Amanda-Users

Re: Cant run two Linux Servers behind my firewall at the same time - only one and vice versa.

2007-01-18 12:25:59
Subject: Re: Cant run two Linux Servers behind my firewall at the same time - only one and vice versa.
From: Frank Smith <fsmith AT hoovers DOT com>
To: chuck AT smtl.co DOT uk
Date: Thu, 18 Jan 2007 11:07:10 -0600
Chuck Amadi Systems Administrator wrote:
> Hi List
> 
> Sorry to nag on is there any suggestions to my post.
> 
> Cheers
> 
> On Thu, 2007-01-18 at 08:27 +0000, chuck.amadi wrote:
>> Hi List I was hoping for some direction to my issue with two servers 
>> behind a firewall running ipchains
>> I can backup one or the other but when I uncomment both DLE I get host down.
>>
>> Thanks in advance.
>>
>>
>> chuck.amadi wrote:
>>
>>> Hi I have two Linux SuSE 9 SLES servers outside of my lan behind a 
>>> firewall using (I know don't laugh) IPChains.
>>> The first server I setup worked without problems by compiling with the 
>>> tcp and udp port range and changing a parameter in security.c file
>>> and increasing the timeout using a ipchain rule, which worked a treat 
>>> but I have another new server outside and behine a firewall.
>>>
>>> Thus when I tried following the same reciepe and compile using the 
>>> same tcp and udp port range and thus a separate tcp and udp port range 
>>> to no joy I am unable to get both to work at the same time if I 
>>> comment out one of the amanda clients within the disklist the other 
>>> doesn't work and vice versa So I know it is not the setup or configure.
>>>
>>> #The timeout is in seconds. If you set the timeout of TCP, TCPFIN
>>> #and UDP to 5 seconds, 5 seconds and 5 seconds, I think they are
>>> #too short.  Please try to set them to 5min, 1min
>>> #and 5min respectively such as 300 60 300.
>>>
>>> # ipchains -M -S 300 tcp 60 tcpfin 300 udp works ok.
>>> ipchains -M -S 7200 60 300
>>>
>>>
>>> I get the Warning: selfcheck request timed out. Host down!. Note that 
>>> when I comment out one of them amcheck works accordingly
>>> I am aware the it's using udp over the firewall But I haven't been 
>>> able to suss this out I assume that my connection is poor.
>>> I have checked both /tmp/amanda/amanda-date.debug and they both moan 
>>> about timeouts failed But are OK when only one of them
>>> is in use.

Any chance your firewall is dong NAT, and mapping both clients to the
same IP?

Frank

>>>
>>> Cheers
>>>
>>


-- 
Frank Smith                                      fsmith AT hoovers DOT com
Sr. Systems Administrator                       Voice: 512-374-4673
Hoover's Online                                   Fax: 512-374-4501