Re: Connection manager redirect
Posted in 2009
A MACH11 setup (primary + SDS) placed Connection Manager in a DMZ so public clients could reach servers on a private network. Clients connected to CM fine, but then failed with network errors. Answer from IBM folks: Connection Manager only redirects/initiates the connection; after redirection the client talks directly to the IDS server using the host/IP from sqlhosts, so clients must be able to reach the database server directly — CM is not a proxy for transactions. No config fix was offered; one poster suggested looking at MaxConnect (similar setup) if security/routing is the concern.
Auto-generated by DrWatson from the posts below — may be imperfect; read the full thread.
Topics: High Availability & Replication, Error Codes & Troubleshooting, Security, Permissions & Auditing, Networking & sqlhosts Configuration, Clustering, Grid & MACH11
What kind of error clients are getting ?
Regards,
Nilesh.,
ids-bounces@iiug.org wrote on 05/05/2009 05:08:25 PM:
> [image removed]
>
> Connection manager redirect [15681]
>
> VIVIAN JONES
>
> to:
>
> ids
>
> 05/05/2009 05:09 PM
>
> Sent by:
>
> ids-bounces@iiug.org
>
> Please respond to ids
>
> We implement a MACH11 environment (one primary server, one SDS server and
two
> connection managers in separate machines); when any client (in a public
> network) establish a connection with the connection manager (DMZ
network),
> this last one redirect the connection to the selected IDS instance
(private
> network), but the instance response directly to the client and in the
same
> session when the client need to establish a communication go directly to
the
> IDS instance without using the connection manager, reporting an error
because
> the client dont know the IP private address of the IDS server.
>
> here the configuration files:
>
> ENVIRONMENT VARIABLES AT CONNECTION MANAGER SERVER
> INFORMIXSQLHOSTS=/informix/etc/sqlhosts
> INFORMIXDIR=/informix
> INFORMIXSERVER=sefin_tcp>
> CONNECTION MANAGER CONFIG FILE
> # Connection Manager name
> NAME cm3
> # re-route Informix clients to the primary for transaction processing
> SLA sefincm1_tcp=(PRI+SDS)
> # Failover Configuration
> FOC SDS,0
> # worker threads for each SLA listener, default is 8
> SLA_WORKERS 16
> #Debugging
> DEBUG 1
> # Connection Manager message file
> LOGFILE /informix/cm3.log
>
> SQLHOSTS AT CONNECTION MANAGER SERVER
> sefincm_tcp group - - c=1
> #Primary Connection Manager server
> sefincm1_tcp onsoctcp 10.4.74.121 4950 g=sefincm_tcp
> sefincm2_tcp onsoctcp 192.168.41.42 4950 g=sefincm_tcp,s=6
> sefincm3_tcp onsoctcp 192.168.41.43 4950 g=sefincm_tcp,s=6
> sefincm4_tcp onsoctcp 192.168.41.44 4950 g=sefincm_tcp,s=6
> #Secondary Connection Manager server
> sefincm11_tcp onsoctcp 192.168.41.141 4950 g=sefincm_tcp,s=6
> sefincm12_tcp onsoctcp 192.168.41.142 4950 g=sefincm_tcp,s=6
> sefincm13_tcp onsoctcp 192.168.41.143 4950 g=sefincm_tcp,s=6
> sefincm14_tcp onsoctcp 192.168.41.144 4950 g=sefincm_tcp,s=6
> sefin_tcpg group - - c=1
> # Primary Server
> sefin_tcp onsoctcp 192.168.41.21 1525 g=sefin_tcpg,s=6
> sefin_tcp2 onsoctcp 192.168.41.22 1525 g=sefin_tcpg,s=6
> sefin_tcp3 onsoctcp 192.168.41.23 1525 g=sefin_tcpg,s=6
> sefin_tcp4 onsoctcp 192.168.41.24 1525 g=sefin_tcpg,s=6
> # SDS Server
> sefinsds_tcp onsoctcp 192.168.41.121 1525 g=sefin_tcpg,s=6
> sefinsds_tcp2 onsoctcp 192.168.41.122 1525 g=sefin_tcpg,s=6
> sefinsds_tcp3 onsoctcp 192.168.41.123 1525 g=sefin_tcpg,s=6
> sefinsds_tcp4 onsoctcp 192.168.41.124 1525 g=sefin_tcpg,s=6
>
> CONNECTION MANAGER LOG FILE
> Tue May 5 11:54:19 2009
> 11:54:19 IBM Informix Connection Manager
> 11:54:19 Connection Manager name is cm3
> 11:54:19 Starting Connection Manager...
