Ok I figured it out.
Wow...Buckled down for this...I dug deep into the firewall, and I forgot I setup firewall blocks for unassigned subnets. Believe it or not, here is your internet lesson for the day.
All the subnet IPs have not been sold yet.
Here is a list of IP subnets you can purchase:
http://www.iana.org/assignments/ipv4-address-space
If you look at the top, you'll see the list got updated 12-22-2008.
that means some company bought another IP BLOCK.
One of the users having problems had an IP of 173.x.x.x Until Dec 2008, there was no such thing as 173.x.x.x IP addresses. Therefore, parniod CHAKORULES blocked any IP address range not currently owed.
Here "WAS" the firewall block: (These are listing of IP blocks that no one owns) or unallocated:
1.0.0.0/8
2.0.0.0/8
5.0.0.0/8
23.0.0.0/8
27.0.0.0/8
31.0.0.0/8
36.0.0.0/8
37.0.0.0/8
39.0.0.0/8
42.0.0.0/8
46.0.0.0/8
94.0.0.0/8
95.0.0.0/8
100.0.0.0/8
101.0.0.0/8
102.0.0.0/8
103.0.0.0/8
104.0.0.0/8
105.0.0.0/8
106.0.0.0/8
107.0.0.0/8
108.0.0.0/8
109.0.0.0/8
110.0.0.0/8
111.0.0.0/8
112.0.0.0/8
113.0.0.0/8
114.0.0.0/8
115.0.0.0/8
173.0.0.0/8
174.0.0.0/8
175.0.0.0/8
176.0.0.0/8
177.0.0.0/8
178.0.0.0/8
179.0.0.0/8
180.0.0.0/8
181.0.0.0/8
182.0.0.0/8
183.0.0.0/8
184.0.0.0/8
185.0.0.0/8
186.0.0.0/8
187.0.0.0/8
197.0.0.0/8
223.0.0.0/8
240.0.0.0/8
241.0.0.0/8
242.0.0.0/8
243.0.0.0/8
244.0.0.0/8
245.0.0.0/8
Now compare that to the list updated 12-22-2008.
http://www.iana.org/assignments/ipv4-address-space
Here are the blocks recently purchased:
108/8 ARIN 2008-12 whois.arin.net ALLOCATED
110/8 APNIC 2008-11 whois.apnic.net ALLOCATED
111/8 APNIC 2008-11 whois.apnic.net ALLOCATED
112/8 APNIC 2008-05 whois.apnic.net ALLOCATED
113/8 APNIC 2008-05 whois.apnic.net ALLOCATED
173/8 ARIN 2008-02 whois.arin.net ALLOCATED
174/8 ARIN 2008-02 whois.arin.net ALLOCATED
184/8 ARIN 2008-12 whois.arin.net ALLOCATED
197/8 AfriNIC 2008-10 whois.afrinic.net ALLOCATED
So I had to go in and update my parniod firewall list...
Wow...apnic.net just purchased a bunch of IP blocks this year...that must mean alot of servers going up.
I opened up the door on the above IP BLOCKS. Let me know if that fixes everyone.
Lesson in IP BLOCKS is over.
Thanks for making me dig into this.
Chako