IDS 11.75 Port Restrictions
Posted in 2013
A user moving IDS 11.50 instances to RHEL4 changed the /etc/services ports for two dbservers from the 1531/1532 range to 60182/60183. The instances then listened only on 127.0.0.1 and remote clients failed with "Host unreachable - Administratively Restricted"; reverting to the low ports made everything work again. Suggestions included checking sqlhosts, bouncing the instance, file permissions, OS ephemeral/reserved port ranges (ports above 49151 are normally ephemeral), and iptables rules. Another user reported the same symptom with HDR and 5-digit ports. No definitive cause or resolution was established.
Auto-generated by DrWatson from the posts below — may be imperfect; read the full thread.
Topics: Error Codes & Troubleshooting, Platform-Specific Issues, Versions, Editions & End-of-Life
I recently moved two Informix Online servers from Solaris to a RHEL4 System running IDS 7.50 UC5. I changed the port assignments for 2 dbservers in the services file from the 1531 to 60182, and 1532 to 60183 respectively. The ip address of the server is 192.168.0.251. The command output from 'netstat -ln' showed ports 60182 and 60183 Listening, but on ip 127.0.0.1. I could not connect any clients. Received udmp packet, error code 13 - "Host unreachable - Administratively Restricted'. I turned off iptables. No effect. No change. I changed the port assignments in the services file back to 1531 & 1532. The clients could connect as before, no problems. The command output from 'netstat -ln' showed ports 1531 and 1532 Listening, but on ip 192.168.0.251. Everything works, I just do not understand why. No an urgent issue. I looked everywhere for an answer inside the Informix Doc Centers to no avail. Thanks In Advance Chet Brion -- Chesley (Chet) Brion Senior Analyst Cornell University 95 Brown Road, #230 Ithaca, NY 14850 phone: 607.257.5708 ext 4 email: cjb16@cornell.edu
I think, it seems system admin able to find out the issue from syslog message (i.e. system error log message) Thank you On Tue, Nov 5, 2013 at 10:59 PM, Chet Brion <cjb16@cornell.edu> wrote: > I recently moved two Informix Online servers from Solaris to a RHEL4 > System running IDS 7.50 UC5. > > I changed the port assignments for 2 dbservers in the services file from > the 1531 to 60182, and 1532 to 60183 respectively. The ip address of the > server is 192.168.0.251. > > The command output from 'netstat -ln' showed ports 60182 and 60183 > Listening, but on ip 127.0.0.1. > > I could not connect any clients. Received udmp packet, error code 13 - > "Host unreachable - Administratively Restricted'. > > I turned off iptables. No effect. No change. > > I changed the port assignments in the services file back to 1531 & 1532. > > The clients could connect as before, no problems. > > The command output from 'netstat -ln' showed ports 1531 and 1532 > Listening, but on ip 192.168.0.251. > > Everything works, I just do not understand why. > > No an urgent issue. I looked everywhere for an answer inside the > Informix Doc Centers to no avail. > > Thanks In Advance > > Chet Brion > > -- > Chesley (Chet) Brion > Senior Analyst > Cornell University > 95 Brown Road, #230 > Ithaca, NY 14850 > phone: 607.257.5708 ext 4 > email: cjb16@cornell.edu > > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. > > --001a1135e1f6d6276004ea6f5e0c
OK, there is no 11.75 nor 7.50, but I'll assume you mean 11.70 or 11.50, either way it doesn't matter in this case. Hmm, is it that you changed the services mentioned in the sqlhosts file to new port numbers? Does the sqlhosts file use the service names or the ports? Usually that's in $INFORMIXDIR/etc unless you have INFORMIXSQLHOSTS set in which case that variable will show the path you need. Did you bounce the instance once you changed the service ports? Need to do that. Art Art S. Kagel, Principal Consultant Advanced DataTools (www.advancedatatools.com) Blog: http://informix-myview.blogspot.com/ Disclaimer: Please keep in mind that my own opinions are my own opinions and do not reflect on my employer, Advanced DataTools, the IIUG, nor any other organization with which I am associated either explicitly, implicitly, or by inference. Neither do those opinions reflect those of other individuals affiliated with any entity with which I am affiliated nor those of the entities themselves. On Tue, Nov 5, 2013 at 6:59 AM, Chet Brion <cjb16@cornell.edu> wrote: > I recently moved two Informix Online servers from Solaris to a RHEL4 > System running IDS 7.50 UC5. > > I changed the port assignments for 2 dbservers in the services file from > the 1531 to 60182, and 1532 to 60183 respectively. The ip address of the > server is 192.168.0.251. > > The command output from 'netstat -ln' showed ports 60182 and 60183 > Listening, but on ip 127.0.0.1. > > I could not connect any clients. Received udmp packet, error code 13 - > "Host unreachable - Administratively Restricted'. > > I turned off iptables. No effect. No change. > > I changed the port assignments in the services file back to 1531 & 1532. > > The clients could connect as before, no problems. > > The command output from 'netstat -ln' showed ports 1531 and 1532 > Listening, but on ip 192.168.0.251. > > Everything works, I just do not understand why. > > No an urgent issue. I looked everywhere for an answer inside the > Informix Doc Centers to no avail. > > Thanks In Advance > > Chet Brion > > -- > Chesley (Chet) Brion > Senior Analyst > Cornell University > 95 Brown Road, #230 > Ithaca, NY 14850 > phone: 607.257.5708 ext 4 > email: cjb16@cornell.edu > > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. > > --089e01227ca472225804ea6f7448
