Re: Cant run two Linux Servers behind my firewall at the same time - only one and vice versa.
2007-01-18 12:25:59
Chuck Amadi Systems Administrator wrote:
> Hi List
>
> Sorry to nag on is there any suggestions to my post.
>
> Cheers
>
> On Thu, 2007-01-18 at 08:27 +0000, chuck.amadi wrote:
>> Hi List I was hoping for some direction to my issue with two servers
>> behind a firewall running ipchains
>> I can backup one or the other but when I uncomment both DLE I get host down.
>>
>> Thanks in advance.
>>
>>
>> chuck.amadi wrote:
>>
>>> Hi I have two Linux SuSE 9 SLES servers outside of my lan behind a
>>> firewall using (I know don't laugh) IPChains.
>>> The first server I setup worked without problems by compiling with the
>>> tcp and udp port range and changing a parameter in security.c file
>>> and increasing the timeout using a ipchain rule, which worked a treat
>>> but I have another new server outside and behine a firewall.
>>>
>>> Thus when I tried following the same reciepe and compile using the
>>> same tcp and udp port range and thus a separate tcp and udp port range
>>> to no joy I am unable to get both to work at the same time if I
>>> comment out one of the amanda clients within the disklist the other
>>> doesn't work and vice versa So I know it is not the setup or configure.
>>>
>>> #The timeout is in seconds. If you set the timeout of TCP, TCPFIN
>>> #and UDP to 5 seconds, 5 seconds and 5 seconds, I think they are
>>> #too short. Please try to set them to 5min, 1min
>>> #and 5min respectively such as 300 60 300.
>>>
>>> # ipchains -M -S 300 tcp 60 tcpfin 300 udp works ok.
>>> ipchains -M -S 7200 60 300
>>>
>>>
>>> I get the Warning: selfcheck request timed out. Host down!. Note that
>>> when I comment out one of them amcheck works accordingly
>>> I am aware the it's using udp over the firewall But I haven't been
>>> able to suss this out I assume that my connection is poor.
>>> I have checked both /tmp/amanda/amanda-date.debug and they both moan
>>> about timeouts failed But are OK when only one of them
>>> is in use.
Any chance your firewall is dong NAT, and mapping both clients to the
same IP?
Frank
>>>
>>> Cheers
>>>
>>
--
Frank Smith fsmith AT hoovers DOT com
Sr. Systems Administrator Voice: 512-374-4673
Hoover's Online Fax: 512-374-4501
|
|
|