> 11:54:19 stat(/informix/etc/passwd_file) failed, errno = 2
> 11:54:19 Warning: Password Manager failed; working in trusted node mode
> 11:54:19 Current max open fd is 2000
> 11:54:19 fcntl(/informix/tmp/cmsm.pid.cm3) success errno = 0
> 11:54:19 dbservername = sefin_tcp
> 11:54:19 nettype = onsoctcp
> 11:54:19 hostname = 192.168.41.21
> 11:54:19 servicename = 1525
> 11:54:19 options = g=sefin_tcpg,s=6
> 11:54:19 switch to daemon mode
> 11:54:19 new daemon pid is 467036
> 11:54:19 create new thread 772 for sefin_tcp
> 11:54:19 listener sefincm1_tcp initializing
> 11:54:19 Listener sefincm1_tcp=(PRI) is active with 16 worker threads
> 11:54:19 Connection Manager successfully connected to sefin_tcp
> 11:54:19 sefin_tcp protocols = 1
> 11:54:19 fetch sysconfig_cursor sqlcode = (100,0,)
> 11:54:19 Adding server sefin_tcp
> 11:54:19 Arbitrator FOC string = DISABLED,0
> 11:54:19 Arbitrator setting primary name = sefin_tcp
> 11:54:19 FOC: Failover Arbitrator disabled
> 11:54:19 FOC timeout = 0
> 11:54:19 get sefin_tcp CM_ADM event 8:3 cm3
> 11:54:19 Arbitrator received CM event, subtype=3, cm=cm3
> 11:54:19 Arbitrator reinitialized CM names
> 11:54:19 Arbitrator added CM name = cm3
> 11:54:19 Arbitrator is active on CM = cm3
> 11:54:20 Connection Manager started successfully
> 11:55:33 SLA sefincm1_tcp redirect SQLI client from 10.4.25.57 to
sefin_tcp
> 192.
> 168.41.21.1525
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
A Network error, because the client at the public network can't connect directly to the IDS server at the private network, it's for that reason we use the connection manager between them. We want to know if always the connection manager is used only to the initial connection to the instance, and the on going communication between the client and the instance go directly without go throw the connection manager?
The connection manager is only used to initiate the connection. = "VIVIAN JONES" = <jones@itconsulti = ngs.net> = To Sent by: ids@iiug.org = ids-bounces@iiug. = cc org = Subj= ect Re: Connection manager redirect = 05/05/2009 08:34 [15683] = PM = = = Please respond to = ids@iiug.org = = = A Network error, because the client at the public network can't connect= directly to the IDS server at the private network, it's for that reason= we use the connection manager between them. We want to know if always the connection manager is used only to the initial connection to the instance, and the= on going communication between the client and the instance go directly wit= hout go throw the connection manager? ***********************************************************************= ******** Forum Note: Use "Reply" to post a response in the discussion forum. =
Hi Madison, and how we work around this problem, because in a real situation when we have remote clients connecting throw the connection manager, the information that receive the client about the way to connect directly to the IDS server is the same that the server has at the sqlhosts file, corresponding to a private IP address, that is unknown for the client.
Connection manager only redirects connection and it was not designed to
redirect or handle transactions. Your clients need to communicate with the
server in DMZ directly.
Regards,
-Ping
--- On Tue, 5/5/09, Nilesh Ozarkar <nilesho@us.ibm.com> wrote:
> From: Nilesh Ozarkar <nilesho@us.ibm.com>
> Subject: Re: Connection manager redirect [15682]
> To: ids@iiug.org
> Date: Tuesday, May 5, 2009, 6:43 PM
> What kind of error clients are
> getting ?
>
> Regards,
> Nilesh.,
>
> ids-bounces@iiug.org
> wrote on 05/05/2009 05:08:25 PM:
>
> > [image removed]
> >
> > Connection manager redirect [15681]
> >
> > VIVIAN JONES
> >
> > to:
> >
> > ids
> >
> > 05/05/2009 05:09 PM
> >
> > Sent by:
> >
> > ids-bounces@iiug.org
>
> >
> > Please respond to ids
> >
> > We implement a MACH11 environment (one primary server,
> one SDS server and
> two
> > connection managers in separate machines); when any
> client (in a public
> > network) establish a connection with the connection
> manager (DMZ
> network),
> > this last one redirect the connection to the selected
> IDS instance
> (private
> > network), but the instance response directly to the
> client and in the
> same
> > session when the client need to establish a
> communication go directly to
> the
> > IDS instance without using the connection manager,
> reporting an error
> because
> > the client dont know the IP private address of the IDS
> server.