Weird.... but you should look in the sytem.... a few notes: - we need to know the version and how did you downloa/installed the product... improper installation (file permissions) may have strange impacts - some system can be configured at the TCP level to define the possible range of ports reserved for "services" and clients. These should not overlap. - when using the low ports 127.0.0.1 does not have listeners? show us the sqlhost file Regards On Nov 5, 2013 3:00 PM, "Chet Brion" <cjb16@cornell.edu> wrote: > I recently moved two Informix Online servers from Solaris to a RHEL4 > System running IDS 7.50 UC5. > > I changed the port assignments for 2 dbservers in the services file from > the 1531 to 60182, and 1532 to 60183 respectively. The ip address of the > server is 192.168.0.251. > > The command output from 'netstat -ln' showed ports 60182 and 60183 > Listening, but on ip 127.0.0.1. > > I could not connect any clients. Received udmp packet, error code 13 - > "Host unreachable - Administratively Restricted'. > > I turned off iptables. No effect. No change. > > I changed the port assignments in the services file back to 1531 & 1532. > > The clients could connect as before, no problems. > > The command output from 'netstat -ln' showed ports 1531 and 1532 > Listening, but on ip 192.168.0.251. > > Everything works, I just do not understand why. > > No an urgent issue. I looked everywhere for an answer inside the > Informix Doc Centers to no avail. > > Thanks In Advance > > Chet Brion > > -- > Chesley (Chet) Brion > Senior Analyst > Cornell University > 95 Brown Road, #230 > Ithaca, NY 14850 > phone: 607.257.5708 ext 4 > email: cjb16@cornell.edu > > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. > > --bcaec51d255ee7c01004ea6fcaa2
is this relevant: http://www.faqs.org/docs/securing/chap6sec70.html regards, Andy. > To: ids@iiug.org > From: domusonline@gmail.com > Subject: Re: IDS 11.75 Port Restrictions [31877] > Date: Tue, 5 Nov 2013 10:36:18 -0500 > > Weird.... but you should look in the sytem.... a few notes: > - we need to know the version and how did you downloa/installed the > product... improper installation (file permissions) may have strange impacts > - some system can be configured at the TCP level to define the possible > range of ports reserved for "services" and clients. These should not > overlap. > - when using the low ports 127.0.0.1 does not have listeners? show us the > sqlhost file > > Regards > On Nov 5, 2013 3:00 PM, "Chet Brion" <cjb16@cornell.edu> wrote: > > > I recently moved two Informix Online servers from Solaris to a RHEL4 > > System running IDS 7.50 UC5. > > > > I changed the port assignments for 2 dbservers in the services file from > > the 1531 to 60182, and 1532 to 60183 respectively. The ip address of the > > server is 192.168.0.251. > > > > The command output from 'netstat -ln' showed ports 60182 and 60183 > > Listening, but on ip 127.0.0.1. > > > > I could not connect any clients. Received udmp packet, error code 13 - > > "Host unreachable - Administratively Restricted'. > > > > I turned off iptables. No effect. No change. > > > > I changed the port assignments in the services file back to 1531 & 1532. > > > > The clients could connect as before, no problems. > > > > The command output from 'netstat -ln' showed ports 1531 and 1532 > > Listening, but on ip 192.168.0.251. > > > > Everything works, I just do not understand why. > > > > No an urgent issue. I looked everywhere for an answer inside the > > Informix Doc Centers to no avail. > > > > Thanks In Advance > > > > Chet Brion > > > > -- > > Chesley (Chet) Brion > > Senior Analyst > > Cornell University > > 95 Brown Road, #230 > > Ithaca, NY 14850 > > phone: 607.257.5708 ext 4 > > email: cjb16@cornell.edu > > > > > > > > > ******************************************************************************* > > Forum Note: Use "Reply" to post a response in the discussion forum. > > > > > > --bcaec51d255ee7c01004ea6fcaa2 > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. >
1) Pardon my mis-info: We are running version 11.50. 2)The port numbers are the only thing that changed in the services file. From settings in the 1530-1535 range to 60180-60185 range. This is the question. Is there reference anywhere that states the port assignments are restricted for servicenames pertaining to dbservers? Once I changed the services file port numbers back to the 1530-1535 range, all dbservers worked fine. 3) The sqlhosts file uses the service names. 4) Yes, I bounced the instances several times. Art...Again, this is not an urgent request. I have all instances running fine with ports running in the lower port range. I want to know why this is the first time I ever ran into this problem. It has been 15 years since I started working with Informix Database products. I just can not figure out what would be stopping the connection due to the port assignment. The ports in the 60180 range are not assigned at all Thanks in advance for your responses. Please do not spend a lot of time on this.
