Networker

Re: [Networker] NetWorker over SSH Tunnel?

2009-08-22 18:37:18
Subject: Re: [Networker] NetWorker over SSH Tunnel?
From: Anacreo <anacreo AT GMAIL DOT COM>
To: NETWORKER AT LISTSERV.TEMPLE DOT EDU
Date: Sat, 22 Aug 2009 17:32:03 -0500
Well I agree I ran into all the problems you're discussing Davina which is
why I farmed it out to the group.  I didn't know about sshfs looks
interesting but not sure it would work with the maintstream OS'es like
Solaris...

We ended up doing an ssh out and do a backup via dd as well as a tar.  So we
can archive this guy off and have a fully recoverable version as well as
easy file level recovery.  It would be nice if NetWorker had a remote client
capable of delivering backups via an https stream or so.. oh well.

Thanks all for the input.

Alec

On Sat, Aug 22, 2009 at 3:16 PM, Davina Treiber <Davina.Treiber AT peevro.co 
DOT uk
> wrote:

> Anacreo wrote:
> > EMC says it can't be done... but we're a crafty lot... has anyone been
> able
> > to fire off an adhoc one time backup via an SSH remote tunnel?  I want to
> > backup a remotely hosted web server to my corporate NetWorker client...
> > I can SSH in but that's about it... my NetWorker server is NOT exposed to
> > the internet, so my outbound is a NAT from our company's shared internet
> > IP...
> >
> > Ideally a config that works from the SaveGroup interface would be great,
> but
> > I can settle for a cron job like:
> >
> > ssh -L NNN:uschi1leg01:NNN sudoroot@remotenode "sudo savefs -s localhost
> > arg1 arg2 arg3"
> >
> > I tried a few times to come up with nsrports/ssh port forwardings, but I
> > feel like if someone got this to work they put many nights into it and I
> > can't afford that amount of effort, so please share if you've gotten it
> to
> > work, no matter how convoluted.
>
> I don't think it is possible. I have used ssh tunnelling quite a bit,
> and can see the following issues:
>
> (1) There are a lot of ports that need forwarding
> (2) Some ports would need forwarding in both directions
> (3) An SSH tunnel requires that you connect to a port on the local
> machine, whereas NetWorker connects to a remote machine. It might be
> possible to do some sort of hack by messing with the hosts file, but
> even if that was possible you would need to do this on both machines.
>
> I wouldn't even want to attempt this. Perhaps you could rsync the data
> if there is not too much needing backing up.
>

To sign off this list, send email to listserv AT listserv.temple DOT edu and 
type "signoff networker" in the body of the email. Please write to 
networker-request AT listserv.temple DOT edu if you have any problems with this 
list. You can access the archives at 
http://listserv.temple.edu/archives/networker.html or
via RSS at http://listserv.temple.edu/cgi-bin/wa?RSS&L=NETWORKER