Join GitHub today
GitHub is home to over 31 million developers working together to host and review code, manage projects, and build software together.Sign up
Unable to access Google or interact with GCE via the Google SDK (gcloud) #210
OS / Environment
Ubuntu 16.04.1 LTS
Version of components from
Thank you for your response and assistance.
Also, to clarify, I am able to access Google ok from the Algo server, just not from my client (Mac). i.e wget is successful from the server; from my Mac it isn't.
First, when not connected to the VPN:
From this I assume the MTU should be 1280. To compare, when connected to the VPN:
From this I assume the MTU should be set to 1400 for the VPN connection.
The MTU was then manually set onmy Mac to 1400 with
I am experiencing a similar issue, though not quite the same as #210 -- more #310 from @joshwardell. Can connect to the GCE instance, but no sites will respond. Interestingly, tcpdumping the interface on the VPN shows the traffic, but it appears that the traffic doesn't get routed back to my machine. (I think that's correct, I'm somewhat a networking newb)
This was verified by doing a DNS query for a domain that doesn't exist (something like foo.bar.baz), and seeing that head out across the interface -- but not receiving the response on my machine.
To further add to the weirdness, I can establish an SSH connection to the machine while not on the VPN and continue to operate it after I connect to the VPN, but cannot establish a "fresh" connection once connected.
Happy to continue debugging this any further. I am still looking at this as I have time, but figured I'd add my notes here.
referenced this issue
Apr 3, 2017
Was linked here through a series of closed tickets, though I question that 210 is actually the same as 310/345/whatever else.
Just to add as another data point, I'm experiencing the same GCE issues as others with my MTU set artificially low. Nother ever above 1400, but tried several steps down to 1280. Cannot get ICMP responses nor DNS responses. Haven't tried anything else since DNS won't work.
referenced this issue
Apr 8, 2017
I have run into this issue connecting to certain sites, specifically google sites, through Algo VPN when I run it on GCE. I am using a Mac with OS 10.11.6 as the client, and did an install on an existing google compute engine instance running ubuntu 16.04 LTS. I tried a couple of things. First, with ICMP connections open to the server, when activating the VPN using the mobileconfig file I find my
I set the
sudo iptables -I FORWARD -p tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
but that did not fix it. I tried a setting up Algo on a new digitalocean server, using the remote ansible commands and everything works fine through the digitalocean server, including google sites.
tl;dr - My report generally confirms the issue others are seeing with GCE specific installation.
I solved the problem on all my computers, but I cannot change the MTU setting on mobile devices (like iOS). Is there any workaround or should I just switch to amazon or digitial ocean?
Btw. I deployed with a default #max_mss setting which was 1316. I don't know if tweaking that would make any difference.