Unable to connect to a server from our AIX server via FTP

My first thought is you have a routing problem and perhaps your netmask is set wrong. But I cannot be sure.

Are you sure your netmask for your subnetwork is correctly set to 0xffff0000 ? (This seems possibly an error).

Do you have the ability to login to your default router host at 172.16.80.100 and check the netmask there? What is that device?

Normally, we do not see big /16 netmasks in subnetwork devices.

Cheers

I'm afraid i don't have much idea regarding the device as i did not get any sort of handover in terms of the company's network architecture . I'm told that the router in question is the SAP router for people in different locations to access the system.

i tried to telnet into the router.

telnet 172.16.80.100
-----------------------------------------------------------------------
Cisco Configuration Professional (Cisco CP) is installed on this device.
This feature requires the one-time use of the username "cisco" with the
password "cisco". These default credentials have a privilege level of 15.

YOU MUST USE CISCO CP or the CISCO IOS CLI TO CHANGE THESE  PUBLICLY-KNOWN
CREDENTIALS

Here are the Cisco IOS commands.

username <myuser>  privilege 15 secret 0 <mypassword>
no username cisco

Replace <myuser> and <mypassword> with the username and password you want
to use.

IF YOU DO NOT CHANGE THE PUBLICLY-KNOWN CREDENTIALS, YOU WILL NOT BE ABLE
TO LOG INTO THE DEVICE AGAIN AFTER YOU HAVE LOGGED OFF.

For more information about Cisco CP please follow the instructions in the
QUICK START GUIDE for your router or go to http://www.cisco.com/go/ciscocp
-----------------------------------------------------------------------


User Access Verification

Password:
% Password expiration warning.
-----------------------------------------------------------------------

Cisco Configuration Professional (Cisco CP) is installed on this device
and it provides the default username "cisco" for  one-time use. If you have
already used the username "cisco" to login to the router and your IOS image
supports the "one-time" user option, then this username has already expired.
You will not be able to login to the router with this username after you exit
this session.

It is strongly suggested that you create a new username with a privilege level
of 15 using the following command.

username <myuser> privilege 15 secret 0 <mypassword>

Replace <myuser> and <mypassword> with the username and password you want to
use.

-----------------------------------------------------------------------

Linc-HO>ipconfig
Translating "ipconfig"...domain server (255.255.255.255) [OK]
Trying ipconfig.yourdomain.com (54.221.207.100)...
% Destination unreachable; gateway or host down

Linc-HO>

I'm lost and have no clue about the

54.221.207.100

ip address

Tried to ping from my AIX terminal.

# ping -c 5 54.221.207.100
PING 54.221.207.100: (54.221.207.100): 56 data bytes

--- 54.221.207.100 ping statistics ---
5 packets transmitted, 0 packets received, 100% packet loss
#

You should find out what software that router is running and now many interfaces it has, etc.

Did you try:

show version

and

show ip interfaces brief

and maybe even

show ip route

and also:

show access-lists

For starters.....

Reference:

https://networking.ringofsaturn.com/Cisco/ciscocommandguide.php

Linc-HO>show version
Cisco IOS Software, C2900 Software (C2900-UNIVERSALK9_NPE-M), Version 15.1(1)T1, RELEASE SOFTWARE (fc2)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2010 by Cisco Systems, Inc.
Compiled Mon 19-Jul-10 02:53 by prod_rel_team

ROM: System Bootstrap, Version 15.0(1r)M9, RELEASE SOFTWARE (fc1)

Linc-HO uptime is 2 weeks, 4 days, 6 hours, 50 minutes
System returned to ROM by power-on
System image file is "flash0:c2900-universalk9_npe-mz.SPA.151-1.T1.bin"
Last reload type: Normal Reload


This product contains cryptographic features and is subject to United
States and local country laws governing import, export, transfer and
use. Delivery of Cisco cryptographic products does not imply
third-party authority to import, export, distribute or use encryption.
Importers, exporters, distributors and users are responsible for
compliance with U.S. and local country laws. By using this product you
agree to comply with applicable laws and regulations. If you are unable
to comply with U.S. and local laws, return this product immediately.

A summary of U.S. laws governing Cisco cryptographic products may be found at:
http://www.cisco.com/wwl/export/crypto/tool/stqrg.html

If you require further assistance please contact us by sending email to
export@cisco.com.

