The online racing simulator
#1 - SJB
my servers "could not connect to master server" since 2 days
Hi!

My dedicated was moved from Frankfurt to Strasbourg at Wednesday morning, and now it says everytime "Could not connect to master server"

But i dont know why... I can ping the master server, trace it, nmap says master server port is "open/filtered"... I dont know what to check next??

I hope someone can help me

Regards, SJB

Quote :...
Oct 29 02:47:09 Blackwood
Oct 29 02:47:09 end of initialisation
Oct 29 02:50:19 Could not connect to master server

Quote :PING master.liveforspeed.net (213.40.20.2) 56(84) bytes of data.
64 bytes from beta.lfs.net (213.40.20.2): icmp_seq=1 ttl=51 time=36.6 ms
64 bytes from beta.lfs.net (213.40.20.2): icmp_seq=2 ttl=51 time=36.6 ms
64 bytes from beta.lfs.net (213.40.20.2): icmp_seq=3 ttl=51 time=36.9 ms
64 bytes from beta.lfs.net (213.40.20.2): icmp_seq=4 ttl=51 time=36.7 ms
64 bytes from beta.lfs.net (213.40.20.2): icmp_seq=5 ttl=51 time=36.7 ms
64 bytes from beta.lfs.net (213.40.20.2): icmp_seq=6 ttl=51 time=36.6 ms
64 bytes from beta.lfs.net (213.40.20.2): icmp_seq=7 ttl=51 time=36.7 ms
64 bytes from beta.lfs.net (213.40.20.2): icmp_seq=8 ttl=51 time=36.4 ms
64 bytes from beta.lfs.net (213.40.20.2): icmp_seq=9 ttl=51 time=36.6 ms
64 bytes from beta.lfs.net (213.40.20.2): icmp_seq=10 ttl=51 time=36.5 ms

--- master.liveforspeed.net ping statistics ---
10 packets transmitted, 10 received, 0% packet loss, time 9012ms
rtt min/avg/max/mdev = 36.488/36.685/36.922/0.280 ms

Quote :traceroute to master.liveforspeed.net (213.40.20.2), 64 hops max, 40 byte packets
1 static-ip-85-25-57-17.inaddr.intergenia.de (85.25.57.17) 0 ms 0 ms 0 ms
2 217.118.16.37 (217.118.16.37) 18 ms 18 ms 18 ms
3 ve498.bbr1.fra3.inetbone.net (83.220.157.37) 18 ms 18 ms 18 ms
4 ve3001.bbr2.dus1.de.inetbone.net (213.203.213.67) 22 ms 22 ms 22 ms
5 unknown.inetbone.net (213.203.213.178) 22 ms 22 ms 22 ms
6 r1.lon1.uk.as5580.net (80.94.64.94) 33 ms 44 ms 33 ms
7 10ge-b224-linx.spn.kcom.com (195.66.224.70) 117 ms amsix.g4-4.lon-th1br.mistral.net (195.69.144.249) 31 ms 103 ms
8 86.54.183.205 (86.54.183.205) 37 ms 36 ms 37 ms
9 lds01-ge-lds02.core.netline.net.uk (212.111.131.21) 37 ms 36 ms 36 ms
10 ldscat01-ge-lds01.core.netline.net.uk (213.40.3.73) 37 ms 36 ms 36 ms
11 beta.lfs.net (213.40.20.2) 37 ms 36 ms 36 ms

Quote :nmap -p8080,29339 -PN master.liveforspeed.net

Starting Nmap 4.62 ( http://nmap.org ) at 2010-10-29 02:00 UTC
Interesting ports on beta.lfs.net (213.40.20.2):
PORT STATE SERVICE
8080/tcp filtered http-proxy
29339/tcp filtered unknown

How is the server set up? IE is it one you're paying for and it's being hosted by a company, or is it a personal one that you're hosting and managing yourself? What is different about this new site in terms of setup?

Have no configuration changes been made on the Dedi? It would seem to me like a firewal/port issue? As long as ICMP ping isn't blocked/disabled by the Dedi server/firewall you will be able to ping and tracert is basically just a ping but shows which routers it's going through.

Also am I right in assuming you were running pings and tracerts etc from the Dedicated Server?
#3 - SJB
Hi!

Its a linux root server, and I manage the LFS Servers myself on it.

I checked the Firewall, incoming the LFS Server Ports are free and outgoing is all allowed.

Yep i did the pings and traceroute from my root.

And nmap says the master server ports are "filtered".

Did not change the config, they turned my server off, after 4hours moving, on again, 1hour later i started the LFS Servers and had the master server problem

I'm really clueless whats the problem

Regards, SJB
May be complicated but if possible reset all network settings and start from scratch, sounds like a config issue to me.
#5 - SJB
I got an public ip and i cant change that, only thing is the firewall of my server, which allows outgoing traffic and imcoming for lfs ports.

