Veritas-bu

[Veritas-bu] NetBackup and Checkpoint Firewall

2003-02-05 11:17:59
Subject: [Veritas-bu] NetBackup and Checkpoint Firewall
From: Dale_Kramer AT steris DOT com (Kramer, Dale)
Date: Wed, 5 Feb 2003 11:17:59 -0500
Solaris 8
Netbackup 4.5

I have a system in our internal DMZ.  I can backup this system fine but I 
cannot restore to this system.  It's not the ports as the firewall is wide open 
for this system.  What I found out was that NetBackup opens a TCP connection to 
use for the restore.  Then the process finds the correct tape, mounts the tape, 
positions the tape, and then searches for the right image.  This can take 
multiple minutes.  In the meantime the opened TCP connection has only seen a 3 
way handshake with no actual data being passed.  Checkpoint has a "hidden" 
timer used for this situation with a default value of 60 seconds. So by the 
time NetBackup is ready to pass data the timeout has kicked in.  So you get the 
message in the restore log of data not being restored  and a listing of files.  
This timeout is suppose to be in the objects.C file in Checkpoint but our 
firewall guy can't find it.  Anybody know where it is?

thanx,
dale

Dale P. Kramer
Senior Systems Administrator
STERIS Corporation
5960 Heisley Rd.
Mentor, OH 44060
440-392-7082

Good news is just life's way of keeping you off balance.



<Prev in Thread] Current Thread [Next in Thread>