+15
Under review
I cannot connect to the tellmon.net site from many different networks. Tracert to the Tellmon server is always following the same path but most of the times the server does not seen to repond and it finally displays "This page can’t be displayed".
I cannot connect to the tellmon.net site from many different LANs. After waiting a while the bowser (any browser) displays "This page can’t be displayed". A tracert to the tellmon.net site displays the same path no matter if it is working or not, so DNS is not a problem.) Firewall seems not likely either
Any ideas?
Any ideas?
Customer support service by UserEcho
I'm using UptimeRobot to monitor uptime from two different physical locations. Tellmon.net is responding from both of these.
Tracing route to tellmon.net [79.161.150.134] over a maximum of 30 hops:
1 1 ms <1 ms 1 ms router.asus.com [192.168.1.1]
2 28 ms 28 ms 29 ms c01A0BF51.dhcp.as2116.net [81.191.160.1]
3 28 ms 37 ms 160 ms te1-0-2.cr2.nord41.as2116.net [195.0.242.153]
4 28 ms 28 ms 28 ms ae1.cr2.bo.as2116.net [193.75.3.43]
5 39 ms 36 ms 37 ms ae2.cr1.prinsg39.as2116.net [193.75.3.40]
6 52 ms 45 ms 44 ms ae2.cr1.san110.as2116.net [195.0.240.90]
7 44 ms 44 ms 44 ms te3-0-0.br1.osls.as2116.net [193.75.2.154]
8 45 ms 45 ms 46 ms 193.156.120.66
9 45 ms 44 ms 44 ms 237.79-160-112.customer.lyse.net [79.160.112.237]
10 45 ms 46 ms 46 ms 2.79-160-49.customer.lyse.net [79.160.49.2]
11 48 ms * 47 ms 65.79-160-49.customer.lyse.net [79.160.49.65]
12 48 ms 47 ms 47 ms 203.79-160-49.customer.lyse.net [79.160.49.203]
13 * * * Request timed out.
14 * * * Request timed out.
30 * * * Request timed out.
Trace complete.
Det ender ikke på den adressen du oppga. 79.161.150.134.
Fra jobben er tracert det samme:
Tracing route to www.tellmon.net [79.161.150.134] over a maximum of 30 hops:
1 * * * Request timed out.
2 <1 ms <1 ms <1 ms 158.39.96.1
3 5 ms 3 ms 3 ms npolar-gw.npolar.no [158.39.97.65]
4 3 ms 3 ms 5 ms vethstromso-gw.uninett.no [128.39.230.189]
5 3 ms <1 ms 1 ms tromso-gw4.uninett.no [128.39.230.205]
6 2 ms 1 ms 1 ms tromso-gw2.uninett.no [128.39.255.157]
7 15 ms 15 ms 17 ms trd-gw.uninett.no [128.39.254.101]
8 22 ms 22 ms 22 ms oslo-gw1.uninett.no [128.39.255.45]
9 24 ms 30 ms 33 ms 193.156.90.66
10 23 ms 23 ms 23 ms 237.79-160-112.customer.lyse.net [79.160.112.237]
11 24 ms 24 ms 28 ms 2.79-160-49.customer.lyse.net [79.160.49.2]
12 26 ms 26 ms 26 ms 65.79-160-49.customer.lyse.net [79.160.49.65]
13 26 ms 26 ms 26 ms 203.79-160-49.customer.lyse.net [79.160.49.203]
14 * * * Request timed out.
15 * * * Request timed out.
30 * * * Request timed out.
Trace complete.
Regner med at sideforespørselen kommer til serveren også her men at noe gjør at den ikke svarer?
Do you not get any respose when trying to access tellmon in your browser?
I now reach tellmon.net using tracert from both locations and can also ping the server from both places. But the website does only respond when I try from 81.191.167.157. From 158.39.96.23 I get no response
Attaching tracert log made when I can not connect.
Tracing route to www.tellmon.net [79.161.150.134]
over a maximum of 30 hops:
1 <1 ms <1 ms <1 ms 192.168.254.90
2 <1 ms <1 ms <1 ms dr-se-sto-kn5-2-vl452.bredband2.net [217.115.41.217]
3 1 ms 1 ms 1 ms cr-se-kista-esbogatan11-1-be2.bredband2.net [82.209.176.141]
4 41 ms 1 ms <1 ms ae3.stk10.ip4.gtt.net [77.67.82.1]
5 1 ms <1 ms <1 ms xe-2-3-0.stk30.ip4.gtt.net [89.149.183.250]
6 5 ms <1 ms <1 ms as3549.ip4.gtt.net [77.67.82.146]
7 1 ms 1 ms 1 ms ae10.csr1.ARN3.gblx.net [67.17.74.41]
8 1 ms 1 ms 1 ms po6-60G.ar2.ARN3.gblx.net [67.16.146.82]
9 9 ms 11 ms 11 ms altbox.tengigabitethernet4-4.ar2.arn3.gblx.net [209.130.172.58]
10 37 ms 34 ms 44 ms 237.79-160-112.customer.lyse.net [79.160.112.237]
11 31 ms 31 ms 31 ms 2.79-160-49.customer.lyse.net [79.160.49.2]
12 37 ms 36 ms 36 ms 65.79-160-49.customer.lyse.net [79.160.49.65]
13 33 ms 33 ms 33 ms 203.79-160-49.customer.lyse.net [79.160.49.203]
14 * * * Request timed out.