Cisco CISCO2911/K9 (revision 1.0) with 2580479K/40960K bytes of memory.
Processor board ID FHK1443F0BY
3 Gigabit Ethernet interfaces
4 Serial(sync/async) interfaces
DRAM configuration is 64 bits wide with parity enabled.
255K bytes of non-volatile configuration memory.
254464K bytes of ATA System CompactFlash 0 (Read/Write)


License Info:

License UDI:

-------------------------------------------------
Device#   PID                   SN
-------------------------------------------------
*0        CISCO2911/K9          FHK1443F0BY



Technology Package License Information for Module:'c2900'

----------------------------------------------------------------
Technology    Technology-package          Technology-package
              Current       Type          Next reboot
-----------------------------------------------------------------
ipbase        ipbasek9      Permanent     ipbasek9
security      None          None          None
uc            None          None          None
data          None          None          None

Configuration register is 0x2102
Linc-HO>show access-lists

Linc-HO>show ip interfaces brief
                         ^
% Invalid input detected at '^' marker.

Linc-HO>show ip route
Codes: L - local, C - connected, S - static, R - RIP, M - mobile, B - BGP
       D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
       N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
       E1 - OSPF external type 1, E2 - OSPF external type 2
       i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2
       ia - IS-IS inter area, * - candidate default, U - per-user static route
       o - ODR, P - periodic downloaded static route, + - replicated route

Gateway of last resort is not set

      10.0.0.0/8 is variably subnetted, 3 subnets, 2 masks
C        10.10.10.20/30 is directly connected, Serial0/1/1
L        10.10.10.21/32 is directly connected, Serial0/1/1
C        10.10.10.22/32 is directly connected, Serial0/1/1
      172.16.0.0/16 is variably subnetted, 2 subnets, 2 masks
C        172.16.0.0/16 is directly connected, GigabitEthernet0/1
L        172.16.80.100/32 is directly connected, GigabitEthernet0/1
      172.17.0.0/24 is subnetted, 1 subnets
S        172.17.80.0 [200/0] via 192.168.198.1
S     172.18.0.0/16 [1/0] via 192.168.198.1
      172.19.0.0/24 is subnetted, 1 subnets
S        172.19.80.0 [1/0] via 10.10.10.22
      172.20.0.0/24 is subnetted, 1 subnets
S        172.20.80.0 [200/0] via 192.168.198.1
      192.168.198.0/24 is variably subnetted, 3 subnets, 3 masks
S        192.168.198.0/24 [1/0] via 192.168.198.1
C        192.168.198.0/30 is directly connected, GigabitEthernet0/0
L        192.168.198.2/32 is directly connected, GigabitEthernet0/0
Linc-HO>

Sorry, on the interfaces, try:

show ip interface brief

or

show ip interface

Also, just FYI on your Cisco OS version:

Table 1. End-of-Life Milestones and Dates for the Cisco IOS Software Release 15.1(1)T

Reference:

End-of-Sale and End-of-Life Announcement for the Cisco IOS Software Release 15.1(1)T - Cisco

So, you are not going to get any support from Cisco, I am guessing :slight_smile:

Anyway, back to the task at hand.... while logged into your router, you should try to ping your ftp server (the one you are trying to reach from your host):

ping 164.52.194.12

Can you ping it from (while logged into) the router?

