Ask Your Question
0

Trouble reaching IPv4 websites

asked 2020-06-05 09:41:08 +0000

BioTo gravatar image

updated 2020-06-05 09:52:34 +0000

Hi everybody!

I have some trouble with reaching IPv4 websites every now and then. My internet connection is via "Unitymedia" so meaning Coax-Cable. As long as i am connected, everything is fine. Speed is good, connection is stable.

But every 1-3 Days (seems randomly) i am not able to connect to any IPv4 website. When i do a IPv4 check, i don't have any IPv4. Of course i reached out for my ISP, but they couldn't find out any issue from their side. I changed my router, for checking if there is a problem, but it doesn't change anything...error still occurs. I searched and searched and searched but couldn't find any solution (or maybe didn't understand)...and then downloaded Wireshark.

While the error occurs, and i start Wireshark its showing a message like:

"81.210.176.137 192.168.178.20 ICMP 106 Destination unreachable (Communication administratively filtered)"

This doesn't appear when i restart my router & the connection is "repaired".

Problem is: i have no clue what im seeing/where the problem is coming from. Is it my network? Or is it my ISP having an error?

Here is a link to an actual capture file: https://www.dropbox.com/s/snzo6uqrujc...

edit retag flag offensive close merge delete

Comments

Screenshots, and much more useful, capture files, can be added to a public share, e,g, Google Drive, DropBox etc. and a link to the file posted back here.

grahamb gravatar imagegrahamb ( 2020-06-05 09:47:28 +0000 )edit

True, thanks for the advice!

https://www.dropbox.com/s/snzo6uqrujc...

BioTo gravatar imageBioTo ( 2020-06-05 09:51:13 +0000 )edit

You now show the situation after it occurred, what happens before is unknown. What does trigger the administrative filter to kick in? What kind of traffic do you generate from your network out to the internet that's flagged? I can only assume the filters are dropped when your link drops, since this seems to resolve the situation temporarily.

Jaap gravatar imageJaap ( 2020-06-05 11:26:24 +0000 )edit

Yeh, you're probably right about that.

Of course there are several machines in the Network (2x Macbook, 2x iPhone, 1x Windows PC, 1x Panasonic TV). The strange thing is, all these machines have been in two other networks before (even all together and single) but with another ISP in a different city and there has never been any error.

But the fact, that contacting the ISP even while the error is still on and the hotline does not seem to find any error on their side they told me the error is probably within my home-network. Of course people on the hotline never heard of whireshark, nor have any idea of what's going on...

I just have to figure out, where the problem is: on my Homenetwork or on the ISP side.

If i get you right, i am blocked (for whatever reason) by my ISP and it ...(more)

BioTo gravatar imageBioTo ( 2020-06-05 13:13:02 +0000 )edit

I'm going to let Wireshark run through the night today, hoping that the error occurs again till tomorrow afternoon maybe. Im going to upload it asap.

BioTo gravatar imageBioTo ( 2020-06-05 13:20:20 +0000 )edit

I don't know who has the router with IPv4 address 81.210.176.137 which reports the filtering, but the DNS resolves to ip-81-210-176-137.hsi17.unitymediagroup.de so that suggests an ISP upstream from you.

Jaap gravatar imageJaap ( 2020-06-05 17:55:38 +0000 )edit

Thanks all for your replies so far!

I was lucky and Wireshark was running today in the morning while the error occurs.

Today, strangely, it had this error and after a while it just went to working normal. But that's not usual. I once waited more than 24h without a restart of my router but it wasn't working until i restarted. So usually i have to restart the router and then it works again.

What i forgot to mention is, that my ISP doesn't give me a native IPv4. I have a "Dual-Stack" IPv4. Sorry, to not to mention it, i guess its an important information for you helping me out!@Jaap: I think this is the router of my ISP. But im not aware of any uploading

Here is the link to the file: https://www.dropbox.com/s/0mwtbde61nv...

