ADSM-L

Re: Dealing with firewall/slow network

2004-06-21 11:06:07
Subject: Re: Dealing with firewall/slow network
From: Zoltan Forray/AC/VCU <zforray AT VCU DOT EDU>
To: ADSM-L AT VM.MARIST DOT EDU
Date: Mon, 21 Jun 2004 11:05:50 -0400
Actually no, but here again my ignorance comes through since someone told
me that since they are behind/in the same "firewall", that shouldn't
matter (please correct me if they/I am wrong).

Server is 10.62.132.x  The clients vary from 10.59.x, 10.61.x, 10.57.x,
10.58.x




Richard van Denzel <RvanDenzel AT SLTNGROUP DOT COM>
Sent by: "ADSM: Dist Stor Manager" <ADSM-L AT VM.MARIST DOT EDU>
06/21/2004 10:34 AM
Please respond to
"ADSM: Dist Stor Manager" <ADSM-L AT VM.MARIST DOT EDU>


To
ADSM-L AT VM.MARIST DOT EDU
cc

Subject
Re: Dealing with firewall/slow network






Zoltan,

Now I'm lost. Both systems are on the same network behind the firewall,
are they also on the same subnet as well?
If they are, then what has the firewall got todo with it?

Maybe there is a routing/gateway/DNS problem on one of the boxes?

Richard.





Zoltan Forray/AC/VCU <zforray AT VCU DOT EDU>
Sent by: "ADSM: Dist Stor Manager" <ADSM-L AT VM.MARIST DOT EDU>
21-06-2004 16:42
Please respond to "ADSM: Dist Stor Manager"

        To:     ADSM-L AT VM.MARIST DOT EDU
        cc:
        Subject:        Re: Dealing with firewall/slow network


Thanks for the tip(s).

>From the response I am seeing, I guess make myself clear.

Both the TSM server and the client are behind the same firewall.  (This
also shows my ignorance about firewalls since I have never had to deal
with them, before !).




"Prather, Wanda" <Wanda.Prather AT JHUAPL DOT EDU>
Sent by: "ADSM: Dist Stor Manager" <ADSM-L AT VM.MARIST DOT EDU>
06/21/2004 10:21 AM
Please respond to
"ADSM: Dist Stor Manager" <ADSM-L AT VM.MARIST DOT EDU>


To
ADSM-L AT VM.MARIST DOT EDU
cc

Subject
Re: Dealing with firewall/slow network






Also, talk to the person who set up the firewall.

Some firewall software has it's own "commtimeout" parms.
If there is a large enough pause in communication between the TSM server
and
client, the firewall shuts down the session.

Because TSM clients spend time noodling around in the filesystem looking
for
data to back up, there are frequent "pauses" in a backup session.  I have
found that you often have to increase the firewall parm or you get a lot
of
TSM "session terminated" messages.

(The backups usually reconnect and finish anyway, but take about 5 times
longer than they should.)

-----Original Message-----
From: ADSM: Dist Stor Manager [mailto:ADSM-L AT VM.MARIST DOT EDU] On Behalf Of
Richard van Denzel
Sent: Monday, June 21, 2004 9:19 AM
To: ADSM-L AT VM.MARIST DOT EDU
Subject: Re: Dealing with firewall/slow network


Zoltan,

For the obivious, Port 1500 is open on the Firewall?

Richard.





Zoltan Forray/AC/VCU <zforray AT VCU DOT EDU>
Sent by: "ADSM: Dist Stor Manager" <ADSM-L AT VM.MARIST DOT EDU>
21-06-2004 15:35
Please respond to "ADSM: Dist Stor Manager"

        To:     ADSM-L AT VM.MARIST DOT EDU
        cc:
        Subject:        Dealing with firewall/slow network


I seem to be having some issues backups various systems to a dedicated
Linux TSM server, which is behind a very secure firewall.

Eventhough both the TSM servers and all the clients are on the same
network, there seems to be some communications issues. I am seeing lots of
these:

6/19/2004 8:00:07 PM ANR8214E Session open with 25 failed due to
connection refusal.
6/19/2004 8:00:07 PM ANR0480W Session 3477 for node MUSTANG () terminated
- connection with client severed.
6/19/2004 8:00:08 PM ANR8214E Session open with 26 failed due to
connection refusal.
6/19/2004 8:00:08 PM ANR0480W Session 3478 for node DINGO () terminated -
connection with client severed.
6/19/2004 8:00:09 PM ANR8214E Session open with 27 failed due to
connection refusal.
6/19/2004 8:00:09 PM ANR0480W Session 3480 for node DOG () terminated -
connection with client severed.

The server TCPIP communications timeout is set to 3,600 and idletimeout is
set to 600.

Any good books/info/recommendations on dealing with this kind of
configuration ?

FWIW, most of the clients are Sun/Solaris systems.

<Prev in Thread] Current Thread [Next in Thread>