NFS with Virtual IP and Firewall

From: Jeff Germain (j.germain@xpedite.com)
Date: Wed Apr 28 2004 - 19:04:19 EDT


Mgrs,

There is a post from Jan 2004 concerning this topic, but with no summary [
so far :-) ].

I've got:
- host A with address ..12.1 sharing out an NFS fileystem.
- host A has a virtual IP address ..12.99 defined in DNS as host AB1.
- host X is on the other side of a firewall, with address ..11.3.

Host X issues "mount AB1:/<filesystem>", which hangs.

It is verified that X can issue "mount A:/<filesystem>" with no problem -
filesystem gets mounted. I've also verified that "mount AB1:/<filesystem>"
works from client T that has no firewall between it and the server. Snoop
output shows that the request from T --> AB1 is issued, but the response is
in the form A --> T, not AB1 --> T. So we're guessing the firewall
considers the response unsolicited and is blocking it.

The earlier post was using a different Firewall (PIX .vs. NetScreen) but the
same issue. I imagine this would be a common problem for Cluster
implementations, but I haven't seen a solution or workaround posted.

Any ideas are welcome - will summarize.

Thanks,

Jeff
_______________________________________________
sunmanagers mailing list
sunmanagers@sunmanagers.org
http://www.sunmanagers.org/mailman/listinfo/sunmanagers



This archive was generated by hypermail 2.1.7 : Wed Apr 09 2008 - 23:28:33 EDT