BioTo gravatar imageBioTo ( 2020-06-06 11:22:29 +0000 )edit

@BioTo: Due to the fact that only new IPv4 connections get blocked, and that your client reaches the end of the available IPv4 ports, I can imagine that a NAT device (probably your Fritz!Box) has no more free ports for NAT. You should doublecheck the open TCP connections and the program that is using them on your clients. Have you checked the IPv4 Internet connection status and the logs of your Fritz!Box when the issue occures? A packet capture from the Fritz!Box (https://192.168.178.1/html/capture.html) of the routing interface during the error could be also helpful.

BTW: Is it only your Apple client which is having the issue, or all devices in your LAN?

JasMan gravatar imageJasMan ( 2020-06-06 14:00:57 +0000 )edit

@JasMan thanks. I'm sorry to disappoint you about that capture thing. I've tried it, but as it seems the "experts" from Fritz have disabled this function in the up-to-date Fritz IOS! For wtf reason i don't know. How do i check the open TCP connections? Sorry, im really not a network expert... . Yes, i have checked the internet connection and error logs of the Fritzbox when the error occurs. There is no issue its saying. It even says, that it is connected. I added two screenshots for you. They're made some days ago, but it always is like this when the error occurs. https://www.dropbox.com/s/caqz1v11nup...https://www.dropbox.com/s/20v9mjigywd... . The error just pops up. Even while surfing, at the same website it just does stop to work. What is your opinion that there is something wrong with the AFTR of ...(more)

BioTo gravatar imageBioTo ( 2020-06-07 10:46:35 +0000 )edit

@BioTo: Strange, I'm using a FB7560 (VDSL) with v7.12 and the capture site is still available. You could try to access the page by going to Inhalt\Fritz!Box Support. But I'm not sure anymore if the capture will help, due your line is using DS-lite. So 81.210.176.137 is definitly a router of UM and not the IPv4 address of your FB. I thought your line uses fully DS. I saw that a lot of UM customers have the same issue as you. So I think we will be not able to help you, because it's a problem of the provider. Even if we find out that e.g. all NAT ports are in use, this will be something that only your provider can solve.

I was a customer of UM in the past. When I upgraded my contract to a higher bandwidth ...(more)

JasMan gravatar imageJasMan ( 2020-06-07 13:46:14 +0000 )edit

1 Answer

Sort by » oldest newest most voted
0

answered 2020-06-08 12:51:36 +0000

SYN-bit gravatar image

Thanks for your traces, I took a look and I'm under the impression that your provider is using Carrier Grade NAT (as you say native dual-stack costs extra) and that the first hop in the provider network has some issues.

The ICMP administratively prohibited messages indicate the device that is restricting your IPv4 access and if we can say for sure it is a device under their control, then supplying them with the packet captures should make the investigate and solve the issue.

Could you make a packet capture while you do the following?

  1. traceroute 8.8.8.8
  2. ping -R 8.8.8.8
  3. A web visit to https://www.myip.com/

Also, could you

  1. tell us how you are making your packet captures?
  2. The WAN ip address of your FB7560 (and does it change when you reboot your router?)
edit flag offensive delete link more

Comments

  1. ok, made a capture! https://www.dropbox.com/s/uvrqdfbjnvv...
    1. ping -R 8.8.8.8 gave me the message: Request timeout for icmp_seq xx (i let it run >100x)
    2. Im just starting Wireshark and then press the start button after a while im stopping it and save it. Not sure if that is the answer and if i got the question right!?
    3. In the FB menu there is only „AFTR-Gateway: 2a02:8070:2000::4000“ shown. My IPv4 91.89.90.xx (not sure if its safe to post the full IP here!?) does not change after i reboot the FB (which is a 6490 cable, not a 7560). It may change when i put the router down for a longer time. Im relatively sure, that it has changed before and is not always the same IP...
    4. „then supplying them with the packet captures should make the investigate and solve ...
(more)
BioTo gravatar imageBioTo ( 2020-06-08 13:36:47 +0000 )edit

Your Answer

Please start posting anonymously - your entry will be published after you log in or create a new account.

Add Answer

Question Tools

2 followers

Stats

Asked: 2020-06-05 09:41:08 +0000

Seen: 1,426 times

Last updated: Jun 08 '20