* Lew Wolfgang
On 04/02/2019 03:38 PM, Patrick Shanahan wrote:
* Patrick Shanahan
[04-02-19 16:11]: * Patrick Shanahan
[04-02-19 16:06]: my local server is running Leap 42.2 all local machines may connect to the server, except one, 192.168.1.10
192.168.1.10 is my main workstation and connected fine until 08:36am this morning local time -4 utc. concerned interfaces are ssh, nfs and http
no software change nor noted system abnormality, except the open ssh windows on 192.168.1.10 froze, would not accept input. ping fails both ways.
stopping SuSEfirewall2 on the server allows connection and ping succeedes both ways server -> 192.168.1.10 and 192.168.1.10 -> server (192.168.1.3) of course I do not wish to run my server w/o a firewall, even though there is one within the router.
Time for some troubleshooting? 192.168.1.3 is the server, right? From your workstation, have you tried nmap to see what ports are open? Maybe try it with the server's firewall both on and off. You should see ports 22, 2049, 80, and maybe 111.
from server/192.168.1.3 # nmap -F 192.168.1.3 Starting Nmap 6.47 ( http://nmap.org ) at 2019-04-02 21:09 EDT Nmap scan report for wahoo.wahoo.no-ip.org (192.168.1.3) Host is up (0.000015s latency). Not shown: 92 closed ports PORT STATE SERVICE 22/tcp open ssh 25/tcp open smtp 80/tcp open http 111/tcp open rpcbind 139/tcp open netbios-ssn 445/tcp open microsoft-ds 2049/tcp open nfs 3306/tcp open mysql Nmap done: 1 IP address (1 host up) scanned in 1.55 seconds # systemctl stop SuSEfirewall2 wahoo: ~ # nmap -F 192.168.1.3 Starting Nmap 6.47 ( http://nmap.org ) at 2019-04-02 21:09 EDT Nmap scan report for wahoo.wahoo.no-ip.org (192.168.1.3) Host is up (0.000020s latency). Not shown: 92 closed ports PORT STATE SERVICE 22/tcp open ssh 25/tcp open smtp 80/tcp open http 111/tcp open rpcbind 139/tcp open netbios-ssn 445/tcp open microsoft-ds 2049/tcp open nfs 3306/tcp open mysql Nmap done: 1 IP address (1 host up) scanned in 1.55 seconds # systemctl start SuSEfirewall2 from workstation/192.168.1.10 # nmap -F 192.168.1.10 Starting Nmap 7.70 ( https://nmap.org ) at 2019-04-02 21:17 EDT Nmap scan report for crash.wahoo.no-ip.org (192.168.1.10) Host is up (0.000023s latency). Not shown: 96 closed ports PORT STATE SERVICE 22/tcp open ssh 25/tcp open smtp 111/tcp open rpcbind 2049/tcp open nfs Nmap done: 1 IP address (1 host up) scanned in 1.54 seconds # systemctl stop firewalld # nmap -F 192.168.1.10 Starting Nmap 7.70 ( https://nmap.org ) at 2019-04-02 21:17 EDT Nmap scan report for crash.wahoo.no-ip.org (192.168.1.10) Host is up (0.000011s latency). Not shown: 96 closed ports PORT STATE SERVICE 22/tcp open ssh 25/tcp open smtp 111/tcp open rpcbind 2049/tcp open nfs Nmap done: 1 IP address (1 host up) scanned in 1.59 seconds # systemctl start firewalld
Then, if you can see the ports, maybe try telnet to see if you can establish a tcp connection and get a banner on port 22. As in "telnet 192.168.1.3 22".
from 192.168.1.10 to server 192.168.1.3 # telnet 192.168.1.3 22 Trying 192.168.1.3... telnet: connect to address 192.168.1.3: Connection timed out from server to workstation (192.168.1.3 -> 192.168.1.10) # telnet 192.168.1.10 22 Trying 192.168.1.10... telnet: connect to address 192.168.1.10: Connection timed out
Oh, are you running ipv6?
it is enabled but not knowing enough about ipv6, I use ipv4 for internal net commands.
Of course, things become more complicated if Windows are involved. All the machines are running Linux, right?
there are windows machines on the net but not involved. afaics the *only* difficulty is between workstation 192.168.1.10 and the server 192.168.1.3 and stopping the server firewall allows ssh from workstation to succeed. tks -- (paka)Patrick Shanahan Plainfield, Indiana, USA @ptilopteri http://en.opensuse.org openSUSE Community Member facebook/ptilopteri Registered Linux User #207535 @ http://linuxcounter.net Photos: http://wahoo.no-ip.org/piwigo paka @ IRCnet freenode -- To unsubscribe, e-mail: opensuse-support+unsubscribe@opensuse.org To contact the owner, e-mail: opensuse-support+owner@opensuse.org