Solved

IP address unreachable from 2nd site

Posted on 2011-09-22
15
543 Views
Last Modified: 2012-06-21
Customer has two sites linked by VPN. The exchange server at the first site has two NICs with IP addresses of 192.168.2.8 and 192.168.2.98.  When logged onto the server at the second site (subnet 192.168.4.0/24), we can not ping or tracert the ‘2.8 address but can do both to the ‘2.98 address. I was also able to ping a half dozen addresses on servers between ‘2.2 and ‘2.10 and a few workstations in a higher range. We logged onto the router/firewall and could see in its logs that Outlook would fail to connect to ‘2.8, then successfully connect to ‘2.98. Can’t find anything on the firewall blocking traffic to ‘2.8. I checked the DNS server and both addresses are present.
Can anyone venture a theory on why ‘2.8 address is unreachable from the second site?
0
Comment
Question by:YMartin
  • 5
  • 4
  • 3
  • +1
15 Comments
 
LVL 26

Expert Comment

by:Soulja
ID: 36581698
Why are both nic on the same subnet? They should not be. It basically sounds like the .98 is the server's preferred network interface. You can change the order of preference in advanced setting under network properties.
0
 
LVL 1

Author Comment

by:YMartin
ID: 36582537
I can't find "preferred network interface" anywhere. I tried to google it, in hopes of finding a step-by-step, but every hit is referring to clusters or Hyper-V. We aren't running any of that. It is just server 2008 R2 hosting Exchange Server. The hardware came with 4 NICs, we decided to plug 2 of them into the network and let DNS' round-robin function provide the load balancing.
0
 
LVL 26

Expert Comment

by:Soulja
ID: 36582549
Here you go:

http://theregime.wordpress.com/2008/03/04/how-to-setview-the-nic-bind-order-in-windows/

I meant to say binding order, just couldn't think of the term at that moment.
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 
LVL 1

Author Comment

by:YMartin
ID: 36589253
I changed the binding order yesterday (and since I learned something new - I went home). This afternoon, I logged onto the server at the second site and pinged the exchange server by name; it returned the .8 address but timed out 4 times. I pinged the .8 address - same result. Tracert 192.168.3.8 times out after 30 hops.  I am able to ping the .98 address and tracert completes in 1 hop. Tracert to the name also times out.
Prior to changing the bind order, ping or tracert to the server by name would have gone to the .98 address. No one at the site is complaining of not getting their emails, so I imagine that they are still connecting to the .98 address.
Still a mystery.
0
 
LVL 26

Expert Comment

by:Soulja
ID: 36589297
Not really, you should not have both interfaces on the same subnet in the first place. Change the subnet of the second nic and put it on a different  network. Otherwise, just disable it, or set up a nic team if the option is available.
0
 
LVL 1

Author Comment

by:YMartin
ID: 36589754
At the 1st site we have another server, named vserver, with 2 NICs on the same subnet. From the 2nd site I can ping vserver by name and by both of its IP addresses - .4 and .6. Doesn't seem to be a problem with that server having 2 NICs and 2 IP addresses on the same subnet.
I also logged onto 2 servers at the 1st site - the TS and DC servers. I pinged exchange and vserver by name from each and got a different IP address each time - indicating that DNS round robin function is working within the site and no problem with the NIC with the .8 address.
Only problem that we are having is reaching the .8 address from the 2nd site.
0
 
LVL 26

Expert Comment

by:Soulja
ID: 36589773
Hmmm, weird.
0
 
LVL 43

Accepted Solution

by:
Steve Knight earned 500 total points
ID: 36713167
Silly Q perhaps but have you got the subnet mask or default gateway set wrongly on the ".8" NIC? Could you post the results from ipconfig /all and route print please:
e.g.
ipconfig /all > file.txt
route print >> file.txt
0
 
LVL 43

Expert Comment

by:Steve Knight
ID: 36713175
Presumably if you disable the second (.98) nic on the exchange box you can't then ping anything on the 4.x network either?
0
 
LVL 16

Expert Comment

by:SteveJ
ID: 36719504
Agree with dragon-it .  .  .verify gateway , mask, next hop
0
 
LVL 1

Author Comment

by:YMartin
ID: 36904849
Dragon-it,
Brilliant! The gateway was missing. Don't know how many sets of eyes looked at that how many times without catching it.
I added the gateway, logged into the second site and am able to ping both IP addresses. Hate when I miss something that simple.
thank you, thank you, thank you.
0
 
LVL 1

Author Closing Comment

by:YMartin
ID: 36904871
Missing gateway.
0
 
LVL 43

Expert Comment

by:Steve Knight
ID: 36905404
no problem.... Firewalls excepting tcip is  pretty simple beast so best to start with the basics :-)  easy to miss to be fair as only issue from outside subnet of course and you already had another route to the internet..

Steve
0

Featured Post

Free Tool: Path Explorer

An intuitive utility to help find the CSS path to UI elements on a webpage. These paths are used frequently in a variety of front-end development and QA automation tasks.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
using BGP Attributes 2 108
Sonicwall SHA issue 4 40
Hit router interface limit 7 37
SonicWall NSA 3600, Geo-IP Filter & blocking sites 2 34
Problem Description:   Couple of months ago we upgraded the ADSL line at our branch office from Home to Business line. The purpose of transforming the service to have static public IP’s. We were in need for public IP’s to publish our web resour…
The Cisco RV042 router is a popular small network interfacing device that is often used as an internet gateway. Network administrators need to get at the management interface to make settings, change passwords, etc. This access is generally done usi…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

856 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question