:
30 * * * Request timed out.
Trace complete.
Just want to check they are have not been blocked by my firewall. Some IP's are doing non-standard http requests and are being blocked by my firewall.
Is the block time limited? I actually succeed in seeing the sensors from time to time.
Thanks again for your site - very useful.
According to the logs you got blocked for doing a unknown HTTP command. I.e. something else than GET, POST, PUT, DELETE, OPTION, HEAD. The log does not state what. Are you running some funny software on your computer?
At the moment I am on
Tracert from that PC done now is as follows
Tracing route to tellmon.net [79.161.150.134]
over a maximum of 30 hops:
1 * * * Request timed out.
2 3 ms <1 ms <1 ms 158.39.96.1
3 3 ms 4 ms 5 ms npolar-gw.npolar.no [158.39.97.65]
4 3 ms 3267 ms 17 ms vethstromso-gw.uninett.no [128.39.230.189]
5 <1 ms <1 ms <1 ms tromso-gw4.uninett.no [128.39.230.205]
6 3 ms <1 ms <1 ms tromso-gw2.uninett.no [128.39.255.157]
7 16 ms 15 ms 15 ms trd-gw.uninett.no [128.39.254.101]
8 23 ms 22 ms 22 ms oslo-gw1.uninett.no [128.39.255.45]
9 23 ms 26 ms 26 ms 193.156.90.66
10 24 ms 23 ms 23 ms 237.79-160-112.customer.lyse.net [79.160.112.237]
11 27 ms 27 ms 28 ms 2.79-160-49.customer.lyse.net [79.160.49.2]
12 26 ms 27 ms 26 ms 65.79-160-49.customer.lyse.net [79.160.49.65]
13 26 ms 26 ms 26 ms 203.79-160-49.customer.lyse.net [79.160.49.203]
14 27 ms 26 ms 30 ms 134.79-161-150.customer.lyse.net [79.161.150.134
]
Trace complete.
I suspect you are running some software on your computer what prevents you from accessing the site.
And post your http headers?
The IP adresses are 158.39.96.x
Request methodGET
Request URI/
Request protocolHTTP/1.1
Accepttext/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept charset
Accept encodinggzip, deflate
Accept languageen-US,en;q=0.5
Connectionkeep-alive Hostmyhttp.info
Referer
User agentMozilla/5.0 (Macintosh; Intel Mac OS X 10.10; rv:37.0) Gecko/20100101 Firefox/37.0
Can you check if you can reach http://paks.no or http://crashtest.ninja as well? These are two other web sites running on the same server.
I've turned on default binding, can you see if you can reach anything now?
There is nothing on Tellmon that should cause it to be blocked. I'm not doing anything fancy, not should the address be blocked by any filters. Could you have a colleague try from another computer on the work network? Good to know if it's an issue with your computer or the whole network.
"Har nu gjort diverse tester och enligt vad jag kan se så är det troligtvis storleken på paketen från ”paks.no” som är problemet. När man kör från vårt demonät är MTU-storleken mindre än från t ex ECN (anledningen till detta är en annan historia…), och i normala fall så anpassas paketstorleken efter detta. Jämför jag t ex storleken på mottagna paket från ”www.dn.se” till en klient på demonätet med en klient på ECN, så ser jag att paketen är mindre som går till klienten på demonätet. Av någon anledning verkar dock inte denna anpassning göras när man kopplar upp sig mot ”paks.no”, vilket gör att paketen inte kommer fram till klienten.
I do not think it’s the actual MTU on the FW that should be changed. 1500 bytes is standard. It seems more like the TCP Path MTU Discovery (PMTUD) isn’t working, i.e. the function to discover the MTU of the complete path between the server and the client. PMTUD is using ICMP, so I think a first step can be to make sure the FW does not block incoming ICMP type 3 code 4 messages (i.e. “Destination Unreachable, Fragmentation Needed and Don’t Fragment was Set”. These ICMP messages must be able to reach the webserver so it can adjust the packet size accordingly.
Open the page and enter paks.no as target and test yourself.
MTU test :
Let me Test it
28
Online MTU test allows you to test the maximum MTU size from our host to your destination. To check your MTU, simply provide your IP or DNS hostname. We will test the PMTU (Path Maximum Transfer Unit) aka maximum MTU size (unfragmented) between our host and your destination, most likely the outside of your router or firewall.
More info: Wikipedia
This online MTU test is in BETA. Please let us know, using our contact form, if you find any irregularities.
This MTU test only tests the MTU on the connection between “www.letmecheck.it” and “paks.no”, not from my client to “paks.no”, i.e. I will get the same result as you.
I still think it’s PMTUD functionality that is broken, the question is which node(s) that breaks it… Is 79.161.150.134 the “real” address of the web server, or it is hidden behind NAT on the FW? What kind of web server are you running?
