Hi,
thanks for your answer.
Here the outputs.
ip addr output is:
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 16436 qdisc noqueue state UNKNOWN
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
inet 127.0.0.1/8 brd 127.255.255.255 scope host lo
inet 127.0.0.2/8 brd 127.255.255.255 scope host secondary lo
inet6 ::1/128 scope host
valid_lft forever preferred_lft forever
2: em1: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc mq state UP qlen 1000
link/ether e0:db:55:1f:a3:12 brd ff:ff:ff:ff:ff:ff
inet 131.173.111.149/23 brd 131.173.111.255 scope global em1
inet6 fe80::e2db:55ff:fe1f:a312/64 scope link
valid_lft forever preferred_lft forever
3: em2: <BROADCAST,MULTICAST> mtu 1500 qdisc noop state DOWN qlen 1000
link/ether e0:db:55:1f:a3:14 brd ff:ff:ff:ff:ff:ff
ip route output is:
default via 131.173.111.254 dev em1
127.0.0.0/8 dev lo scope link
131.173.110.0/23 dev em1 proto kernel scope link src 131.173.111.149
ip -s link output when not working:
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 16436 qdisc noqueue state UNKNOWN
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
inet 127.0.0.1/8 brd 127.255.255.255 scope host lo
inet 127.0.0.2/8 brd 127.255.255.255 scope host secondary lo
inet6 ::1/128 scope host
valid_lft forever preferred_lft forever
2: em1: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc mq state UP qlen 1000
link/ether e0:db:55:1f:a3:12 brd ff:ff:ff:ff:ff:ff
inet 131.173.111.149/23 brd 131.173.111.255 scope global em1
inet6 fe80::e2db:55ff:fe1f:a312/64 scope link
valid_lft forever preferred_lft forever
3: em2: <BROADCAST,MULTICAST> mtu 1500 qdisc noop state DOWN qlen 1000
link/ether e0:db:55:1f:a3:14 brd ff:ff:ff:ff:ff:ff
ip -s link output when working:
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 16436 qdisc noqueue state UNKNOWN
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
RX: bytes packets errors dropped overrun mcast
3678447 5228 0 0 0 0
TX: bytes packets errors dropped carrier collsns
3678447 5228 0 0 0 0
2: em1: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc mq state UP qlen 1000
link/ether e0:db:55:1f:a3:12 brd ff:ff:ff:ff:ff:ff
RX: bytes packets errors dropped overrun mcast
24337807 57230 0 556 0 4746
TX: bytes packets errors dropped carrier collsns
6505926 23458 0 0 0 0
3: em2: <BROADCAST,MULTICAST> mtu 1500 qdisc noop state DOWN qlen 1000
link/ether e0:db:55:1f:a3:14 brd ff:ff:ff:ff:ff:ff
RX: bytes packets errors dropped overrun mcast
0 0 0 0 0 0
TX: bytes packets errors dropped carrier collsns
0 0 0 0 0 0
iptables -nvL output when not working:
Chain INPUT (policy DROP 995 packets, 155K bytes)
pkts bytes target prot opt in out source destination
71 168K ACCEPT all – lo * 0.0.0.0/0 0.0.0.0/0
677 79517 ACCEPT all – * * 0.0.0.0/0 0.0.0.0/0 state ESTABLISHED
0 0 ACCEPT icmp – * * 0.0.0.0/0 0.0.0.0/0 state RELATED
Chain FORWARD (policy DROP 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
Chain OUTPUT (policy ACCEPT 679 packets, 50292 bytes)
pkts bytes target prot opt in out source destination
73 168K ACCEPT all – * lo 0.0.0.0/0 0.0.0.0/0
Chain reject_func (0 references)
pkts bytes target prot opt in out source destination
0 0 REJECT tcp – * * 0.0.0.0/0 0.0.0.0/0 reject-with tcp-reset
