Amanda-Users

Firewall, amanda client and ports

2007-07-18 08:49:19
Subject: Firewall, amanda client and ports
From: Charles Stroom <charles AT stremen.xs4all DOT nl>
To: amanda-users AT amanda DOT org
Date: Wed, 18 Jul 2007 14:15:56 +0200
Greetings,

my server (fiume) and my client (stremen) both have a firewall and the
client fails to be backed up (the server goes fine).  amcheck reports
no problem.  On the client, I have opened TCP/UDP port 10080, and TCP
ports 10082 and 10083, because I seem to have seen something like that
when googling.

I have also seen that apparently the data connection between server and
client at the time of the actual backup uses a variety of ports, or are
looking for free ports, but I do not understand really all this.  Below
are the relevant error messages:


Hostname: fiume
Org     : daily_backup
Config  : daily
Date    : July 18, 2007

These dumps were to tape daily-09.
The next tape Amanda expects to use is: daily-10.

FAILURE AND STRANGE DUMP SUMMARY:
  stremen.localnet  /      lev 0  FAILED [cannot read header: got 0 instead of 
32768]
  stremen.localnet  /      lev 0  FAILED [too many dumper retry: "[could not 
connect DATA stream: can't connect stream to stremen.localnet port 22580: 
Connection timed out]"]
  stremen.localnet  /      lev 0  FAILED [cannot read header: got 0 instead of 
32768]
  stremen.localnet  /usr   lev 0  FAILED [cannot read header: got 0 instead of 
32768]
  stremen.localnet  /usr   lev 0  FAILED [cannot read header: got 0 instead of 
32768]
  stremen.localnet  /usr   lev 0  FAILED [too many dumper retry: "[could not 
connect DATA stream: can't connect stream to stremen.localnet port 12327: 
Connection timed out]"]
  stremen.localnet  /var   lev 0  FAILED [cannot read header: got 0 instead of 
32768]
  stremen.localnet  /var   lev 0  FAILED [too many dumper retry: "[could not 
connect DATA stream: can't connect stream to stremen.localnet port 10731: 
Connection timed out]"]
  stremen.localnet  /var   lev 0  FAILED [cannot read header: got 0 instead of 
32768]
  stremen.localnet  /opt   lev 0  FAILED [cannot read header: got 0 instead of 
32768]
  stremen.localnet  /opt   lev 0  FAILED [cannot read header: got 0 instead of 
32768]
  stremen.localnet  /opt   lev 0  FAILED [too many dumper retry: "[could not 
connect DATA stream: can't connect stream to stremen.localnet port 8232: 
Connection timed out]"]
  stremen.localnet  /home  lev 0  FAILED [cannot read header: got 0 instead of 
32768]
  stremen.localnet  /home  lev 0  FAILED [cannot read header: got 0 instead of 
32768]
  stremen.localnet  /home  lev 0  FAILED [too many dumper retry: "[could not 
connect DATA stream: can't connect stream to stremen.localnet port 21891: 
Connection timed out]"]
  stremen.localnet  /boot  lev 0  FAILED [cannot read header: got 0 instead of 
32768]
  stremen.localnet  /boot  lev 0  FAILED [too many dumper retry: "[could not 
connect DATA stream: can't connect stream to stremen.localnet port 24997: 
Connection timed out]"]
  stremen.localnet  /boot  lev 0  FAILED [cannot read header: got 0 instead of 
32768]


STATISTICS:
                          Total       Full      Incr.
                        --------   --------   --------
Estimate Time (hrs:min)    0:02
Run Time (hrs:min)         0:46
Dump Time (hrs:min)        0:05       0:02       0:03
Output Size (meg)        2546.2     1606.8      939.4
Original Size (meg)      2546.2     1606.8      939.4
Avg Compressed Size (%)     --         --         --    (level:#disks ...)
Filesystems Dumped            9          2          7   (1:6 2:1)
Avg Dump Rate (k/s)      8428.7    11827.1     5651.2

Tape Time (hrs:min)        0:28       0:17       0:12
Tape Size (meg)          2546.4     1606.8      939.5
Tape Used (%)              20.7       13.1        7.6   (level:#disks ...)
Filesystems Taped             9          2          7   (1:6 2:1)

Chunks Taped                  0          0          0
Avg Tp Write Rate (k/s)  1530.3     1634.8     1379.4

USAGE BY TAPE:
  Label          Time      Size      %    Nb    Nc
  daily-09       0:28  2607488K   20.7     9     0

[......]

DUMP SUMMARY:
                                       DUMPER STATS               TAPER STATS 
HOSTNAME     DISK        L ORIG-KB  OUT-KB  COMP%  MMM:SS   KB/s MMM:SS   KB/s
-------------------------- ------------------------------------- -------------
fiume.localn /           1    3670    3680    --     0:04  832.2   0:04  887.1
fiume.localn /boot       1      10      32    --     0:00  666.2   0:01   24.1
fiume.localn /home       2  928560  928576    --     1:36 9640.8  11:15 1375.9
fiume.localn -s/pictures 1     870     896    --     0:06  139.1   0:02  554.9
fiume.localn /local      1      10      32    --     0:05    2.0   0:01   24.1
fiume.localn /opt        0 1135990 1136000    --     1:39 11467.0  11:31 1644.7
fiume.localn /usr        1   28480   28480    --     0:57  503.2   0:13 2231.8
fiume.localn /usr/local  1     360     384    --     0:02  225.7   0:01  268.6
fiume.localn /var        0  509400  509408    --     0:40 12717.5   5:16 1613.2
stremen.loca /           0 FAILED --------------------------------------------
stremen.loca /boot       0 FAILED --------------------------------------------
stremen.loca /home       0 FAILED --------------------------------------------
stremen.loca /opt        0 FAILED --------------------------------------------
stremen.loca /usr        0 FAILED --------------------------------------------
stremen.loca /var        0 FAILED --------------------------------------------

(brought to you by Amanda version 2.5.2p1)

It looks as if everytime another port is used, but is this TCP or UDP?
Can somebody tell me what I have to tell the firewall (on opensuse 10.2), so
that it all works?

Regards,


-- 
Charles Stroom
email: charles at no-spam.stremen.xs4all.nl (remove the "no-spam.")