Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 18 Oct 2006 10:52:24 -0400
From:      Marc Chabot <marcchabot@marcchabot.com>
To:        Martin Turgeon <turgeon.martin@gmail.com>
Cc:        freebsd-pf@freebsd.org
Subject:   Re: Routing with external interface doesn't work after a while
Message-ID:  <20061018101558.7B28.MARCCHABOT@marcchabot.com>
In-Reply-To: <0J7C00A3541CUN90@VL-MH-MR001.ip.videotron.ca>
References:  <0J7C00A3541CUN90@VL-MH-MR001.ip.videotron.ca>

next in thread | previous in thread | raw e-mail | index | archive | help

hello  Martin Turgeon,

On Wed, 18 Oct 2006 09:56:12 -0400
Martin Turgeon <turgeon.martin@gmail.com> wrote:
<snip a lot>
MT> running FreeBSD 6.1 on a Celeron 2.8GHz with 512Mo of RAM. It looks likes
MT> after a while (a couple of weeks) the routing isn't working anymore, but
MT> only with the external interface (the one connected to my cable modem from
MT> Videotron in Montreal). The box is acting as the gateway of the network with
MT> PF, OpenVPN 2.0.5-1 and ISC-DHCPd 3.0.3-1 running. The problem also occurred
MT> on FreeBSD 6.0 on another box.
<snip a lot>
MT> The solution was to renew the address of the external interface with
MT> dhclient fxp0.
<snip a lot>

oh... videotron dynamic modem cable...
about 2 years ago, videotron had problems with their dhcp, it took them
quite some time to fix it, they had to schrink the lease time to 4 hours,
8 hours and the like.   I, friends and the majority of our customers
using videotron-dynamic were calling because internet traffic stopped. 
Many customers were using cheapo nat boxes (dlink, linksys, you name it)
of all makes with different firmware versions, a few with cisco pix 501s,
etc...
The solution?  Same as yours: renew the address of the external interface.
(or simply power cycle the nat box for end users).

And since videotron seems to glue IPs with MAC addresses, users keep
their public IP for many months.  I have never had one stick for more
than 11 months though, but 8 to 9 months is common.   Comically, some
home user desperate to change IPs had to change NIC or clone mac adress
inside their nat boxes and then power cycle the modem cable (clear arp
of the modem) to get a different public ip adress.

That was quite a while ago.
Now, sometimes i see for myself such behavior but just localized, no
customers calling en masse.  When it happens to me (once every two
months?) my mail client beeps and awake me in the middle of the night,
and when i go check my mail servers, well, the whole internet is
unaccessible, i renew the address of the external interface, and voila.
In some cases i had to power cycle the modem cable, it seems to always
happend in the middle of the night, at a time that is apropriate for
them to play with their equipment and disturb as less customers as
possible.   Having has my share of they pretty much useless customer
service, i didn't bother to call them and confirm this.

And I'm not using a *BSD box at home.
At first glance, it does not look like a *BSD bug.

Drop the videotron home service and call VTL (videotron telecomm limitee)
to get a business static ip address, they put a cisco soho91 in between
your modem cable and your router to give you a static ip.

Besides, the support service of videotron home is just as catastrophicly
lousy as sympatico and others, while in some cases i was surprized to
hear some employes of VTL have clue.  The business side of videotron is
more competent then the residential side.

-- 
Best regards,             mail to:  MarcChabot@MarcChabot.com
SysAdmin & MailAdmin for http://www.caminfo.ca
I find television very educating.  Every time somebody turns on the 
T.V., I go into the other room and read a book.  --Groucho Marx





Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20061018101558.7B28.MARCCHABOT>