Old 07-12-2009, 05:32 PM   #41 (permalink)
Master Untangler
 
neiby's Avatar
 
Join Date: Jun 2009
Location: Denver, CO
Posts: 603
neiby is on a distinguished road
Default

It's possible that there's a negotiation issue, but we're not seeing any signs of general IP traffic loss. Pings don't seem to have any problem. I think your other suggestions are probably closer to the truth. We'll know tomorrow morning. I'll do some more testing as soon as I get to work.
__________________
Disclaimer: I may or may not have had enough coffee when I'm posting. Interpret my responses thusly.
neiby is offline  
Old 07-13-2009, 10:51 AM   #42 (permalink)
Master Untangler
 
neiby's Avatar
 
Join Date: Jun 2009
Location: Denver, CO
Posts: 603
neiby is on a distinguished road
Default

Okay, we moved UT over to an unused interface on the ASA and connected a laptop behind it. It works perfectly. So, now we're stumped. We can't figure out why it behaves differently when connected to our main "inside" interface. We've applied the same policies to it. We did not apply any ACLs to it, but those shouldn't matter.

We're going to do some more testing after lunch to see if we can figure it out.
__________________
Disclaimer: I may or may not have had enough coffee when I'm posting. Interpret my responses thusly.
neiby is offline  
Old 07-13-2009, 11:23 AM   #43 (permalink)
Untangle Ninja
 
sky-knight's Avatar
 
Join Date: Apr 2008
Location: Phoenix, AZ
URLs submitted: 8
Posts: 15,457
sky-knight is on a distinguished road
Default

Try this...

Get a small unmanaged switch and put it between the ASA and the main network. Then dangle the UT off that switch with the laptop off it.

Then you're on the same interface, in deployment position. If it works there... I'd finally be stumped.
__________________
Rob Sandling, BS:SWE, MCP
Intouch Technology
Phone: 480-272-9889
rob@intouchtechllc.com

UntangleAppliances.com
Phone: 866-794-8879
sky-knight is offline  
Old 07-13-2009, 11:59 AM   #44 (permalink)
Master Untangler
 
neiby's Avatar
 
Join Date: Jun 2009
Location: Denver, CO
Posts: 603
neiby is on a distinguished road
Default

We have a theory about this. We think the problem is that threat detection is enabled on the ASA. Threat detection is based on the rate of particular types of events. We think UT is working now because there is only one laptop behind it. With UT inline with our main link, it has hundreds of devices behind it. I think that dramatically increases the rate of whatever is happening, which causes threat detection to kick in and start blocking stuff.

We can test this pretty easily. We can put UT back in production and then turn off threat detection. I'll let you know how it goes!
__________________
Disclaimer: I may or may not have had enough coffee when I'm posting. Interpret my responses thusly.
neiby is offline  
Old 07-13-2009, 12:20 PM   #45 (permalink)
Master Untangler
 
neiby's Avatar
 
Join Date: Jun 2009
Location: Denver, CO
Posts: 603
neiby is on a distinguished road
Default

So, our theory was wrong. We turned off threat detection and moved UT back inline with our main connection. As before, pings work fine but all DNS was being blocked. We didn't have time to setup the packet captures. Or, I should say that we didn't configure them beforehand. We did capture the firewall logs, though, so maybe we'll figure this out from there.
__________________
Disclaimer: I may or may not have had enough coffee when I'm posting. Interpret my responses thusly.
neiby is offline  
Old 07-13-2009, 12:23 PM   #46 (permalink)
Untangle Ninja
 
sky-knight's Avatar
 
Join Date: Apr 2008
Location: Phoenix, AZ
URLs submitted: 8
Posts: 15,457
sky-knight is on a distinguished road
Default

Have you by chance tried to bypass outgoing UDP destination port 53?

There have been cases in the past where this was required... but for the life of me I can't figure out why.
__________________
Rob Sandling, BS:SWE, MCP
Intouch Technology
Phone: 480-272-9889
rob@intouchtechllc.com

UntangleAppliances.com
Phone: 866-794-8879
sky-knight is offline  
Old 07-13-2009, 12:32 PM   #47 (permalink)
Master Untangler
 
neiby's Avatar
 
Join Date: Jun 2009
Location: Denver, CO
Posts: 603
neiby is on a distinguished road
Default

I'm looking through the firewall logs and it looks like DNS requests are being sent out, so something must be breaking on the return trip. I have no idea what, though.
__________________
Disclaimer: I may or may not have had enough coffee when I'm posting. Interpret my responses thusly.
neiby is offline  
Old 07-13-2009, 12:46 PM   #48 (permalink)
Untangle Ninja
 
sky-knight's Avatar
 
Join Date: Apr 2008
Location: Phoenix, AZ
URLs submitted: 8
Posts: 15,457
sky-knight is on a distinguished road
Default

How do you handle DNS for that network segment?
__________________
Rob Sandling, BS:SWE, MCP
Intouch Technology
Phone: 480-272-9889
rob@intouchtechllc.com

UntangleAppliances.com
Phone: 866-794-8879
sky-knight is offline  
Old 07-13-2009, 12:48 PM   #49 (permalink)
Master Untangler
 
neiby's Avatar
 
Join Date: Jun 2009
Location: Denver, CO
Posts: 603
neiby is on a distinguished road
Default

Quote:
Originally Posted by sky-knight View Post
Have you by chance tried to bypass outgoing UDP destination port 53?

There have been cases in the past where this was required... but for the life of me I can't figure out why.
Okay, I just tried this. I used Policy Manager to send all port 53 traffic to "No Rack". Is that right?

It didn't work, though. Same result: no DNS. Grrr.....
__________________
Disclaimer: I may or may not have had enough coffee when I'm posting. Interpret my responses thusly.
neiby is offline  
Old 07-13-2009, 12:50 PM   #50 (permalink)
Master Untangler
 
neiby's Avatar
 
Join Date: Jun 2009
Location: Denver, CO
Posts: 603
neiby is on a distinguished road
Default

Quote:
Originally Posted by sky-knight View Post
How do you handle DNS for that network segment?
We use Active Directory. Clients send queries to our local servers, which in turn query Internet servers. We tried setting the server to 4.2.2.1 for PCs and on UT itself. No change. They can ping it, but name resolution fails.
__________________
Disclaimer: I may or may not have had enough coffee when I'm posting. Interpret my responses thusly.
neiby is offline  
Closed Thread

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 07:45 AM.


© 2010 Untangle, Inc. All Rights Reserved.   SEO by vBSEO 3.6.0 PL2