Regards, SJB
#6 - SJB
Okay, i remembered an method to look if my server contacts the master. It talks to the master, but again "Oct 29 18:51:08 Could not connect to master server"

Regards, SJB

Quote :tcpdump host master.liveforspeed.net
18:47:59.798747 IP ***.vserver.de.47356 > beta.lfs.net.29339: S 4015430939:4015430939(0) win 5840 <mss 1460,sackOK,timestamp 233004308 0,nop,wscale 2>
18:47:59.837996 IP beta.lfs.net.29339 > ***.vserver.de.47356: S 3452681838:3452681838(0) ack 4015430940 win 65535 <mss 1460,nop,wscale 3,sackOK,timestamp 1284040848 233004308>
18:48:02.797473 IP ***.vserver.de.47356 > beta.lfs.net.29339: S 4015430939:4015430939(0) win 5840 <mss 1460,sackOK,timestamp 233007308 0,nop,wscale 2>
18:48:02.836318 IP beta.lfs.net.29339 > ***.vserver.de.47356: S 3452681838:3452681838(0) ack 4015430940 win 65535 <mss 1460,nop,wscale 3,sackOK,timestamp 1284040848 233007308>
18:48:05.902879 IP beta.lfs.net.29339 > ***.vserver.de.47356: S 3452681838:3452681838(0) ack 4015430940 win 65535 <mss 1460,nop,wscale 3,sackOK,timestamp 1284040848 233007308>
18:48:08.796430 IP ***.vserver.de.47356 > beta.lfs.net.29339: S 4015430939:4015430939(0) win 5840 <mss 1460,sackOK,timestamp 233013308 0,nop,wscale 2>
18:48:08.834806 IP beta.lfs.net.29339 > ***.vserver.de.47356: S 3452681838:3452681838(0) ack 4015430940 win 65535 <mss 1460,nop,wscale 3,sackOK,timestamp 1284040848 233013308>
18:48:11.901920 IP beta.lfs.net.29339 > ***.vserver.de.47356: S 3452681838:3452681838(0) ack 4015430940 win 65535 <mss 1460,nop,wscale 3,sackOK,timestamp 1284040848 233013308>
18:48:18.032301 IP beta.lfs.net.29339 > ***.vserver.de.47356: S 3452681838:3452681838(0) ack 4015430940 win 65535 <mss 1460,nop,wscale 3,sackOK,timestamp 1284040848 233013308>
18:48:20.795533 IP ***.vserver.de.47356 > beta.lfs.net.29339: S 4015430939:4015430939(0) win 5840 <mss 1460,sackOK,timestamp 233025308 0,nop,wscale 2>
18:48:20.833691 IP beta.lfs.net.29339 > ***.vserver.de.47356: S 3452681838:3452681838(0) ack 4015430940 win 65535 <mss 1460,nop,wscale 3,sackOK,timestamp 1284040848 233025308>
18:48:23.898308 IP beta.lfs.net.29339 > ***.vserver.de.47356: S 3452681838:3452681838(0) ack 4015430940 win 65535 <mss 1460,nop,wscale 3,sackOK,timestamp 1284040848 233025308>
18:48:30.029790 IP beta.lfs.net.29339 > ***.vserver.de.47356: S 3452681838:3452681838(0) ack 4015430940 win 65535 <mss 1460,nop,wscale 3,sackOK,timestamp 1284040848 233025308>
18:48:42.289413 IP beta.lfs.net.29339 > ***.vserver.de.47356: S 3452681838:3452681838(0) ack 4015430940 win 65535 <mss 1460,nop,wscale 3,sackOK,timestamp 1284040848 233025308>
18:48:44.791053 IP ***.vserver.de.47356 > beta.lfs.net.29339: S 4015430939:4015430939(0) win 5840 <mss 1460,sackOK,timestamp 233049308 0,nop,wscale 2>
18:48:44.829715 IP beta.lfs.net.29339 > ***.vserver.de.47356: S 3452681838:3452681838(0) ack 4015430940 win 65535 <mss 1460,nop,wscale 3,sackOK,timestamp 1284040848 233049308>
18:48:47.891589 IP beta.lfs.net.29339 > ***.vserver.de.47356: S 3452681838:3452681838(0) ack 4015430940 win 65535 <mss 1460,nop,wscale 3,sackOK,timestamp 1284040848 233049308>
18:48:54.018976 IP beta.lfs.net.29339 > ***.vserver.de.47356: S 3452681838:3452681838(0) ack 4015430940 win 65535 <mss 1460,nop,wscale 3,sackOK,timestamp 1284040848 233049308>
18:49:06.273001 IP beta.lfs.net.29339 > ***.vserver.de.47356: S 3452681838:3452681838(0) ack 4015430940 win 65535 <mss 1460,nop,wscale 3,sackOK,timestamp 1284040848 233049308>
18:49:32.784479 IP ***.vserver.de.47356 > beta.lfs.net.29339: S 4015430939:4015430939(0) win 5840 <mss 1460,sackOK,timestamp 233097308 0,nop,wscale 2>

#7 - SJB
Okay i tried again and turned the firewall from my server off for 2minutes (server firewall should be never off )

And it worked, after 2Secs it was visible at LFSworld.net

Something of the firewall is blocking the master server connection, but port check for 63392 says always its opened when firewall is active???

