# Can ping SLES11 Server

**URL:** <https://forums.suse.com/t/can-ping-sles11-server/24226>\
**Category:** SLES Networking\
**Created:** [August 2, 2013, 12:44am UTC](https://forums.suse.com/t/can-ping-sles11-server/24226 "2013-08-02T00:44:28Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![nix34](https://avatars.discourse-cdn.com/v4/letter/n/ce7236/32.png) [@nix34](https://forums.suse.com/u/nix34)\
**Post date:** [August 2, 2013, 12:44am UTC](https://forums.suse.com/t/can-ping-sles11-server/24226/1 "2013-08-02T00:44:28Z")

</div>

I have a new SLES11 server built at a branch 1.

I can ping anything inside the branch from the server and everything at other branches as well. Can also access internet

I go to another branch, lets say branch 2. I can’t ping this server at branch 1 but can ping everything else at branch 1.

---

<div class="post-metadata">

**Author:** ![Jens-U](https://avatars.discourse-cdn.com/v4/letter/j/d78d45/32.png) [@Jens-U](https://forums.suse.com/u/Jens-U)\
**Post date:** [August 2, 2013, 1:06pm UTC](https://forums.suse.com/t/can-ping-sles11-server/24226/2 "2013-08-02T13:06:34Z")

</div>

Hi nix34,

[QUOTE=nix34;14882]I have a new SLES11 server built at a branch 1.

I can ping anything inside the branch from the server and everything at other branches as well. Can also access internet

I go to another branch, lets say branch 2. I can’t ping this server at branch 1 but can ping everything else at branch 1.[/QUOTE]

sounds like that new server does not have a proper default route set up.

Regards,  
Jens

---

<div class="post-metadata">

**Author:** ![Jens-U](https://avatars.discourse-cdn.com/v4/letter/j/d78d45/32.png) [@Jens-U](https://forums.suse.com/u/Jens-U)\
**Post date:** [August 2, 2013, 1:10pm UTC](https://forums.suse.com/t/can-ping-sles11-server/24226/3 "2013-08-02T13:10:08Z")

</div>

Hi nix34,

answered too quickly - I mis-read your second line (I somehow read the “others” at branch1 can reach anything else, too).

Can you verify that the new server at branch1 receives the icmp echo requests from branch2? If yes, how/where are the replies sent? You can use “tcpdump -nvv icmp” on server at branch1 to trace the ICMP (echo request/response, AKA “ping”) packets.

Regards,  
Jens

---

<div class="post-metadata">

**Author:** ![KEVIN1](https://avatars.discourse-cdn.com/v4/letter/k/a9adbd/32.png) [@KEVIN1](https://forums.suse.com/u/KEVIN1)\
**Post date:** [August 2, 2013, 7:49pm UTC](https://forums.suse.com/t/can-ping-sles11-server/24226/4 "2013-08-02T19:49:15Z")

</div>

nix34 wrote:  
[color=blue]

> I go to another branch, lets say branch 2. I can’t ping this server  
> at branch 1 but can ping everything else at branch 1.[/color]

Is your firewall running?

Check /etc/sysconfig/SuSEfirewall2. There you can specify what type of  
access is allowed. For example:

[color=blue]

> # 9.)
> 
> # Which TCP services _on the firewall_ should be accessible from
> 
> # untrusted networks?
> 
> # 
> 
> # Enter all ports or known portnames below, seperated by a space.
> 
> # TCP services (e.g. SMTP, WWW) must be set in FW\_SERVICES\_\*\_TCP, and
> 
> # UDP services (e.g. syslog) must be set in FW\_SERVICES\_\*\_UDP.
> 
> # e.g. if a webserver on the firewall should be accessible from the
> 
> internet:
> 
> # FW\_SERVICES\_EXT\_TCP=“www”[/color]

and  
[color=blue]

> # 10.)
> 
> # Which services should be accessible from ‘trusted’ hosts or nets?
> 
> # 
> 
> # Define trusted hosts or networks (doesn’t matter whether they are
> 
> internal or
> 
> # external) and the services (tcp,udp,icmp) they are allowed to use.
> 
> This can
> 
> # be used instead of FW\_SERVICES\_\* for further access restriction.
> 
> Please note
> 
> # that this is no replacement for authentication since IP addresses
> 
> can be
> 
> # spoofed. Also note that trusted hosts/nets are not allowed to ping
> 
> the
> 
> # firewall until you also permit icmp.
> 
> # 
> 
> # Format: space separated list of network[,protocol[,port]]
> 
> # in case of icmp, port means the icmp type
> 
> # 
> 
> # Example: “172.20.1.1 172.20.0.0/16 1.1.1.1,icmp 2.2.2.2,tcp,22”[/color]

–  
Kevin Boyle - Knowledge Partner  
If you find this post helpful and are logged into the web interface,  
show your appreciation and click on the star below…

---

<div class="post-metadata">

**Author:** ![nix34](https://avatars.discourse-cdn.com/v4/letter/n/ce7236/32.png) [@nix34](https://forums.suse.com/u/nix34)\
**Post date:** [August 3, 2013, 1:27am UTC](https://forums.suse.com/t/can-ping-sles11-server/24226/5 "2013-08-03T01:27:05Z")

</div>

Basically trying to set up VNC so the helpdesk can access server. For example: http:\\server name or IP:5801 When trying this, it failed

When we tried to ping the server, that failed. However, when we were pinging pc’s, laptops, printers, switches, routers at that locaiton, we can ping those devices without any problems. What was missed when installing SLES11?

Now, when we visit the site, we CAN ping the server since we are there locally.

