Veritas-bu

[Veritas-bu] Re: backing up a firewall (not through it)

2001-03-26 19:00:14
Subject: [Veritas-bu] Re: backing up a firewall (not through it)
From: Dana AT slamdunknetworks DOT com (Dana Bourgeois)
Date: Mon, 26 Mar 2001 16:00:14 -0800
> > I have read through the mailling list on this one and have tried but
don't
> > seem to be getting network connection with netbackup (I can ping ok from
the
> > fw to the backup server).
> > 
> > Netbackup 3.4 error 41 network connection timed out
> > 
> > I am trying to backup a firewall, not through a firewall, just backup
the
> > firewall. Of course the fw admins don't want to open up many ports. I
have
> > the client installed on the firewall.
> > 
> > 1) What is the minimum ports per fw to do a backup?
> > 
> > 2) Here is the config. Will this work?
> > On the client (the firewall) I have in bp.conf
> > ALLOW_NON_RESERVED_PORTS
> > SERVER_PORT_WINDOW = 13740 13750
> > CLIENT_PORT_WINDOW = 13740 13750
> > RANDOM_PORTS = NO
> > 
> > On the backup server (master) I have this in bp.conf
> > ALLOW_NON_RESERVED_PORTS
> > SERVER_PORT_WINDOW = 13740 13750
> > CLIENT_PORT_WINDOW = 13740 13750
> > RANDOM_PORTS = NO
> > 
> > The firewall folks have allowed the following:
> > TCP on port 13782, 13720 & 13740 to 13750
> > 
> > I have tried most permutations of the above commands and I am obviously
> > missing something. Any ideas?
> > 
> > Thanks
 
To backup a firewall you need three things:
        You need to have networking support (interface setup properly, good
 routing table and name support).
        The firewall OS has to allow connections.
        The firewall software has to allow connections. 
 
 
Probably your firewall OS is hardened and connections are being refused.
Check for my previous post on how to use a kernel trace program to see what
is really happening.  The subject has 'truss' in the subject line, I think.
 
 
 
 
Dana Bourgeois
Slam Dunk Networks 
Digital Mechanic & Network Janitor
1.650.632-5543
1.650.996-5687  [cell]

<Prev in Thread] Current Thread [Next in Thread>