Amanda-Users

Re: Re: Backup via ssh-tunnel

2005-11-24 10:58:01
Subject: Re: Re: Backup via ssh-tunnel
From: Paddy Sreenivasan <paddy AT zmanda DOT com>
To: matilda matilda <matilda AT grandel DOT de>
Date: Thu, 24 Nov 2005 07:41:29 -0800


On 11/24/05, matilda matilda <matilda AT grandel DOT de> wrote:
Hi Paddy,

thank you for your answer and your patience.
But I'm missing just some elements to understand which ports and
are TCP/IP-Connections are involved in a regular backup.

1) Server is contacting the client by initiating a connecton to port
10080 (/etc/services amanda).
2) Who initiates a connection to what port back to the backup-server?
 
amandad (sendbackup) initiates connection to the backup-server. It uses 3 ports to send backup.
(messages, index, data). 3 ports are choosen from the portrange you specify during configure.
by driver. Dumper (on backup server) listens to these 3 ports.

3) What connections are established when a amcheck is issued on the
backupserver?
 
amandad (selfcheck) establishes a TCP connection. amcheck on the server communicates with
amandad on port 10080.

I have to use version 2.4.4 of amanda.

So I would be really happy if you could clearify the whole protocol stuff
with respect to initiating TCP/IP connections to which port from which
host.
 
 
We will add the information to wiki.zmanda.com soon.
 
Paddy

Best regards
Andreas Mock


>>> Paddy Sreenivasan < paddy AT zmanda DOT com> 22.11.2005  21.12 Uhr >>>
On 11/22/05, matilda matilda <matilda AT grandel DOT de> wrote:
>
> Good morning,
>
> one client in our network which we want to backup with amanda is only
> reachable
> throuh ssh because it is in the DMZ. (Only connections from intranet to
> DMZ allowed).
>
> Is there a way to use AMANDA through a properly established tunnel?


I have updated Amanda wiki with SSH tunnel information (
http://wiki.zmanda.com/index.php/Amanda_and_ssh_tunnels).
I have not tested the procedure. This procedure is cumbersome. We are
working on
making Amanda improvements to make it easier.

You can use 2.5.0b1 and "ssh" authentication method if you want to use the
ssh for all Amanda clients.

Is there a way to specify a different than the default port for a certain
> client (DLE)?


This is a good feature to have. It should be possible to restrict amanda
client and server communication to
a port (or few ports) on the server. Can you open a bug in
sourceforge.net<http://sourceforge.net>tracker? (
http://sourceforge.net/tracker/?group_id=120&atid=100120)

Thanks,
Paddy

Best regards
> Andreas Mock
>
>
>
>
>
>


--

Amanda documentation: wiki.zmanda.com < http://wiki.zmanda.com>
Amanda forums: forums.zmanda.com <http://forums.zmanda.com>




--

Amanda documentation: wiki.zmanda.com
Amanda forums: forums.zmanda.com
<Prev in Thread] Current Thread [Next in Thread>