---

<div class="post-metadata">

**Author:** ![nix34](https://avatars.discourse-cdn.com/v4/letter/n/ce7236/32.png) [@nix34](https://forums.suse.com/u/nix34)\
**Post date:** [August 3, 2013, 1:27am UTC](https://forums.suse.com/t/can-ping-sles11-server/24226/6 "2013-08-03T01:27:55Z")

</div>

No firewall is on

[QUOTE=KBOYLE;14900]nix34 wrote:  
[color=blue]

> I go to another branch, lets say branch 2. I can’t ping this server  
> at branch 1 but can ping everything else at branch 1.[/color]

Is your firewall running?

Check /etc/sysconfig/SuSEfirewall2. There you can specify what type of  
access is allowed. For example:

[color=blue]

> # 9.)
> 
> # Which TCP services _on the firewall_ should be accessible from
> 
> # untrusted networks?
> 
> # 
> 
> # Enter all ports or known portnames below, seperated by a space.
> 
> # TCP services (e.g. SMTP, WWW) must be set in FW\_SERVICES\_\*\_TCP, and
> 
> # UDP services (e.g. syslog) must be set in FW\_SERVICES\_\*\_UDP.
> 
> # e.g. if a webserver on the firewall should be accessible from the
> 
> internet:
> 
> # FW\_SERVICES\_EXT\_TCP=“www”[/color]

and  
[color=blue]

> # 10.)
> 
> # Which services should be accessible from ‘trusted’ hosts or nets?
> 
> # 
> 
> # Define trusted hosts or networks (doesn’t matter whether they are
> 
> internal or
> 
> # external) and the services (tcp,udp,icmp) they are allowed to use.
> 
> This can
> 
> # be used instead of FW\_SERVICES\_\* for further access restriction.
> 
> Please note
> 
> # that this is no replacement for authentication since IP addresses
> 
> can be
> 
> # spoofed. Also note that trusted hosts/nets are not allowed to ping
> 
> the
> 
> # firewall until you also permit icmp.
> 
> # 
> 
> # Format: space separated list of network[,protocol[,port]]
> 
> # in case of icmp, port means the icmp type
> 
> # 
> 
> # Example: “172.20.1.1 172.20.0.0/16 1.1.1.1,icmp 2.2.2.2,tcp,22”[/color]

–  
Kevin Boyle - Knowledge Partner  
If you find this post helpful and are logged into the web interface,  
show your appreciation and click on the star below…[/QUOTE]

---

<div class="post-metadata">

**Author:** ![Jens-U](https://avatars.discourse-cdn.com/v4/letter/j/d78d45/32.png) [@Jens-U](https://forums.suse.com/u/Jens-U)\
**Post date:** [August 3, 2013, 8:54pm UTC](https://forums.suse.com/t/can-ping-sles11-server/24226/7 "2013-08-03T20:54:51Z")

</div>

Hi nix34,

unfortunately, you did not provide information on the ICMP packets, as seen from the new server. Could you please run the tcpdump and report back the results?

_If_ the new server receives the ICMP echo requests (“ping” requests), then please include the interface IP setup and routing table of the new server, per c&p of the according commands.

Regards,  
Jens

---

<div class="post-metadata">

**Author:** ![KEVIN1](https://avatars.discourse-cdn.com/v4/letter/k/a9adbd/32.png) [@KEVIN1](https://forums.suse.com/u/KEVIN1)\
**Post date:** [August 3, 2013, 11:33pm UTC](https://forums.suse.com/t/can-ping-sles11-server/24226/8 "2013-08-03T23:33:24Z")

</div>

nix34 wrote:  
[color=blue]

> No firewall is on  
> [/color]

How is your network at branch 1 configured?

1. This new server connects to the Internet via a separate router…

or

1. This new server is your gateway to the Internet. It has one  
interface connected to the external network (Internet) and another  
interface connected to the internal network.

As Jens already mentioned, the first step is to confirm that the ICMP  
echo request (ping) actually reaches the server. The next step is to  
determine whether a response is sent and what happens to it. If the  
default route is incorrect, the response may never be returned to the  
host that issues the ICMP echo request. If you’re using  
nat/masquerading and it is misconfigured, the response may very well be  
sent but it may appear to be from a different device and not recognised  
as a valid reply to the ICMP echo request.

–  
Kevin Boyle - Knowledge Partner  
If you find this post helpful and are logged into the web interface,  
show your appreciation and click on the star below…

---

<div class="post-metadata">

**Author:** ![smflood](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/smflood/32/10576_2.png) [@smflood](https://forums.suse.com/u/smflood)\
**Post date:** [August 4, 2013, 2:32pm UTC](https://forums.suse.com/t/can-ping-sles11-server/24226/9 "2013-08-04T14:32:23Z")

</div>

jmozdzen wrote:  
[color=blue]

> sounds like that new server does not have a proper default route set  
> up.[/color]

… or has an incorrect network mask set.

## HTH.

Simon  
SUSE Knowledge Partner

---

<div class="post-metadata">

**Author:** ![Jens-U](https://avatars.discourse-cdn.com/v4/letter/j/d78d45/32.png) [@Jens-U](https://forums.suse.com/u/Jens-U)\
**Post date:** [August 4, 2013, 3:01pm UTC](https://forums.suse.com/t/can-ping-sles11-server/24226/10 "2013-08-04T15:01:47Z")

</div>

Hi Simon,

[QUOTE=smflood;14915]jmozdzen wrote:  
[color=blue]

> sounds like that new server does not have a proper default route set  
> up.[/color]

… or has an incorrect network mask set.

## HTH.

Simon  
SUSE Knowledge Partner[/QUOTE]

then it’d be astonishing that the new server can ping everything at other branches. OTOH, it may not have been fully tested, that’s why I’m after the c&p of the interface config.

Regards,  
Jens
