Re: Ping reply through the same interface



1. You didn't give the mask. These have to be in two different subnets.
You are *not* supposed to have two nics in the same subnet unless they are
"Teamed".

2. If they are in the same subnet they will not work as you want.

3. If they are in different subnet they will work as you want and there is
nothing for you to do to make it happen.

4. If the source of the Ping is not in the same subnet as the nic it pinged
it will not work as you want and the server will reply on from the nic that
is associated with the Default Gateway. This is the same thing that will
happen if you use the same source machine for both of the "pings". That is
the way TCP/IP works. That is the way it is supposed to be,...you can't
change it,...it has nothing to do with Windows.

Routes leaving the server are determined by the Destination and how the
Destination fits into the Routing Table,...it has nothing to do with the nic
that received the "ping". The incomming ICMP packet and the outbound ICMP
Reply can,..and very often do,...take two different paths. That is why Ping
is not used to trace routing pathes,...that is what Tracert (Trace Route) or
Path-Ping are for. But even they may not take the same path for the
reply,...they overcome that by taking information about the object that was
pinged on that particular hop and packaging it in the Reply,..however the
Reply itself may take a completey different path.


--
Phillip Windell
www.wandtv.com

The views expressed, are my own and not those of my employer, or Microsoft,
or anyone else associated with me, including my cats.
-----------------------------------------------------
Understanding the ISA 2004 Access Rule Processing
http://www.isaserver.org/articles/ISA2004_AccessRules.html

Troubleshooting Client Authentication on Access Rules in ISA Server 2004
http://download.microsoft.com/download/9/1/8/918ed2d3-71d0-40ed-8e6d-fd6eeb6cfa07/ts_rules.doc

Microsoft Internet Security & Acceleration Server: Partners
http://www.microsoft.com/isaserver/partners/default.asp

Microsoft ISA Server Partners: Partner Hardware Solutions
http://www.microsoft.com/forefront/edgesecurity/partners/hardwarepartners.mspx
-----------------------------------------------------

"Dmitry Perets" <Dmitry.Perets@xxxxxxxxx> wrote in message
news:1188464912.119500.45940@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Hello,

My server has two interfaces. Let's say, 10.10.10.1 and 10.10.11.1.
Now, I have a collection station which probes these interfaces using
ICMP (to determine that they are up). When this station pings these
interfaces, I want the reply to be sent through the same interface
from which it received ping request. That is, if the station pings
10.10.10.1 then I want the server to reply through 10.10.10.1. And if
the station pings 10.10.11.1, I want it to reply through 10.10.11.1.

The reason is that there are stateful firewalls between the station
and the server, so that when a ping request travels towards
10.10.10.1, it passes through one firewall, and then the reply (which
goes through 10.10.11.1) passes through ANOTHER firewall, which of
course blockes the reply, because it has no idea about the appropriate
session.

The server is running Windows NT 4. Another one (with the same issue)
is running Windows 2000 Advanced Server.
Is there any way to make Windows reply to ping through the same
interface from which it receives the request?

Thank you.



.



Relevant Pages

  • Re: Dynamic DNS and failed journal
    ... changed control clause to be updated by localhost and server ... i thought it was odd too....but in retrospect, it means to listen on 127.0.0.1 and any other NICS using 192.168.10.0/24 netowrk that may be in the box ... ... I would have thought allow-wuery would have been ok with an acl ... ... had to be done outside of the subnet clauses. ...
    (Fedora)
  • Re: Help!! Web Server outage - ping failure
    ... :I have a Windows 2003 web server running IIS sitting behind a pix 506. ... Why would you allow ping responses from your router, ... Did you try the NICs in other ...
    (microsoft.public.inetserver.iis)
  • Re: Default Gateway Reverts to Old Setting
    ... This server is on the only IP subnet at the client's main office. ... The server has two identical 10/100/1000 NICs, ... TCP/IP is the only network protocol installed. ...
    (microsoft.public.windows.server.networking)
  • Re: Problem using Remoting with 2 NICs
    ... I agree with you on the 2 NIC's with same subnet being a bad idea. ... Setting the http channels useIpAddress property to false on the server fixed ... I have clients connecting successfully on NIC 1, ... When both NICs are enabled. ...
    (microsoft.public.dotnet.framework.remoting)
  • Re: Multihomed server 2000
    ... I have a server with 2 NICs; ... and everything on this NIC is normal and active; I can ping it ... for 192.168.200 to the RRAS router. ...
    (microsoft.public.windows.server.networking)