Possible mal-configuration for ACL for some aggregates

9 views
Skip to first unread message

Dong Mo

unread,
Jan 12, 2014, 5:35:14 PM1/12/14
to he...@geni.net, geni-...@googlegroups.com
Hi all,

After repeated retries I successfully created link stitch between uthddc and uky using the example stitching script "stitch-ig-utahddc-pg-uky.rspec".

with the following sliver detail for network interfaces:
ig-utahddc:if0 pc27:eth1 024216e63fa3 ipv4: 192.168.1.1
pg-uky:if0 pc48:eth1 02bf859ccc0b ipv4: 192.168.1.2
I can do ping between 192.168.1.1 and 192.168.1.2. However, I cannot initiate any TCP flows between them.

I tried this using iperf, iperf shows it is connected successfully, but no feedback comes back.

The current situation looks like there is some ACL or firewall rule there banning all TCP/UDP traffic but letting the ICMP through....


Could anyone help me investigate on that?

Possibly some mal-configuration or outage

Thank you so much
-Mo

niky riga

unread,
Jan 12, 2014, 5:42:51 PM1/12/14
to geni-...@googlegroups.com
This seems like it might be a problem with the MTU, can you set the MTU
of your data interface to something smaller:

sudo ifconfig <interface_name> mtu 1400

Do that in both hosts.

--niky

Dong Mo wrote:
> Hi all,
>
> After repeated retries I successfully created link stitch between uthddc
> and uky using the example stitching script "stitch-ig-utahddc-pg-uky.rspec".
>
> with the following sliver detail for network interfaces:
> ig-utahddc:if0pc27:eth1024216e63fa3ipv4: 192.168.1.1
> pg-uky:if0pc48:eth102bf859ccc0bipv4: 192.168.1.2

Luisa Nevers

unread,
Jan 13, 2014, 8:59:28 AM1/13/14
to geni-...@googlegroups.com, he...@geni.net
Hello,

The problem you are seeing is a known issue (http://groups.geni.net/geni/ticket/1086)  which has not been addressed.  You can workaround this problem by specifying an MTU for your TCP traffic. I do not know when/if a solution is coming.

Luisa
--
GENI Users is a community supported mailing list, so please help by responding to questions you know the answer to.
 
If this is your first time posting a question to this list, please review http://groups.geni.net/geni/wiki/GENIExperimenter/CommunityMailingList
---
You received this message because you are subscribed to the Google Groups "GENI Users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to geni-users+...@googlegroups.com.
For more options, visit https://groups.google.com/groups/opt_out.

Reply all
Reply to author
Forward
0 new messages