News: This forum is now permanently frozen.
Pages: [1]
Topic: problem with simultaneously pinging wan adresses from local clients  (Read 3029 times)
« on: February 24, 2008, 10:23:27 »
Oneofthe8devilz *
Posts: 3

I have the classcial setup:

A generic PC running monowall at local ip adress 192.168.0.1

And 3 Clients runing XP connected to it with ip adresses: 192.168.0.2, 192.168.0.3 and 192.168.0.4

As long as I ping an address (ie www.qsc.de) just from one Client all works fine and I get a ping reply.

But as soon as I try to ping the same address from another Client (while the pinging on the first Client still runs) I get a "Request timed out" on the second Client. When I stop the pinging on the first Client then immediatelly I start to get a ping reply on the second Client.....

I would like to be able to ping any wan ip address on any Client at any time....

So advise would be greatly apreciated...

Thanks in advance 

« Reply #1 on: March 03, 2008, 02:56:05 »
cmb *****
Posts: 851

That's a limitation of the NAT software m0n0wall uses. That might not be the case with 1.3, if you really need to do that, try it.
« Reply #2 on: March 03, 2008, 08:08:32 »
ChainSaw
Guest

Tested this with two 1.3b10 over the Internet and the remote m0n0wall pings fine from one PC but pinging the same public IP from a second PC shows random timeouts on both PCs.  Kill the second PC and no timeout on the first PC.

CS...
« Last Edit: March 03, 2008, 08:10:07 by ChainSaw »
« Reply #3 on: March 27, 2008, 21:22:40 »
SlickNetAaron *
Posts: 44

Wow, that's a big flaw, isn't it?
« Reply #4 on: April 14, 2008, 15:15:19 »
dirkb *
Posts: 15

Is this officialy seen as being a bug and will this be "fixed"?

Did anyone test this with the latest build? (1.3b10 or 1.3b11)
« Reply #5 on: May 01, 2008, 20:24:58 »
dirkb *
Posts: 15

Is this officialy seen as being a bug and will this be "fixed"?

Did anyone test this with the latest build? (1.3b10 or 1.3b11)
Nobody?
« Reply #6 on: May 01, 2008, 21:10:47 »
Manuel Kasper
Administrator
*****
Posts: 364

This is not considered a bug. Unlike TCP and UDP, ICMP doesn't have port numbers that could be used to distinguish between concurrent ICMP "sessions". Some firewalls use the ICMP ID to do that, but ipnat (from ipfilter, the packet filter used in m0n0wall) doesn't. I don't think it's a big deal, as it works properly for TCP and UDP.

If you really want it fixed, get someone to implement ICMP ID based NAT in ipfilter/ipnat. Which will probably mean that you'll have to do it yourself. Wink
« Reply #7 on: May 01, 2008, 21:16:19 »
dirkb *
Posts: 15

I can understand your point-of-view.
I'm afraid that my knowledge is not good enough to "fix" this myself :-(

 
Pages: [1]
 
 
Powered by SMF 1.1.20 | SMF © 2013, Simple Machines