Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

DMZ backup across PIX Firewall failing 2

Status
Not open for further replies.

Intervoice123

IS-IT--Management
Dec 1, 2006
15
0
0
US
Hi
In the last 3 weeks, I am noticing failures on all my DMZ clients on a scheduled backup (see below). Even turning the verbose option in the group (this was a workaround I was using until I moved to 7.2 last year) fails. I do not recall making any changes on the PIX firewall. Assuming they were some changes, can someone please tell me exactly what ports (bi-directional?) need to be opened between the internal backup server and the DMZ clients. I am running Legato Networker 7.2 (Build 172). PIX FW version 6.x When I do an rpcinfo -p from DMZ client, I get "can't contact lgtomapper: Remote system error - Connection timed out". nslookup, ping by short and FQDN works from both ends. Thx for your time.

DMZclient:All 1 retry attempted
* DMZclient:All rcmd DMZclient, user root: `savefs -s backup_server -c DMZclient -g PIX -p -l full -R -v'
DMZclient: Connection refused
* DMZclient:All 02/12/07 17:01:33 nsrexec: SYSTEM error: Connection refused
* DMZclient:All 02/12/07 17:01:02 nsrexec: nsrexecd on DMZclient is unavailable. Using rsh instead.
 
The client's service ports to contact are 7937 & 7938. Same goes for the server to establish connection.

The messages however indicate that the client listener (nsrexecd) is not running. It also works as portmapper.
 
Thx for your response. I presume this is TCP 7937, 7938 - both inbound and outbound. nsrexecd is running on client and server.
Raghu
 
Actually, these are "service ports" (inbound). The ooutbound "connection ports" are not considered dangerous any longer.
 
Thx. In Firewall, I have to specy if it is TCP or UDP. What is port 10000.? Thx
Raghu
 
Not sure what Port 10000 is for?

10001 is the start of the "data stream ports". Networker uses ports 10001-30000 to stream the data to the storage node or server.

Other ports to check are 111, 514, 7937-9936.
 
If you mean that port 10000 also works as a service port, this is correct - NW uses it for the NDMP Tape Services, if installed.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top