It is being NATed by a pfSense based firewall. Port 80 is forwarded to IIS which in turn uses the HOST http header to route to the correct web site.
It's available via both IPv4 and IPv6
---
I do not have any experience of pfSense firewalls, but looking at the web it seems like pfSense has a known problem with PMTUD in conjunction with NAT. My suggestion is to try the setting the kernel parameter “net.inet.icmp.reply_from_interface=1” according to the following web site to see if that fixes the problem:
https://plone.lucidsolutions.co.nz/networking/pfsense/pfsense-v2.1.5-pmtud-issue-with-ipv4-and-nat
---
Tellmon has over 1500 users, the other web sites running on the same server has even more users. I find it strange that an supposed MTU issue should prevent 3 users access. My feeling is that a much larger group should have issues. I've tested the site with all the tools and checks I can think of. And none are reporting any issues.
Tellmon is available via both IPv4 and IPv6 from over 50 different locations I've tested from.
If the error is in our domain or in yours we probably never will find out unless we continue to work together, but if you find it to much of a hassle I will stop the work initiated and move to another network when I need to connect to tellmon.net.
Or can't you access those web sites neither from the same network you have issues with tellmon from?
If you have telnet installed you can do the following from a command prompt:
telnet tellmon.net 80
It will try to connect to port 80 (http) on tellmon, it would be good to know if it connects at all. If you do not have telnet installed download a tool called portping that I made here: https://www.dropbox.com/s/2tth5ig7oqg0iiw/PortPing.zip?dl=0
Unzip and run from command prompt (requires .Net runtime)
portping tellmon.net 80
The telnet reports the following:
mg11:~ Mats$ telnet tellmon.net 80
Trying 79.161.150.134...
telnet: connect to address 79.161.150.134: Operation timed out
Trying 2a01:79d:3e86:5a18:5945:87fd:f332:83c...
telnet: connect to address 2a01:79d:3e86:5a18:5945:87fd:f332:83c: No route to host
telnet: Unable to connect to remote host
1 10.4.4.1 (10.4.4.1) 3.298 ms 1.915 ms 2.128 ms
2 192.36.162.9 (192.36.162.9) 2.676 ms 2.291 ms 2.279 ms
3 ilikr2-ge-0-0-3-1.ilik.net (192.71.20.21) 5.031 ms 509.863 ms 4.442 ms
4 telia-gw.ilik.net (192.71.20.25) 2.745 ms 2.808 ms 2.957 ms
5 193.181.252.67 (193.181.252.67) 3.065 ms 3.087 ms 2.987 ms
6 sesbww01-r12.ericsson.net (193.180.17.236) 2.984 ms 3.087 ms 3.340 ms
7 78.77.163.217 (78.77.163.217) 3.033 ms 4.801 ms 3.232 ms
8 s-b6-link.telia.net (80.91.250.43) 3.828 ms 4.179 ms 4.517 ms
9 level3-ic-155475-s-b2.c.telia.net (213.248.99.134) 42.783 ms 31.932 ms 31.786 ms
10 * ae-1-3.bear1.oslo2.level3.net (4.69.202.245) 28.569 ms 29.383 ms
11 ae-1-3.bear1.oslo2.level3.net (4.69.202.245) 28.428 ms 28.698 ms 28.451 ms
12 62.140.27.6 (62.140.27.6) 28.766 ms 28.999 ms 28.393 ms
13 216.213-167-114.customer.lyse.net (213.167.114.216) 29.179 ms 30.508 ms 31.162 ms
14 237.79-160-112.customer.lyse.net (79.160.112.237) 30.061 ms 28.175 ms 28.393 ms
15 2.79-160-49.customer.lyse.net (79.160.49.2) 29.889 ms 29.706 ms 29.963 ms
16 65.79-160-49.customer.lyse.net (79.160.49.65) 32.049 ms 31.082 ms 31.180 ms
17 203.79-160-49.customer.lyse.net (79.160.49.203) 31.332 ms 31.903 ms 31.391 ms
18 134.79-161-150.customer.lyse.net (79.161.150.134) 31.324 ms 31.248 ms 31.329 ms
IPv6:
$ telnet tellmon.net 80
Trying 2a01:79d:3e86:5a18:5945:87fd:f332:83c...
Connected to tellmon.net
IPv4
$ telnet -4 tellmon.net 80
Trying 79.161.150.134...
Connected to 134.79-161-150.customer.lyse.net
about: config
and set settingnetwork.dns.disableIPv6
to true$ tracepath -n 79.161.150.134
(ping -g 1444 -G 1508 -c 2 -h 1 -D tellmon.net)
https://www.dropbox.com/s/d6zznaypfb2uw49/Tracepath-tellmon_net.pdf?dl=0
Even without cookies you should always get the front page, since that does not require authentication. Also people with connectivity issues cannot reach any of the other web sites on the same server either (test http://paks.no or http://crashtest.ninja).
That it works from an iOS device on the same network is really interesting though.
http://crashtest.ninja and http://paks.no are also NOT accessible from Chrome, but accessible from Tor...