> >
> > here the configuration files:
> >
> > ENVIRONMENT VARIABLES AT CONNECTION MANAGER SERVER
> > INFORMIXSQLHOSTS=/informix/etc/sqlhosts
> > INFORMIXDIR=/informix
> > INFORMIXSERVER=sefin_tcp> >
> > CONNECTION MANAGER CONFIG FILE
> > # Connection Manager name
> > NAME cm3
> > # re-route Informix clients to the primary for
> transaction processing
> > SLA sefincm1_tcp=(PRI+SDS)
> > # Failover Configuration
> > FOC SDS,0
> > # worker threads for each SLA listener, default is 8
> > SLA_WORKERS 16
> > #Debugging
> > DEBUG 1
> > # Connection Manager message file
> > LOGFILE /informix/cm3.log
> >
> > SQLHOSTS AT CONNECTION MANAGER SERVER
> > sefincm_tcp group - - c=1
> > #Primary Connection Manager server
> > sefincm1_tcp onsoctcp 10.4.74.121 4950 g=sefincm_tcp
> > sefincm2_tcp onsoctcp 192.168.41.42 4950
> g=sefincm_tcp,s=6
> > sefincm3_tcp onsoctcp 192.168.41.43 4950
> g=sefincm_tcp,s=6
> > sefincm4_tcp onsoctcp 192.168.41.44 4950
> g=sefincm_tcp,s=6> > #Secondary Connection Manager server
> > sefincm11_tcp onsoctcp 192.168.41.141 4950
> g=sefincm_tcp,s=6
> > sefincm12_tcp onsoctcp 192.168.41.142 4950
> g=sefincm_tcp,s=6
> > sefincm13_tcp onsoctcp 192.168.41.143 4950
> g=sefincm_tcp,s=6
> > sefincm14_tcp onsoctcp 192.168.41.144 4950
> g=sefincm_tcp,s=6
> > sefin_tcpg group - - c=1> > # Primary Server
> > sefin_tcp onsoctcp 192.168.41.21 1525 g=sefin_tcpg,s=6
>
> > sefin_tcp2 onsoctcp 192.168.41.22 1525
> g=sefin_tcpg,s=6
> > sefin_tcp3 onsoctcp 192.168.41.23 1525
> g=sefin_tcpg,s=6
> > sefin_tcp4 onsoctcp 192.168.41.24 1525
> g=sefin_tcpg,s=6> > # SDS Server
> > sefinsds_tcp onsoctcp 192.168.41.121 1525
> g=sefin_tcpg,s=6
> > sefinsds_tcp2 onsoctcp 192.168.41.122 1525
> g=sefin_tcpg,s=6
> > sefinsds_tcp3 onsoctcp 192.168.41.123 1525
> g=sefin_tcpg,s=6
> > sefinsds_tcp4 onsoctcp 192.168.41.124 1525
> g=sefin_tcpg,s=6> >
> > CONNECTION MANAGER LOG FILE
> > Tue May 5 11:54:19 2009
> > 11:54:19 IBM Informix Connection Manager
> > 11:54:19 Connection Manager name is cm3
> > 11:54:19 Starting Connection Manager...
> > 11:54:19 stat(/informix/etc/passwd_file) failed, errno
> = 2
> > 11:54:19 Warning: Password Manager failed; working in
> trusted node mode
> > 11:54:19 Current max open fd is 2000
> > 11:54:19 fcntl(/informix/tmp/cmsm.pid.cm3) success
> errno = 0
> > 11:54:19 dbservername = sefin_tcp
> > 11:54:19 nettype = onsoctcp
> > 11:54:19 hostname = 192.168.41.21
> > 11:54:19 servicename = 1525
> > 11:54:19 options = g=sefin_tcpg,s=6
> > 11:54:19 switch to daemon mode
> > 11:54:19 new daemon pid is 467036
> > 11:54:19 create new thread 772 for sefin_tcp
> > 11:54:19 listener sefincm1_tcp initializing
> > 11:54:19 Listener sefincm1_tcp=(PRI) is active with 16
> worker threads
> > 11:54:19 Connection Manager successfully connected to
> sefin_tcp
> > 11:54:19 sefin_tcp protocols = 1
> > 11:54:19 fetch sysconfig_cursor sqlcode = (100,0,)
> > 11:54:19 Adding server sefin_tcp
> > 11:54:19 Arbitrator FOC string = DISABLED,0
> > 11:54:19 Arbitrator setting primary name = sefin_tcp
> > 11:54:19 FOC: Failover Arbitrator disabled
> > 11:54:19 FOC timeout = 0
> > 11:54:19 get sefin_tcp CM_ADM event 8:3 cm3
> > 11:54:19 Arbitrator received CM event, subtype=3,
> cm=cm3
> > 11:54:19 Arbitrator reinitialized CM names
> > 11:54:19 Arbitrator added CM name = cm3
> > 11:54:19 Arbitrator is active on CM = cm3
> > 11:54:20 Connection Manager started successfully
> > 11:55:33 SLA sefincm1_tcp redirect SQLI client from
> 10.4.25.57 to
> sefin_tcp
> > 192.
> > 168.41.21.1525
> >
> >
> >
>
>
*******************************************************************************
>
>
> > Forum Note: Use "Reply" to post a response in the
> discussion forum.
> >
>
>
>
*******************************************************************************
>
> Forum Note: Use "Reply" to post a response in the
> discussion forum.
>
>
If the security is the main concern, you can have a try with MaxConnect, setting up MaxConnect is very similar to Connection Manager. you can find more information about MaxConnect at http://publib.boulder.ibm.com/infocenter/idshelp/v10/index.jsp?topic=/com.ibm.ad min.doc/admin169.htm Regards