Customer cannot access their sites / Control Panel

Ref Ticket ETV-91282-151

Wanted to see if anyone else has seen this or a similar problem. Jodohost support replied that we should contact the ISP, which we have and have not gotten anywhere.

Here is the issue:

I have a customer who can no longer get to his websites from his home PC. From any browser (Firefox, IE) the sites in question simply time out and say the page cannot be displayed.

I can see them OK from other locations.

He is on AT&T DSL in the Atlanta, Georgia area with a persistent IP address.

I had him perform a trace route and it times out when it gets down to the Miami datacenter (best I can tell).

Please see the attached screen shot of the trace route.

We have been working with AT&T on this end, but have not gotten anywhere.

He can see other sites hosted on other servers at Jodohost, so it seems to be related to his IP and the particular server that his sites are hosted on.

The sites in question are:

www.nationalsuperbike.com
www.souldout.org
www.slashfit.com

All are Wordpress blogs hosted on the same shared server within my reseller account.

He also cannot get into his web hosting control panel.

His persistent IP address is listed in the traceroute - it is the IP listed after the 192.168.xx address.

Any help would be appreciated. So far he has been on the phone for a total of 4 hours with AT&T with no resolution. Just trying to determine where the problem is exactly.

Thanks,
Dan

http://www.fusioncomputing.com/images/curttraceroute.jpg

I am moving this to Customers Only so it doesn’t hit google with any private info, I have added you as a customer, but please send me a private message with your reseller ID so I can document it.

Thanks, checking into issue.

We can ping and trace most of the way back to this IP :frowning:

This is the oddest issue, a couple reports of it in Bell Canada, Roadrunner midwest, and now ATT, but routing looks fine, no blocks on the servers for the IP. almost like some sort of content filtering on these IPs is killing it! but we don’t allow bad content, adult, spam, etc so it should never be blocked as such, and the fact we can trace and ping back is really baffling.

This is from the server that the sites are hosted on:
PING 65.14.248.16 (65.14.248.16) 56(84) bytes of data.
64 bytes from 65.14.248.16: icmp_seq=0 ttl=52 time=17.5 ms
64 bytes from 65.14.248.16: icmp_seq=1 ttl=52 time=18.0 ms
64 bytes from 65.14.248.16: icmp_seq=2 ttl=52 time=17.3 ms
64 bytes from 65.14.248.16: icmp_seq=3 ttl=52 time=17.8 ms

— 65.14.248.16 ping statistics —
4 packets transmitted, 4 received, 0% packet loss, time 3007ms
rtt min/avg/max/mdev = 17.305/17.687/18.066/0.290 ms, pipe 2

trace
traceroute to 65.14.248.16 (65.14.248.16), 30 hops max, 38 byte packets
1 64.71.235.254 (64.71.235.254) 6.901 ms 3.449 ms 2.312 ms
2 64.71.225.25 (64.71.225.25) 0.457 ms 0.563 ms 0.482 ms
3 ibgp.border1.nota.mia.webhosting.net (64.71.226.33) 2.419 ms 0.573 ms *
4 border5.ge1-4.webhosting-12.mia003.pnap.net (216.52.162.65) 0.626 ms 0.530 ms 0.528 ms
5 core3.t6-2.bbnet2.mia003.pnap.net (69.25.0.67) 0.546 ms 0.603 ms 0.551 ms
6 12.118.175.81 (12.118.175.81) 15.388 ms 15.278 ms 15.257 ms
7 cr1.ormfl.ip.att.net (12.122.143.30) 16.203 ms 15.888 ms 15.621 ms
MPLS Label=16780 CoS=6 TTL=255 S=0
8 cr2.attga.ip.att.net (12.122.31.29) 16.109 ms 15.495 ms 15.692 ms
MPLS Label=0 CoS=6 TTL=255 S=0
MPLS Label=16747 CoS=0 TTL=255 S=0
9 cr84.attga.ip.att.net (12.123.22.250) 16.407 ms 16.115 ms 15.718 ms
MPLS Label=17101 CoS=6 TTL=255 S=0
10 gar25.attga.ip.att.net (12.122.140.17) 15.667 ms 15.233 ms 15.069 ms
11 * 65.83.238.201 (65.83.238.201) 28.939 ms 15.668 ms
12 12.83.0.180 (12.83.0.180) 17.076 ms 16.685 ms 16.394 ms
MPLS Label=16054 CoS=6 TTL=255 S=0
13 12.83.2.118 (12.83.2.118) 16.984 ms 16.671 ms 16.379 ms
MPLS Label=16054 CoS=6 TTL=255 S=0
14 12.83.2.157 (12.83.2.157) 16.727 ms 16.669 ms 16.310 ms
15 * * *
16 * * *
17 * * *
18 * * *
19 * * *
20 * * *

I’ve found the only way we will really be able to diagnose this is with a layer four traceoute, which I cannot find a windows xp sp2+ client that will do as such.

A layer 4 traceroute allows you to doa trace over port 80(webserver port) to see exactly where it quits to find where blocks happen.

Stephen,

Thanks for looking into this. If I have to, I will take my Macbook to this customer’s location and see if I can do a layer 4 traceroute. I won’t be able to do this until this weekend at earliest, though.

-Dan

There IS a mac client for layer 4 traceroute, so that could work out.

You’d need to use it and traceroute over port 80.

My customer spent another hour on the phone today with AT&T - this time he had a level 3 tech on the phone. The tech said there was nothing that AT&T was doing to block access on their end. He believes the IP is being blocked at the data center side.

This is strange to me, because it seems like it is just this one server - my customer can see other sites on Jodohost servers in the same datacenter.

The tech recommended that he switch from a persistent IP to a dynamic one, but that has to be done by AT&T sales, and they are closed until Saturday due to the New Year’s holiday.

I’ll try to get a Layer 4 traceroute this weekend and let you know what I see.

-Dan

nothing blocked this side, we’ve checked that as well…just to confirm

I ran some trace routes from my customer’s network using Path Analyzer Pro on my Mac. The only protocol that would show anything beyond the router was ICMP.

The last message when tracing to nationalsuperbike.com is “No reply packets received after TTL 15. You may try changing settings”

The output from Path Analyzer Pro shows it stopping at 64.71.225.26, which is the same point it stopped in the screenshot above.

When I trace to other sites I also host (which my customer can see) it gets right past the above IP address to the server.

I’m not sure what is at that IP address, but that is where it seems to stop.

Any ideas?

That is our router but it isn’t blocked there or after it, and it pings ont eh way back properly, very odd situation.

Here is the trace route attached as a (zipped) csv file. Not sure if it provides any more information or not.

Can we try moving the sites to a different server? Is that something your linux team can do easily?

traceroute1.csv.zip (854 Bytes)

A migration can be done from admin cp, will need a ticket.

JodoHost Support:

Ref Ticket: ETV-91282-151

When can I expect an update on this? I requested the sites to be moved to a new server - it is my understanding that you can do this easily within the Admin CP on your end.

If this is not true, or if you cannot move them, please let me know. We are at a dead end here with AT&T - the only option we can determine on this side is to switch my client to a dynamic IP.

That is not the best solution for him (did not want to give up his persistent IP), but as of right now he does not have access to his websites from his network.

I understand this is a strange problem and that you have many customers to support. However, I just need to know what you want me to do.

Thanks,
Dan

Ticket replied. We will do the move for you. We have removed many blocks from this web server, but nothing seems to help this case.