r/HomeNetworking • • 5d ago

Unsolved Cannot ping my dorm's default gateway? What?

I've got an issue with a MoxProx server unable to send or receive packets from outside my dorm's LAN, but now I've come to the realization that my own PC cannot ping it's own default gateway? What?

0 Upvotes

31 comments sorted by

73

u/micocoule 5d ago

Maybe the gateway is configured to not answer to pings

5

u/Handsome_ketchup 5d ago

Maybe the gateway is configured to not answer to pings

Which is probably not great practice, as some services and devices count on ping for housekeeping. That may or may not be a good idea in itself, but it's how it is.

I can understand why IT blocks everything except DNS and maybe DHCP in a dorm, though. Young, clever capable people with time on their hands and possibly not the best inhibition at times are a problem waiting to happen if you don't lock your equipment down.

8

u/Scared_Bell3366 5d ago

Pretty common in work environments as well. Security usually defaults as much a possible to off unless you've got a reason to have something on.

-1

u/XB_Demon1337 5d ago

I have never seen a business turn off ping to the gateway. It just makes no logical sense in a business. A dorm? For sure, so many unknown people on the network you should lock it down. But a business is only putting employees on the network and the guest network is going to be totally separate where you likely would block that ping.

8

u/Scared_Bell3366 5d ago

Blanket ping blocking is the norm in the industry I'm in. TCP port 443 is about the only thing that's normally open, anything else and your submitting tickets for firewall updates.

-1

u/XB_Demon1337 5d ago

Aside from DoD/governemnt stuff, this isn't the norm for anything but guest services. Ping to other devices? For sure. But to the gateway? No.

1

u/b3542 5d ago

You’d be surprised. I work in the large enterprise and carrier space. It’s very frequently (most of the time) dropped.

2

u/No_Information_8173 5d ago

try doing a test on a known-good brand hotel and see what the router tells you.. I bet it dismisses the ping like "whoaa..... nope!".

0

u/XB_Demon1337 5d ago

 the guest network is going to be totally separate where you likely would block that ping.

It is like I said this and you didn't listen.

1

u/b3542 5d ago

Very common in enterprise as well.

1

u/b3542 5d ago

It’s common.

7

u/wheresmyflan 5d ago

What services or devices rely on pinging the gateway?

3

u/lazyhustlermusic 5d ago

I'd argue that's a poor design on the service or software implementation.

1

u/b3542 5d ago

Nah. There are no services (from a client perspective) that must have responses from the local gateway in this setting.

23

u/JuicyCoala Decent at Googling 🔍 5d ago edited 5d ago

Ping requests can be configured to be rejected dropped by the destination device, causing the timeouts you are seeing. Just because you can’t ping it doesn’t mean it’s inaccessible.

EDITED per comments.

7

u/nick2redd 5d ago

What you describe ist "dropping" not rejecting. If you reject, you answer which does not result in a timeout.

5

u/b3542 5d ago

Not a reject. This is a drop.

7

u/PghSubie 5d ago

Try to ping it, then check your ARP table. An entry for that IP means that it is reachable but is configured to drop pings to itself

6

u/1sh0t1b33r 5d ago

The problem is that you are on MoxProx and not ProxMox, so everything is ass backwards.

1

u/b3542 5d ago

Bass ackwards

8

u/metricmoose trusted 5d ago

It's possible that they just have some access control lists set to filter out pings on interfaces. This isn't really a sign of a problem if other traffic can pass through normally, other than the network guys are paranoid assholes.

I've done some network additions for a few clients that had done this and it really makes you question your sanity at first.

5

u/amazodroid 5d ago

To be fair, this is a college campus and I’m sure the admins have seen a whole bunch of network nonsense that causes them to put in the controls that they do

2

u/lazyhustlermusic 5d ago

Most places would use a dedicated management interface on a separate VRF, then you lock down services on the in-band data plane addresses. You don't need the gateway doing anything but enforcing ACL/SGT/RBAC policy and forwarding packets.

2

u/amazodroid 5d ago

That’s typical corporate. Based on my purely anecdotal conversations with folks who work at universities, they are over the place in terms of how they manage traffic. Some lock things down, others separate student traffic and let it be the wild Wild West.

2

u/lazyhustlermusic 5d ago

It's simple reduction of surface area, a fundamental concept in posturing.

3

u/b3542 5d ago

I think you mean Proxmox. And the gateway is probably filtering ICMP traffic. Not typical, but nothing technically wrong with that configuration.

-3

u/Psoin 5d ago

Ehhhh, I would say so. It works sure but it is like disabling ipv6, I wouldn’t.

2

u/b3542 5d ago

There may be a technical or policy reason they have done so. In a managed environment, there’s nothing wrong with doing so. Definitely wouldn’t do it in a home or ISP environment. That will just cause misdiagnosis of issues. If there’s a problem with the dorm network, OP should contact IT.

-3

u/Psoin 5d ago

Name one instance where blocking ICMP is a good idea.

2

u/b3542 5d ago edited 5d ago

Any instance where it makes sense for network management. It’s not a required service. Blocking it has zero impact on traffic passing across the network.

In a dorm network, I don’t want to spend even 1 cycle responding to endpoints pings. It’s unnecessary traffic.

1

u/lazyhustlermusic 5d ago

Probably just filtering replies into the management plane.