online.net 163.172.*.*段服务器无法访问特定网站的技术求助
Hey there, let's break down this issue step by step. You've got multiple servers with Online.net, and only those in the 163.172.*.* subnet can't reach baniancitynews.com—even though the site loads locally, shows as "up" on isup.me, and works fine on other Online.net servers. Someone mentioned the problem isn't on Online.net's end, so let's dig into what could be going on.
1. Deep Dive Into Your MTR Output
First, let's squeeze all the info out of that mtr --report output:
- Spot the first failing hop: Does packet loss start at an Online.net router, or does it drop after jumping to a third-party network? This tells you if the issue is internal to Online.net or further upstream.
- Distinguish timeouts vs actual loss: ICMP packets are often deprioritized, so
* * *timeouts don't always mean full traffic block. Use TCP-based MTR for more accurate results:mtr --report --tcp --port 443 baniancitynews.com - Compare working vs non-working servers: Run the same MTR command on a working Online.net server, then compare the hop paths. The first differing hop is your clue.
2. Rule Out Subnet-Specific DNS Issues
Sometimes a subnet uses a unique DNS resolver that's returning bad IPs:
- On a problematic server, check the resolved IP:
Compare this to the IP returned by a working server or your local machine. If they don't match, the subnet's default DNS is likely the culprit.nslookup baniancitynews.com dig baniancitynews.com - Test with a public resolver to confirm:
If this returns the correct IP and you can reach the site afterward, you'll need to adjust the server's DNS settings.dig @8.8.8.8 baniancitynews.com
3. Check for IP Range Blocking by the Site
It's possible baniancitynews.com has accidentally or intentionally blocked the entire 163.172.*.* range:
- Run a verbose curl request to see the exact error:
Look for responses likecurl -v https://baniancitynews.com403 Forbidden(clear sign of a block) orConnection timed out. - If you have access to a working Online.net server, set up a simple local proxy there and route traffic from the problematic server through it—if the site loads, that confirms the block is targeting your subnet.
4. Verify Online.net's Subnet Routing
Even if someone says it's not their end, don't skip this:
- Collect the MTR outputs from both working and non-working servers, then reach out to Online.net support. Point out the exact hop where traffic diverges or drops—they might have a routing policy specific to
163.172.*.*that's causing issues with the site's network. - Ask if the subnet uses a different transit provider than your working servers—transit disputes or outages can cause targeted reachability problems.
5. Double-Check Local Server Rules
Don't overlook server-side blocks:
- Verify outgoing traffic isn't blocked by iptables/ufw:
iptables -L -n ufw status - Check if security tools like fail2ban or a server-side WAF are blocking the site's IP range.
Final Takeaway
Most likely, this is either a subnet-specific DNS glitch, an IP block from the site's end targeting 163.172.*.*, or a routing anomaly in Online.net's network for that subnet. Narrow down the root cause with the TCP MTR and DNS tests, then present that data to either Online.net support or the site's admin to resolve it.
内容的提问来源于stack exchange,提问作者Fluffy