Linc-HO>ping 164.52.194.12

Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 164.52.194.12, timeout is 2 seconds:
.....
Success rate is 0 percent (0/5)
Linc-HO>
Linc-HO>show ip interface
GigabitEthernet0/0 is up, line protocol is up
  Internet address is 192.168.198.2/30
  Broadcast address is 255.255.255.255
  Address determined by non-volatile memory
  MTU is 1500 bytes
  Helper address is not set
  Directed broadcast forwarding is disabled
  Outgoing access list is not set
  Inbound  access list is not set
  Proxy ARP is enabled
  Local Proxy ARP is disabled
  Security level is default
  Split horizon is enabled
  ICMP redirects are always sent
  ICMP unreachables are always sent
  ICMP mask replies are never sent
  IP fast switching is enabled
  IP fast switching on the same interface is disabled
  IP Flow switching is disabled
  IP CEF switching is enabled
  IP CEF switching turbo vector
  IP multicast fast switching is enabled
  IP multicast distributed fast switching is disabled
  IP route-cache flags are Fast, CEF
  Router Discovery is disabled
  IP output packet accounting is disabled
  IP access violation accounting is disabled
  TCP/IP header compression is disabled
  RTP/IP header compression is disabled
  Policy routing is disabled
  Network address translation is disabled
  BGP Policy Mapping is disabled
  Input features: MCI Check
  WCCP Redirect outbound is disabled
  WCCP Redirect inbound is disabled
  WCCP Redirect exclude is disabled
GigabitEthernet0/1 is up, line protocol is up
  Internet address is 172.16.80.100/16
  Broadcast address is 255.255.255.255
  Address determined by non-volatile memory
  MTU is 1500 bytes
  Helper address is not set
  Directed broadcast forwarding is disabled
  Outgoing access list is not set
  Inbound  access list is not set
  Proxy ARP is enabled
  Local Proxy ARP is disabled
  Security level is default
  Split horizon is enabled
  ICMP redirects are always sent
  ICMP unreachables are always sent
  ICMP mask replies are never sent
  IP fast switching is enabled
  IP fast switching on the same interface is disabled
  IP Flow switching is disabled
  IP CEF switching is enabled
  IP CEF switching turbo vector
  IP multicast fast switching is enabled
  IP multicast distributed fast switching is disabled
  IP route-cache flags are Fast, CEF
  Router Discovery is disabled
  IP output packet accounting is disabled
  IP access violation accounting is disabled
  TCP/IP header compression is disabled
  RTP/IP header compression is disabled
  Policy routing is disabled
  Network address translation is disabled
  BGP Policy Mapping is disabled
  Input features: MCI Check
  WCCP Redirect outbound is disabled
  WCCP Redirect inbound is disabled
  WCCP Redirect exclude is disabled
GigabitEthernet0/2 is down, line protocol is down
  Internet address is 10.224.102.13/30
  Broadcast address is 255.255.255.255
  Address determined by non-volatile memory
  MTU is 1500 bytes
  Helper address is not set
  Directed broadcast forwarding is disabled
  Outgoing access list is not set
  Inbound  access list is not set
  Proxy ARP is enabled
  Local Proxy ARP is disabled
  Security level is default
  Split horizon is enabled
  ICMP redirects are always sent
  ICMP unreachables are always sent
  ICMP mask replies are never sent
  IP fast switching is enabled
  IP fast switching on the same interface is disabled
  IP Flow switching is disabled
  IP CEF switching is enabled
  IP CEF switching turbo vector
  IP multicast fast switching is enabled
  IP multicast distributed fast switching is disabled
  IP route-cache flags are Fast, CEF
  Router Discovery is disabled
  IP output packet accounting is disabled
  IP access violation accounting is disabled
  TCP/IP header compression is disabled
  RTP/IP header compression is disabled
  Policy routing is disabled
  Network address translation is disabled
  BGP Policy Mapping is disabled
  Input features: MCI Check
  WCCP Redirect outbound is disabled
  WCCP Redirect inbound is disabled
  WCCP Redirect exclude is disabled
Serial0/0/0 is down, line protocol is down
  Internet address is 10.10.10.6/30
  Broadcast address is 255.255.255.255
  Address determined by non-volatile memory
  MTU is 1500 bytes
  Helper address is not set
  Directed broadcast forwarding is disabled
  Outgoing access list is not set
  Inbound  access list is not set
  Proxy ARP is enabled
  Local Proxy ARP is disabled
  Security level is default
  Split horizon is enabled
  ICMP redirects are always sent
  ICMP unreachables are always sent
  ICMP mask replies are never sent
  IP fast switching is enabled
  IP fast switching on the same interface is enabled
  IP Flow switching is disabled
  IP CEF switching is enabled
  IP CEF switching turbo vector
  IP multicast fast switching is enabled
  IP multicast distributed fast switching is disabled
  IP route-cache flags are Fast, CEF
  Router Discovery is disabled
  IP output packet accounting is disabled
  IP access violation accounting is disabled
  TCP/IP header compression is disabled
  RTP/IP header compression is disabled
  Policy routing is disabled
  Network address translation is disabled
  BGP Policy Mapping is disabled
  Input features: MCI Check
  WCCP Redirect outbound is disabled
  WCCP Redirect inbound is disabled
  WCCP Redirect exclude is disabled
Serial0/0/1 is down, line protocol is down
  Internet address is 10.10.10.9/30
  Broadcast address is 255.255.255.255
  Address determined by non-volatile memory
  MTU is 1500 bytes
  Helper address is not set
  Directed broadcast forwarding is disabled
  Outgoing access list is not set
  Inbound  access list is not set
  Proxy ARP is enabled
  Local Proxy ARP is disabled
  Security level is default
  Split horizon is enabled
  ICMP redirects are always sent
  ICMP unreachables are always sent
  ICMP mask replies are never sent
  IP fast switching is enabled
  IP fast switching on the same interface is enabled
  IP Flow switching is disabled
  IP CEF switching is enabled
  IP CEF switching turbo vector
  IP multicast fast switching is enabled
  IP multicast distributed fast switching is disabled
  IP route-cache flags are Fast, CEF
  Router Discovery is disabled
  IP output packet accounting is disabled
  IP access violation accounting is disabled
  TCP/IP header compression is disabled
  RTP/IP header compression is disabled
  Policy routing is disabled
  Network address translation is disabled
  BGP Policy Mapping is disabled
  Input features: MCI Check
  WCCP Redirect outbound is disabled
  WCCP Redirect inbound is disabled
  WCCP Redirect exclude is disabled
Serial0/1/0 is down, line protocol is down
  Internet address is 10.10.10.13/30
  Broadcast address is 255.255.255.255
  Address determined by non-volatile memory
  MTU is 1500 bytes
  Helper address is not set
  Directed broadcast forwarding is disabled
  Outgoing access list is not set
  Inbound  access list is not set
  Proxy ARP is enabled
  Local Proxy ARP is disabled
  Security level is default
  Split horizon is enabled
  ICMP redirects are always sent
  ICMP unreachables are always sent
  ICMP mask replies are never sent
  IP fast switching is enabled
  IP fast switching on the same interface is enabled
  IP Flow switching is disabled
  IP CEF switching is enabled
  IP CEF switching turbo vector
  IP multicast fast switching is enabled
  IP multicast distributed fast switching is disabled
  IP route-cache flags are Fast, CEF
  Router Discovery is disabled
  IP output packet accounting is disabled
  IP access violation accounting is disabled
  TCP/IP header compression is disabled
  RTP/IP header compression is disabled
  Policy routing is disabled
  Network address translation is disabled
  BGP Policy Mapping is disabled
  Input features: MCI Check
  WCCP Redirect outbound is disabled
  WCCP Redirect inbound is disabled
  WCCP Redirect exclude is disabled
Serial0/1/1 is up, line protocol is up
  Internet address is 10.10.10.21/30
  Broadcast address is 255.255.255.255
  Address determined by non-volatile memory
  Peer address is 10.10.10.22
  MTU is 1500 bytes
  Helper address is not set
  Directed broadcast forwarding is disabled
  Outgoing access list is not set
  Inbound  access list is not set
  Proxy ARP is enabled
  Local Proxy ARP is disabled
  Security level is default
  Split horizon is enabled
  ICMP redirects are always sent
  ICMP unreachables are always sent
  ICMP mask replies are never sent
  IP fast switching is enabled
  IP fast switching on the same interface is enabled
  IP Flow switching is disabled
  IP CEF switching is enabled
  IP CEF switching turbo vector
  IP multicast fast switching is enabled
  IP multicast distributed fast switching is disabled
  IP route-cache flags are Fast, CEF
  Router Discovery is disabled
  IP output packet accounting is disabled
  IP access violation accounting is disabled
  TCP/IP header compression is disabled
  RTP/IP header compression is disabled
  Policy routing is disabled
  Network address translation is disabled
  BGP Policy Mapping is disabled
  Input features: MCI Check
  WCCP Redirect outbound is disabled
  WCCP Redirect inbound is disabled
  WCCP Redirect exclude is disabled

