B
B
Big_F2021-09-29 15:03:16
linux
Big_F, 2021-09-29 15:03:16

Why is the site not working?

Good afternoon.
There is the following problem with one site - it opens, after a couple of clicks it stops responding and seems to be blocked for a while, then it works again. The problem exists on devices on the network behind Mikrotik RB4011.
2 providers are connected, the problem is relevant on both. At the moment when the site is "blocked" it is available by ping, it is available from the mobile Internet, it is available on the PC behind other routers from the same providers. At the same time, there is a moment that the site works normally on the Linux distribution of ThinStation (it is possible that on other Linux distributions too, but this one was at hand =)), but if at that moment you log in from a PC under Win, then the site is blocked, including on ThinStation. In the Mikrotik firewall, they turned off all the prohibiting rules, tried to change the MSS through the mangle, tried to set up a route through the VPN to Mikrotik, behind which everything works - it did not help. Wireshark monitored the exchange of packets, at some point TCP Retransmissions and destination unreachable (port unreachable) begin. Absolutely incomprehensible behavior. Can someone suggest something what could be the problem? They've broken their brains.

Answer the question

In order to leave comments, you need to log in

2 answer(s)
H
hint000, 2021-09-29
@hint000

Start by pulling out the Dlink DIR-300 or something similar from the trash can and concretely check that the problem is in Mikrotik . Here we let it through another router and the problem disappears, but we let it through Mikrotik, and the problem reappears.

the site works fine on the ThinStation Linux distribution
The difference, for example, is that on Windows the TTL of the outgoing packet is 64, and on Linux it is 128. Ie. theoretically, there may be some kind of network anomaly leading to a very long route, on the verge of 64 hops ( did you do a trace? ), and for some reason the length of the route floats more or less (do not ask why this can be), but Linux does not care. But kill me - I have no idea what is happening, that Windows can break the connection to Linux with its packages.
Is the URL of the problem site a secret?

M
Maxim Karamyshev, 2021-09-30
@minimaximka

Good day, how do you set up 2 wan interfaces and who balances requests to the site?
as an option - try to cut off one provider and remove the non-working channel from the A records in the hoster's dns - if the problem is solved - look towards MPLS\Connection mark.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question