Quote :-P INPUT DROP
-P FORWARD ACCEPT
-P OUTPUT ACCEPT
-N ip-xxx.xxx.xxx.xxx-INPUT
-A INPUT -j ip-xxx.xxx.xxx.xxx-INPUT
-A ip-xxx.xxx.xxx.xxx-INPUT -d xxx.xxx.xxx.xxx/32 -p tcp -m tcp --dport *** -j ACCEPT
-A ip-xxx.xxx.xxx.xxx-INPUT -d xxx.xxx.xxx.xxx/32 -p tcp -m tcp --dport ***:*** -j ACCEPT
-A ip-xxx.xxx.xxx.xxx-INPUT -d xxx.xxx.xxx.xxx/32 -p tcp -m tcp --sport ***:*** ! --tcp-flags FIN,SYN,RST,ACK SYN -j ACCEPT
-A ip-xxx.xxx.xxx.xxx-INPUT -d xxx.xxx.xxx.xxx/32 -p tcp -m tcp --dport *** -j ACCEPT
-A ip-xxx.xxx.xxx.xxx-INPUT -d xxx.xxx.xxx.xxx/32 -p tcp -m tcp --dport 80 -j ACCEPT
-A ip-xxx.xxx.xxx.xxx-INPUT -d xxx.xxx.xxx.xxx/32 -p tcp -m tcp --dport *** -j ACCEPT
-A ip-xxx.xxx.xxx.xxx-INPUT -d xxx.xxx.xxx.xxx/32 -p tcp -m tcp --dport *** -j ACCEPT
-A ip-xxx.xxx.xxx.xxx-INPUT -d xxx.xxx.xxx.xxx/32 -p tcp -m tcp --dport *** -j ACCEPT
-A ip-xxx.xxx.xxx.xxx-INPUT -d xxx.xxx.xxx.xxx/32 -p udp -m udp --sport *** -j ACCEPT
-A ip-xxx.xxx.xxx.xxx-INPUT -d xxx.xxx.xxx.xxx/32 -p udp -m udp --sport *** -j ACCEPT
-A ip-xxx.xxx.xxx.xxx-INPUT -d xxx.xxx.xxx.xxx/32 -p icmp -j ACCEPT
-A ip-xxx.xxx.xxx.xxx-INPUT -s ***.***.***.***/32 -d xxx.xxx.xxx.xxx/32 -p tcp -m tcp --sport *** -j ACCEPT
-A ip-xxx.xxx.xxx.xxx-INPUT -d xxx.xxx.xxx.xxx/32 -p udp -m udp --dport 9987 -j ACCEPT
-A ip-xxx.xxx.xxx.xxx-INPUT -d xxx.xxx.xxx.xxx/32 -p tcp -m tcp --dport 63392:63394 -m state --state NEW -j ACCEPT
-A ip-xxx.xxx.xxx.xxx-INPUT -d xxx.xxx.xxx.xxx/32 -p udp -m udp --dport 63392:63394 -m state --state NEW -j ACCEPT
-A ip-xxx.xxx.xxx.xxx-INPUT -d xxx.xxx.xxx.xxx/32 -p tcp -m tcp --dport 63392 -m state --state NEW -j ACCEPT
-A ip-xxx.xxx.xxx.xxx-INPUT -d xxx.xxx.xxx.xxx/32 -p udp -m udp --dport 63392 -m state --state NEW -j ACCEPT

#8 - SJB
it works now, my x years old firewall rule was not saved, so it wasnt there after the "reboot"...

I added
Quote :iptables -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT

now and it works again - but this shows, LFS needs more ports incoming than just the server port e.g. 63392

Regards, SJB
#9 - SJB
it works to connect etc, but when a second person comes online u cant see him driving - I think I read about it on the wine problem threads "ghost drivers"

I think I played to much with different wine version when i tried to fix the master server problem...
Quote from SJB :it works now, my x years old firewall rule was not saved, so it wasnt there after the "reboot"...

I addednow and it works again - but this shows, LFS needs more ports incoming than just the server port e.g. 63392

Regards, SJB

At least it works now. (Hasten to say that's what I said it was previous!! Woohoo) I only do Network stuff so can't really suggest a reason as to why other drivers don't appear. Perhaps it's a bug with the version of LFS or something...not sure.
#11 - SJB
Quote :iptables -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT

I modified this for tcp only and forgot to set it for udp too

Servers are up and running again (without ghosts) since 31st October


And when your Insim cant connect to lfs server "localhost" make sure u accept all from interface "lo" = localhost, when the default policy is INPUT=DROP

Regards, SJB

FGED GREDG RDFGDR GSFDG