SNMP agent + IPMP

From: Schernau, Ed (Edward.Schernau@CITIZENSBANK.com)
Date: Thu Apr 22 2004 - 15:34:51 EDT


Hello all,

I am using an SNMP-based agent on a 480R with 2 GigE interfaces, ce0 and
ce1, configured for IP Multipathing. I do not have root, I did not set them
up. I can only connect to 1 of the aliased interfaces, the 2nd one, if I
connect to the first one, a snoop done on the machine shows my connections
to 1, but the replies coming out of the 2nd. I hope this is clear:

/etc/hosts info:
foo #grep `hostname` /etc/hosts
10.1.40.5 foo loghost
10.1.40.6 foo-dumb
10.1.40.7 foo1-2
10.1.40.8 foo1-2-dumb
10.1.55.75 fooc

ifconfig -a:
foo #/sbin/ifconfig -a
lo0: flags=1000849<UP,LOOPBACK,RUNNING,MULTICAST,IPv4> mtu 8232 index 1
        inet 127.0.0.1 netmask ff000000
ce0:
flags=9040843<UP,BROADCAST,RUNNING,MULTICAST,DEPRECATED,IPv4,NOFAILOVER> mtu
1500 index 2
        inet 10.1.40.6 netmask ffffff80 broadcast 10.1.40.127
        groupname production
ce0:1: flags=1000843<UP,BROADCAST,RUNNING,MULTICAST,IPv4> mtu 1500 index 2
        inet 10.1.40.5 netmask ffffff80 broadcast 10.1.40.127
ce1:
flags=9040843<UP,BROADCAST,RUNNING,MULTICAST,DEPRECATED,IPv4,NOFAILOVER> mtu
1500 index 3
        inet 10.1.40.8 netmask ffffff80 broadcast 10.1.40.127
        groupname production
ce1:1: flags=1000843<UP,BROADCAST,RUNNING,MULTICAST,IPv4> mtu 1500 index 3
        inet 10.1.40.7 netmask ffffff80 broadcast 10.1.40.127

I can only point my SNMP browser at the 10.1.40.7 address. If I try and
connect to the .5 address, i.e. pointing at the 'hostname' address, the
responses from my SNMP query come from 10.1.40.7, which confuses intervening
firewalls mightily.

Any solution for this? I'm no multipathing expert - can I bind ANOTHER IP
to one of the NICs, that never floats, so that inbound request traffic to
that IP comes back from the same source IP ?

TIA, will summarize

Ed Schernau
Systems Management Specialist, ECC
Citizens Bank, East Providence Operations Center
401.282.1262 ed.schernau@citizensbank.com

-----------------------------------------
Use of email is inherently insecure. Confidential information, including account information, and personally identifiable information, should not be transmitted via email, or email attachment. In no event shall Citizens or any of its affiliates accept any responsibility for the loss, use or misuse of any information including confidential information, which is sent to Citizens or its affiliates via email, or email attachment. Citizens does not guarantee the accuracy of any email or email attachment, that an email will be received by Citizens or that Citizens will respond to any email.

This email message is confidential and/or privileged. It is to be used by the intended recipient only. Use of the information contained in this email by anyone other than the intended recipient is strictly prohibited. If you have received this message in error, please notify the sender immediately and promptly destroy any record of this email.
_______________________________________________
sunmanagers mailing list
sunmanagers@sunmanagers.org
http://www.sunmanagers.org/mailman/listinfo/sunmanagers



This archive was generated by hypermail 2.1.7 : Wed Apr 09 2008 - 23:28:31 EDT