0 0 REJECT udp – * * 0.0.0.0/0 0.0.0.0/0 reject-with icmp-port-unreachable
0 0 REJECT all – * * 0.0.0.0/0 0.0.0.0/0 reject-with icmp-proto-unreachable
iptables -nvL output when working:
Chain INPUT (policy DROP 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
27 2587 ACCEPT all – lo * 0.0.0.0/0 0.0.0.0/0
391 34556 ACCEPT all – * * 0.0.0.0/0 0.0.0.0/0 state ESTABLISHED
0 0 ACCEPT icmp – * * 0.0.0.0/0 0.0.0.0/0 state RELATED
170 30429 input_ext all – em1 * 0.0.0.0/0 0.0.0.0/0
0 0 input_ext all – em2 * 0.0.0.0/0 0.0.0.0/0
0 0 input_ext all – * * 0.0.0.0/0 0.0.0.0/0
0 0 LOG all – * * 0.0.0.0/0 0.0.0.0/0 limit: avg 3/min burst 5 LOG flags 6 level 4 prefix `SFW2-IN-ILL-TARGET ’
0 0 DROP all – * * 0.0.0.0/0 0.0.0.0/0
Chain FORWARD (policy DROP 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
0 0 LOG all – * * 0.0.0.0/0 0.0.0.0/0 limit: avg 3/min burst 5 LOG flags 6 level 4 prefix `SFW2-FWD-ILL-ROUTING ’
Chain OUTPUT (policy ACCEPT 363 packets, 257K bytes)
pkts bytes target prot opt in out source destination
27 2587 ACCEPT all – * lo 0.0.0.0/0 0.0.0.0/0
Chain forward_ext (0 references)
pkts bytes target prot opt in out source destination
Chain input_ext (3 references)
pkts bytes target prot opt in out source destination
163 29969 DROP all – * * 0.0.0.0/0 0.0.0.0/0 PKTTYPE = broadcast
0 0 ACCEPT icmp – * * 0.0.0.0/0 0.0.0.0/0 icmp type 4
0 0 ACCEPT icmp – * * 0.0.0.0/0 0.0.0.0/0 icmp type 8
0 0 LOG tcp – * * 0.0.0.0/0 0.0.0.0/0 limit: avg 3/min burst 5 tcp dpts:12097:12099 flags:0x17/0x02 LOG flags 6 level 4 prefix SFW2-INext-ACC-TCP ' 0 0 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpts:12097:12099 0 0 LOG tcp -- * * 0.0.0.0/0 0.0.0.0/0 limit: avg 3/min burst 5 tcp dpt:4544 flags:0x17/0x02 LOG flags 6 level 4 prefix
SFW2-INext-ACC-TCP ’
0 0 ACCEPT tcp – * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:4544
0 0 LOG tcp – * * 0.0.0.0/0 0.0.0.0/0 limit: avg 3/min burst 5 tcp dpt:9090 flags:0x17/0x02 LOG flags 6 level 4 prefix SFW2-INext-ACC-TCP ' 0 0 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:9090 0 0 LOG tcp -- * * 0.0.0.0/0 0.0.0.0/0 limit: avg 3/min burst 5 tcp dpt:22 flags:0x17/0x02 LOG flags 6 level 4 prefix
SFW2-INext-ACC-TCP ’
0 0 ACCEPT tcp – * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:22
6 380 LOG all – * * 0.0.0.0/0 0.0.0.0/0 limit: avg 3/min burst 5 PKTTYPE = multicast LOG flags 6 level 4 prefix SFW2-INext-DROP-DEFLT ' 7 460 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 PKTTYPE = multicast 0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 PKTTYPE = broadcast 0 0 LOG tcp -- * * 0.0.0.0/0 0.0.0.0/0 limit: avg 3/min burst 5 tcp flags:0x17/0x02 LOG flags 6 level 4 prefix
SFW2-INext-DROP-DEFLT ’
0 0 LOG icmp – * * 0.0.0.0/0 0.0.0.0/0 limit: avg 3/min burst 5 LOG flags 6 level 4 prefix SFW2-INext-DROP-DEFLT ' 0 0 LOG udp -- * * 0.0.0.0/0 0.0.0.0/0 limit: avg 3/min burst 5 state NEW LOG flags 6 level 4 prefix
SFW2-INext-DROP-DEFLT ’
0 0 DROP all – * * 0.0.0.0/0 0.0.0.0/0
Chain reject_func (0 references)
pkts bytes target prot opt in out source destination
0 0 REJECT tcp – * * 0.0.0.0/0 0.0.0.0/0 reject-with tcp-reset
0 0 REJECT udp – * * 0.0.0.0/0 0.0.0.0/0 reject-with icmp-port-unreachable
0 0 REJECT all – * * 0.0.0.0/0 0.0.0.0/0 reject-with icmp-proto-unreachable
Best regards
Gerlinde Hammer