G
Guest
Problem:
So what is happening is we have workstations that are using DHCP and well it
seems like after being connected for a while they will loose their connection
to be able to browse the internet do any kind of external nslookup or ping
any external IP Address but they can access any resource on the internal LAN.
When an IP die’s any machine with that IP can ping 10.0.2.1 (gateway) or any
internal machine on the Internal and DMZ LAN just fine, but not
210.86.17.129(Router Interface) or any ping able external IP.
Adding external DNS servers to the list makes no difference.
The IP that is 'dead' - you can set up another machine with that IP, and
then that machine won't have net access, but they can access (and of course
ping) everything on the internal network (including the internal interface of
any gateway).
The most curious thing is that existing TCP connections continue to work.
However, new TCP connections are denied (time out).
So if you have outlook open, which has keepalive connections to our external
exchange hosted by Mi8, that works just fine - but your browsing dies
(because those are all unique TCP connection requests).
Also observed that a dead IP becomes live again after some time – approx 75
minutes.
Doesn't sound anything whatsoever like a DNS issue to me - remember, we're
failing to ping the gateway's external IP address, not a DNS name.
Any suggestions on where to go from here or where to look?
So what is happening is we have workstations that are using DHCP and well it
seems like after being connected for a while they will loose their connection
to be able to browse the internet do any kind of external nslookup or ping
any external IP Address but they can access any resource on the internal LAN.
When an IP die’s any machine with that IP can ping 10.0.2.1 (gateway) or any
internal machine on the Internal and DMZ LAN just fine, but not
210.86.17.129(Router Interface) or any ping able external IP.
Adding external DNS servers to the list makes no difference.
The IP that is 'dead' - you can set up another machine with that IP, and
then that machine won't have net access, but they can access (and of course
ping) everything on the internal network (including the internal interface of
any gateway).
The most curious thing is that existing TCP connections continue to work.
However, new TCP connections are denied (time out).
So if you have outlook open, which has keepalive connections to our external
exchange hosted by Mi8, that works just fine - but your browsing dies
(because those are all unique TCP connection requests).
Also observed that a dead IP becomes live again after some time – approx 75
minutes.
Doesn't sound anything whatsoever like a DNS issue to me - remember, we're
failing to ping the gateway's external IP address, not a DNS name.
Any suggestions on where to go from here or where to look?