Bon, si tu as le retour du ping, c’est bizarre que le MAC ne te dit pas que tout va bien.
Maintenant, fais la chose suivante:
[edit: tu peux faire aussi un ping 82.66.248.254 ou autre appel vers l’extérieur au lieu de tester google]
Sur srvweb
tcpdump -i eth1
et sur le MAC, une connexion HTTP. Regardes si tu as un échange de ce style:
[quote]18:51:29.149430 totoche.rebelles.32791 > dns1.proxad.net.domain: 4736+ A? google.com. (32) (DF)
18:51:29.194557 dns1.proxad.net.domain > totoche.rebelles.32791: 4736- 2/0/0 CNAME l.google.com., (68) (DF)
18:51:29.195012 totoche.rebelles.34393 > 66.249.93.104.www: S 1087487198:1087487198(0) win 5840 <mss 1460,sackOK,timestamp 2851928 0,nop,wscale 0> (DF)
18:51:29.287165 66.249.93.104.www > totoche.rebelles.34393: S 347562321:347562321(0) ack 1087487199 win 8190 <mss 1460>
18:51:29.287436 totoche.rebelles.34393 > 66.249.93.104.www: . ack 1 win 5840 (DF)
18:51:29.287901 totoche.rebelles.34393 > 66.249.93.104.www: P 1:426(425) ack 1 win 5840 (DF)
18:51:29.361076 66.249.93.104.www > totoche.rebelles.34393: . ack 426 win 7765
18:51:29.361781 66.249.93.104.www > totoche.rebelles.34393: . ack 426 win 6432
18:51:29.380337 66.249.93.104.www > totoche.rebelles.34393: P 1:398(397) ack 426 win 6432
18:51:29.380984 totoche.rebelles.34393 > 66.249.93.104.www: . ack 398 win 6432 (DF)
18:51:29.382130 totoche.rebelles.32791 > dns1.proxad.net.domain: 4737+ A? google.fr. (31) (DF)
18:51:29.428882 dns1.proxad.net.domain > totoche.rebelles.32791: 4737- 2/0/0 CNAME[|domain] (DF)
18:51:29.429346 totoche.rebelles.34394 > 66.249.93.99.www: S 1092113936:1092113936(0) win 5840 <mss 1460,sackOK,timestamp 2851952 0,nop,wscale 0> (DF)
18:51:29.492896 66.249.93.99.www > totoche.rebelles.34394: S 4149914471:4149914471(0) ack 1092113937 win 8190 <mss 1460>
18:51:29.493169 totoche.rebelles.34394 > 66.249.93.99.www: . ack 1 win 5840 (DF)
18:51:29.493637 totoche.rebelles.34394 > 66.249.93.99.www: P 1:425(424) ack 1 win 5840 (DF)
18:51:29.567052 66.249.93.99.www > totoche.rebelles.34394: . ack 425 win 7766
18:51:29.568343 66.249.93.99.www > totoche.rebelles.34394: . ack 425 win 6432
18:51:29.682483 66.249.93.99.www > totoche.rebelles.34394: . 1:1431(1430) ack 425 win 6432
18:51:29.684075 totoche.rebelles.34394 > 66.249.93.99.www: . ack 1431 win 8580 (DF)
…[/quote]
Où si seulement un bout passe
Puis si tu n’as qu’un sens, vérifie que si tu fais
tcpdump -i eth0
Tu as bien l’adresse de srvweb qui s’est substituée l’adresse de ton MAC avec un échange de ce type:
[quote]18:54:50.755468 [TON SRVWEB].59872 > dns1.proxad.net.domain: 54361+ A? mir3.ovh.net. (30) (DF)
18:54:50.756593 [TON SRVWEB].59873 > dns2.proxad.net.domain: 49675+ PTR? 252.53.27.212.in-addr.arpa. (44) (DF)
18:54:50.803056 dns2.proxad.net.domain > [TON SRVWEB].59873: 49675- 1/0/0 (73) (DF)
18:54:50.803132 dns1.proxad.net.domain > [TON SRVWEB].59872: 54361- 1/0/0 A mir3.ovh.net (46) (DF)
18:54:50.806659 [TON SRVWEB].59873 > dns2.proxad.net.domain: 49676+ PTR? 91.33.186.213.in-addr.arpa. (44) (DF)
18:54:50.833777 [TON SRVWEB].33206 > mir3.ovh.net.ftp: S 2559708680:2559708680(0) win 5840 <mss 1460,sackOK,timestamp 992085918 0,nop,wscale 0> (DF)
18:54:50.852589 dns2.proxad.net.domain > [TON SRVWEB].59873: 49676- 1/0/0 (70) (DF)
18:54:50.852658 dns2.proxad.net.domain > [TON SRVWEB].59873: 49676 ServFail- 0/0/0 (44) (DF)
18:54:50.878381 mir3.ovh.net.ftp > [TON SRVWEB].33206: S 349186328:349186328(0) ack 2559708681 win 5792 <mss 1460,sackOK,timestamp 926278050 992085918,nop,wscale 0> (DF)
18:54:50.878761 [TON SRVWEB].33206 > mir3.ovh.net.ftp: . ack 1 win 5840 <nop,nop,timestamp 992085922 926278050> (DF)
18:54:50.925988 mir3.ovh.net.ftp > [TON SRVWEB].33206: P 1:37(36) ack 1 win 5792 <nop,nop,timestamp 926278055 992085922> (DF)
18:54:50.926347 [TON SRVWEB].33206 > mir3.ovh.net.ftp: . ack 37 win 5840 <nop,nop,timestamp 992085927 926278055> (DF)
18:54:50.928441 [TON SRVWEB].33206 > mir3.ovh.net.ftp: P 1:17(16) ack 37 win 5840 <nop,nop,timestamp 992085927 926278055> (DF)
18:54:50.973266 mir3.ovh.net.ftp > [TON SRVWEB].33206: . ack 17 win 5792 <nop,nop,timestamp 926278060 992085927> (DF)
18:54:50.973351 mir3.ovh.net.ftp > [TON SRVWEB].33206: P 37:71(34) ack 17 win 5792 <nop,nop,timestamp 926278060 992085927> (DF)
18:54:50.975423 [TON SRVWEB].33206 > mir3.ovh.net.ftp: P 17:59(42) ack 71 win 5840 <nop,nop,timestamp 992085932 926278060> (DF)
[/quote]