That is not a good sign (cannot ping from intermediate router).

Let's trace the route, then (from the router to your ftp host):

traceroute 164.52.194.12
Linc-HO>traceroute 164.52.194.12

Type escape sequence to abort.
Tracing the route to e2e-62-12.e2enetworks.net.in (164.52.194.12)

  1  *  *  *
  2  *  *  *
  3  *  *  *
  4  *  *  *
  5  *  *  *
  6  *  *  *
  7  *  *  *
  8  *  *  *
  9  *  *  *
 10  *  *  *
 11  *  *  *
 12  *  *  *
 13  *  *  *
 14  *  *  *
 15  *  *  *
 16  *  *  *
 17  *  *  *
 18  *  *  *
 19  *  *  *
 20  *  *  *
 21  *  *  *
 22  *  *  *
 23  *  *  *
 24  *  *  *
 25  *  *  *
 26  *  *  *
 27  *  *  *
 28  *  *  *
 29  *  *  *
 30  *  *  *
Linc-HO>

Thanks for doing a great job working to troubleshoot your own problem, Bruno.

Without a basic network diagram, it is hard for me to advise, since I cannot readily visualize what is going on.

However, so far, it seems we have some potential issues with subnet masks but I'm not convinced that is the issue, since you cannot ping or traceroute from your router.

Your router does not have any access control lists, and so normally we would look at the next hop; but I don't know where your next hop is.

We could try to figure it out with:

show arp

But it would be better if you drew a sketch of the Internet (as a cloud) and where your Internet gateways (for your organizations) attach to the Internet, and the devices / hosts in the path (in your org).

Note: See next post about your "10"net WAN.

Right now, there is no path from your router (where you are logged in) to the Internet, or so it seems from what I have read so far. You have done a good job of showing the details. Thanks for your patience.

Can you ping or traceroute to any device on the Internet from your router? If so, via what interface on your router?

OBTW, Bruno,

Your router shows a serial interface on the "10" network. This leads me to believe or guess (at least) that your router is connected to a private wide area network (WAN).

Is that correct?