Chesley: Ports above 49151 are officially "unreserved" and normally left unassigned to be used by listeners as ephemeral ports to assign to temporary use. For example, when you connect to Informix your session will likely be assigned a port in or above the 49000 range for communication with its poll thread in the engine. It may be that the listener code won't listen on a port number above that range by design, though why the code would ignore a port and the engine fail to start up without putting a message in the log detailing the reason, I don't know. Personally, I tend to use the old traditional SQL ports in the 152x range that Ingres, Oracle, and Informix first carved out (unofficially) years ago when I need a bunch of them at a site or the newer IANA registered Informix ports 9088 & 9089 when I only need one or two. All that said, I have no firm idea why you had trouble using the ports in the 60xxx range. Art Art S. Kagel, Principal Consultant Advanced DataTools (www.advancedatatools.com) Blog: http://informix-myview.blogspot.com/ Disclaimer: Please keep in mind that my own opinions are my own opinions and do not reflect on my employer, Advanced DataTools, the IIUG, nor any other organization with which I am associated either explicitly, implicitly, or by inference. Neither do those opinions reflect those of other individuals affiliated with any entity with which I am affiliated nor those of the entities themselves. On Tue, Nov 19, 2013 at 9:05 AM, CHESLEY BRION <cjb16@cornell.edu> wrote: > 1) Pardon my mis-info: We are running version 11.50. > > 2)The port numbers are the only thing that changed in the services file. > From > settings in the 1530-1535 range to 60180-60185 range. > > This is the question. Is there reference anywhere that states the port > assignments are restricted for servicenames pertaining to dbservers? > Once I changed the services file port numbers back to the 1530-1535 range, > all > dbservers worked fine. > > 3) The sqlhosts file uses the service names. > > 4) Yes, I bounced the instances several times. > > Art...Again, this is not an urgent request. I have all instances running > fine > with ports running in the lower port range. > > I want to know why this is the first time I ever ran into this problem. It > has > been 15 years since I started working with Informix Database products. > I just can not figure out what would be stopping the connection due to the > port assignment. The ports in the 60180 range are not assigned at all > > Thanks in advance for your responses. Please do not spend a lot of time on > this. > > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. > > --089e0158b5d430f27b04eb888163
I am afraid that I cannot offer you any answers however I did see a similar problem in the 11.5 family in that I could not start HDR with a port number in the 5 digit range. I lowered it to a 4 digit number and it worked, nothing else changed and I verified the port was not in use elsewhere. I could find nothing in documentation either. Go figure. Dan -----Original Message----- From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of CHESLEY BRION Sent: Tuesday, November 19, 2013 9:05 AM To: ids@iiug.org Subject: Re: IDS 11.75 Port Restrictions [31967] 1) Pardon my mis-info: We are running version 11.50. 2)The port numbers are the only thing that changed in the services file. From settings in the 1530-1535 range to 60180-60185 range. This is the question. Is there reference anywhere that states the port assignments are restricted for servicenames pertaining to dbservers? Once I changed the services file port numbers back to the 1530-1535 range, all dbservers worked fine. 3) The sqlhosts file uses the service names. 4) Yes, I bounced the instances several times. Art...Again, this is not an urgent request. I have all instances running fine with ports running in the lower port range. I want to know why this is the first time I ever ran into this problem. It has been 15 years since I started working with Informix Database products. I just can not figure out what would be stopping the connection due to the port assignment. The ports in the 60180 range are not assigned at all Thanks in advance for your responses. Please do not spend a lot of time on this. ******************************************************************************* Forum Note: Use "Reply" to post a response in the discussion forum.
Please have a look to your iptables. Probably the port range is blocked. With RHEL4 and iptables configured only few ports are open per default. I don't believe that it has anything to do with informix. From our Linux expert: Try iptables -nL. If the output is plenty of stuff presumably you have configured rules and the ports may be blocked by the internal firewall. HTH, Reinhard. > -----Original Message----- > From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of > CHESLEY BRION > Sent: Tuesday, November 19, 2013 3:05 PM > To: ids@iiug.org > Subject: Re: IDS 11.75 Port Restrictions [31967] > > 1) Pardon my mis-info: We are running version 11.50. > > 2)The port numbers are the only thing that changed in the services file. From > settings in the 1530-1535 range to 60180-60185 range. > > This is the question. Is there reference anywhere that states the port assignments > are restricted for servicenames pertaining to dbservers? > Once I changed the services file port numbers back to the 1530-1535 range, all > dbservers worked fine. > > 3) The sqlhosts file uses the service names. > > 4) Yes, I bounced the instances several times. > > Art...Again, this is not an urgent request. I have all instances running fine with > ports running in the lower port range. > > I want to know why this is the first time I ever ran into this problem. It has been 15 > years since I started working with Informix Database products. > I just can not figure out what would be stopping the connection due to the port > assignment. The ports in the 60180 range are not assigned at all > > Thanks in advance for your responses. Please do not spend a lot of time on this. > > > ************************************************************************ ******* > Forum Note: Use "Reply" to post a response in the discussion forum.