)
Transmission Control Protocol, Src Port: 1156 (1156), Dst Port: http (80),
Seq: 745, Ack: 794, Len: 0

Frame 10 (54 bytes on wire, 54 bytes captured)
Ethernet II, Src: 00:04:75:e8:8b:51, Dst: 00:30:94:e5:bb:23
Internet Protocol, Src Addr: 10.114.96.253 (10.114.96.253), Dst Addr:
129.33.131.219 (129.33.131.219)
Transmission 

RE: IPENCAP issue

2004-01-09 Thread tomt
I want to thank everyone for their replies to this.  When I first composed
this I was trying to get a handle on how to describe the problem let
alone fix it.  I apologize for not including more details.

Here is the layout
Wireless cloud network
192.168.0.0/27
192.168.0.1-192.168.0.30(usable addresses)

Building A network
10.114.252.0/22
10.114.252.1-10.114.255.254(usable addresses)

Building B network
10.114.96.0/24
10.114.96.1-10.114.111.254(usable addresses)


Client computer
I have been testing from this machine to the Internet via Mozilla Firebird
1.71
Running Mac OS X 10.3.2(also tried a Windows 2000 machine here)
IP: 10.114.96.253
DG: 10.114.96.1

Building B FreeBSD 5.1 router
LAN IP: 10.114.96.1
DG: 10.114.252.1
External IP: 192.168.0.6/27

Building A FreeBSD 5.1 router
External IP: 192.168.0.3/27
DG: 10.114.255.254
LAN IP: 10.114.252.1

Internet router(Cisco 2501)
IP: 10.114.255.254
DG: ISP provided

Here is my test, I configured the Mac OS X machine to connect to
the Building B FreeBSD router and access www.sears.com
The machine connects to the site and in the browser displays
the HTML title to the site but hangs forever waiting to connect
to the site.

Note: All these sites work from a machine connected to Building A
on the 10.114.252.0/22 network and going out the 10.114.255.254
gateway.

I have tried other sides and the sites that appear to work are ones
that contain a single A record for their webserver like freebsd.org,
ebay.com, cisco.com.  When a site has more that 1 A record I get
the same behavior as described above examples: sears.com,
drudgereport.com, microsoft.com and msnbc.com

Here are tcpdumps from 3 places within this test network, I do have
the raw files if anyone wants them email me offlist

Tcpdump from Building A
Description: This tcpdump was done on the FreeBSD router located
at 10.114.252.1/192.168.0.3

Frame 1 (62 bytes on wire, 62 bytes captured)
Ethernet II, Src: 00:04:75:e8:8b:51, Dst: 00:30:94:e5:bb:23
Internet Protocol, Src Addr: 10.114.96.253 (10.114.96.253), Dst Addr:
129.33.131.219 (129.33.131.219)
Transmission Control Protocol, Src Port: 1156 (1156), Dst Port: http (80),
Seq: 0, Ack: 0, Len: 0

Frame 2 (62 bytes on wire, 62 bytes captured)
Ethernet II, Src: 00:30:94:e5:bb:23, Dst: 00:04:75:e8:8b:51
Internet Protocol, Src Addr: 129.33.131.219 (129.33.131.219), Dst Addr:
10.114.96.253 (10.114.96.253)
Transmission Control Protocol, Src Port: http (80), Dst Port: 1156 (1156),
Seq: 0, Ack: 1, Len: 0

Frame 3 (54 bytes on wire, 54 bytes captured)
Ethernet II, Src: 00:04:75:e8:8b:51, Dst: 00:30:94:e5:bb:23
Internet Protocol, Src Addr: 10.114.96.253 (10.114.96.253), Dst Addr:
129.33.131.219 (129.33.131.219)
Transmission Control Protocol, Src Port: 1156 (1156), Dst Port: http (80),
Seq: 1, Ack: 1, Len: 0

Frame 4 (798 bytes on wire, 96 bytes captured)
Ethernet II, Src: 00:04:75:e8:8b:51, Dst: 00:30:94:e5:bb:23
Internet Protocol, Src Addr: 10.114.96.253 (10.114.96.253), Dst Addr:
129.33.131.219 (129.33.131.219)
Transmission Control Protocol, Src Port: 1156 (1156), Dst Port: http (80),
Seq: 1, Ack: 1, Len: 744
Hypertext Transfer Protocol

Frame 5 (60 bytes on wire, 60 bytes captured)
Ethernet II, Src: 00:30:94:e5:bb:23, Dst: 00:04:75:e8:8b:51
Internet Protocol, Src Addr: 129.33.131.219 (129.33.131.219), Dst Addr:
10.114.96.253 (10.114.96.253)
Transmission Control Protocol, Src Port: http (80), Dst Port: 1156 (1156),
Seq: 1, Ack: 745, Len: 0

Frame 6 (646 bytes on wire, 96 bytes captured)
Ethernet II, Src: 00:30:94:e5:bb:23, Dst: 00:04:75:e8:8b:51
Internet Protocol, Src Addr: 129.33.131.219 (129.33.131.219), Dst Addr:
10.114.96.253 (10.114.96.253)
Transmission Control Protocol, Src Port: http (80), Dst Port: 1156 (1156),
Seq: 1, Ack: 745, Len: 592
Hypertext Transfer Protocol

Frame 7 (255 bytes on wire, 96 bytes captured)
Ethernet II, Src: 00:30:94:e5:bb:23, Dst: 00:04:75:e8:8b:51
Internet Protocol, Src Addr: 129.33.131.219 (129.33.131.219), Dst Addr:
10.114.96.253 (10.114.96.253)
Transmission Control Protocol, Src Port: http (80), Dst Port: 1156 (1156),
Seq: 593, Ack: 745, Len: 201
Hypertext Transfer Protocol

Frame 8 (60 bytes on wire, 60 bytes captured)
Ethernet II, Src: 00:30:94:e5:bb:23, Dst: 00:04:75:e8:8b:51
Internet Protocol, Src Addr: 129.33.131.219 (129.33.131.219), Dst Addr:
10.114.96.253 (10.114.96.253)
Transmission Control Protocol, Src Port: http (80), Dst Port: 1156 (1156),
Seq: 794, Ack: 745, Len: 0

Frame 9 (54 bytes on wire, 54 bytes captured)
Ethernet II, Src: 00:04:75:e8:8b:51, Dst: 00:30:94:e5:bb:23
Internet Protocol, Src Addr: 10.114.96.253 (10.114.96.253), Dst Addr:
129.33.131.219 (129.33.131.219)
Transmission Control Protocol, Src Port: 1156 (1156), Dst Port: http (80),
Seq: 745, Ack: 794, Len: 0

Frame 10 (54 bytes on wire, 54 bytes captured)
Ethernet II, Src: 00:04:75:e8:8b:51, Dst: 00:30:94:e5:bb:23
Internet Protocol, Src Addr: 10.114.96.253 (10.114.96.253), Dst Addr:
129.33.131.219 (129.33.131.219)
Transmission