no ping from SSH - STILL a serious issue

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

no ping from SSH - STILL a serious issue

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
no ping from SSH - STILL a serious issue
no ping from SSH - STILL a serious issue
2022-12-17 14:03:22
Model: EAP245  
Hardware Version: V3
Firmware Version: 5.0.5 Build 20220216 Rel. 61848(5553)

The issue raised in Topic 158407 is still real, and still open 3+ years later.

 

Ping is essential for debugging network issues in even a moderately complicated network.  

 

You support VLANs.  That's complicated.  You support SSH.  You need to support ping from the SSH account.

 

ping is not a security risk.  As explained in 158407, not allowing ping is a BUG.

 

ping requiring root permissions was a bug introduced into some Linux distros due to the package maintainers not updating the ping/busybox packages when kernel policy did change.

 

You can correct this by replacing busybox ping with the standard command and either setting the SETUID bit for ping or by granting ping the right to use raw sockets if your Linux version running on EAP supports extended file attributes. Newer Linux distros have corrected this bug in the ping package already.

 

I am currently struggling to determine why a device is successfully connected according to the access point, is pingable, but reports no internet connectivity.  The SSID is on a trunked VLAN.  Other devices on the VLAN can connet to the outside world.  Trying to diagnose that issue without the ability to test from the AP is next to impossible.

 

Please, Please fix this firmware bug.  I can't recommend and certainly won't be buying more of this otherwise good AP until it is fixed.  My manager is also very unhappy.

  0      
  0      
#1
Options
1 Reply
Re:no ping from SSH - STILL a serious issue
2022-12-20 10:38:00

  @tlhackque 

 

I'm not familiar with the bug you mentioned. However refer to the devices no Internet issue, I think you should check the routing table on the switch/router, and confirm the router will do NAT for this VLAN. Ping is just a tool.

 

What is your whole network topology? If you set up a port on the switch to the same VLAN(that you don't have Internet via SSID), and connect a PC to this Ethernet port, can you go to outside Internet?

  1  
  1  
#2
Options