Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

SQL 2005 Clustered Mirroring through a firewall??

Status
Not open for further replies.

Hondy

Technical User
Mar 3, 2003
864
GB
Hi

We have a remote mirror set up, full IP access works fine with our custom ports.

The problem is when using the browser service that is a part of the mirror set up.

one server initiates a 1434 UDP to the destination server, then the desintation server replies with by sending a UDP to a dynamic port.

The SQL service is already running custom ports in the Network Configuration.

But how do you fix the UDP reply to a specific port?

Thanks
 
to simplify my question I have read up further.

The source server makes an SSRP to 1434 using a dynamic port and the destination browser service replies to the original source address and port.

So how do you fix the source port on the server that initiates the SSRP request to the 1434 browser service?

Cheers!
 
You don't. That's the way that TCP and UDP communications work. The destination port number is always known, but the source port number is never known because Windows will assign the source application what ever port number is available.

The firewall should be smart enough to see what port the communication is coming from and allow the communication to return along the same path.

Denny
MCSA (2003) / MCDBA (SQL 2000)
MCTS (SQL 2005 / Microsoft Windows SharePoint Services 3.0: Configuration / Microsoft Office SharePoint Server 2007: Configuration)
MCITP Database Administrator (SQL 2005) / Database Developer (SQL 2005)

My Blog
 
yeh, it "should" be smart enough, but its UDP so its stateless. Once it has shot the request off it is gone.

So are you saying you can NEVER fix a source port? so then you can never secure that comms! Surely you can specify a source port in some registry setting somewhere other wise how can you tighten it down?

Cheers

 
As far as I know there is no way to fix a source port. If there was, what happens if that port is in use by something else?

Denny
MCSA (2003) / MCDBA (SQL 2000)
MCTS (SQL 2005 / Microsoft Windows SharePoint Services 3.0: Configuration / Microsoft Office SharePoint Server 2007: Configuration)
MCITP Database Administrator (SQL 2005) / Database Developer (SQL 2005)

My Blog
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top