Veritas-bu

[Veritas-bu] How to troubleshoot a Firewall Client Backup with Clustered Netbackup Server

2005-11-08 20:23:05
Subject: [Veritas-bu] How to troubleshoot a Firewall Client Backup with Clustered Netbackup Server
From: blaine_robison AT yahoo DOT com (Blaine Robison)
Date: Tue, 8 Nov 2005 17:23:05 -0800 (PST)
>From the looks of your error and description of your environment, it appears
you are still communicating on the Client reserved ports 512 to 1023. Have the
FW admin open these ports going from the client to the master and media
servers, and see if it runs, if so then look at your vnetd configuration. 

--- marshall.a.skare AT accenture DOT com wrote:

> Two rather basic things to check, but they're worth looking into:
> 
>  
> 
> -          Do you have access to firewall logs to verify that you're
> seeing the traffic reach the firewall and make it through?
> 
> -          Are either the NBU servers and/or clients sitting behind a
> NAT for some reason?
> 
>  
> 
> Marshall Skare
> 
> ATIS - Unix Engineering
> 
> (612) 277-4434
> 
> ________________________________
> 
> From: veritas-bu-admin AT mailman.eng.auburn DOT edu
> [mailto:veritas-bu-admin AT mailman.eng.auburn DOT edu] On Behalf Of
> Kilpatrick, Mark
> Sent: Monday, November 07, 2005 11:11 AM
> To: veritas-bu AT mailman.eng.auburn DOT edu
> Subject: [Veritas-bu] How to troubleshoot a Firewall Client Backup with
> Clustered Netbackup Server
> 
>  
> 
> Hi, I am attempting to backup two Solaris NBU5.1 clients through a
> firewall and they are unsuccessful. I would like some pointers on
> troubleshooting this procedure.
> 
>  
> 
> The firewall rules have been set up for bpcd (13782) going out to the
> client from the master server and media servers.
> 
> The firewall rules have been set up for vnetd (13724) going into the
> server.
> 
> The client attribute of vnetd port has been selected from the master
> server properties for each of the clients.
> 
> When selecting the client properties from the NBU admin interface the
> error of cannot connect on socket (status 25) returns immediately
> 
> When running a test backup the error of (58) can't connect to client
> returns almost immediately.
> 
>  
> 
> I have run the bpclient -client -nameofclient -L command on each of the
> firewalled clients and the No call back connections is set to yes. But
> the IP address returned is 0.0.0.0 
> 
> I have checked the /etc/services and /etc/inetd.conf on each client
> 
> I have checked the bp.conf on each client and server and media server
> names are present
> 
> I have checked /etc/hosts on server and client
> 
> I have enabled logging of bpcd and vnetd on the clients but there are no
> log files created - indicating no communication with the clients from
> the master
> 
> I have enabled logging of bpcd on the master
> 
>  
> 
> How can I determine if the problem lies with the firewall rules created
> by the firewall admin team or with netbackup (version 5.1 HP-UX running
> on a VCS cluster). Could the issue be related to the fact that I have a
> netbackup clustered server. The firewall rules only specify the virtual
> server hostname. Addition of physical name and IP to firewall rules is
> not possible.
> 
>  
> 
>  
> 
> Regards, Mark K 
> 
>  
> 
>  
> 
>  
> 
> Due to continued expansion Sabeo Technologies have moved office - to The
> Courtyard, Carmanhall Road, Sandyford, Dublin 18. Our telephone and fax
> numbers remain unchanged. A location map is available on our website
> www.sabeo.com.
> 
>  
> 
>  
> 
>  
> 
> **********************************************************************
> 
> This email and any files transmitted with it are confidential and
> 
> intended solely for the use of the individual or entity to whom they
> 
> are addressed. If you have received this email in error please notify
> 
> Sabeo Technologies.
> 
>  
> 
> This footnote also confirms that this email message has been swept for
> the presence of computer viruses.
> 
> **********************************************************************
> 
>  
> 
> 
> 
> This message is for the designated recipient only and may contain privileged,
> proprietary, or otherwise private information.  If you have received it in
> error, please notify the sender immediately and delete the original.  Any
> other use of the email by you is prohibited.
> 


Blaine Robison
Solaris Ceritfied System Administrator 
Solaris Certified Network Administrator
Veritas Certified Professional
972-853-2459
214-578-5391


                
__________________________________ 
Start your day with Yahoo! - Make it your home page! 
http://www.yahoo.com/r/hs

<Prev in Thread] Current Thread [Next in Thread>