ER - Primary -Target (firewall issue)
Posted in 2000
A user setting up Enterprise Replication (primary-target) couldn't initialise it because the primary server sat behind a firewall: the primary could reach the target, but not vice versa, so 'cdr define server --init --sync' failed with "unable to connect to server specified (5)" and -908 connect errors in the target's log. Madison Pruet explained that ER attempts connections from both sides but only one needs to succeed, and that 'cdr define server' must run on the server being defined. Reversing the order — defining the target first, then syncing the primary to it — solved it. He warned that with multiple target servers you'd still need to bypass the firewall during setup.
Auto-generated by DrWatson from the posts below — may be imperfect; read the full thread.
Topics: Server Administration, Security, Permissions & Auditing
Hi!
I'm trying to set up a Primary-Target replication involving two
servers. The issue is that the Primary server is behind the firewall. I
can get to the target from the primary without inputting the username
and password using dbaccess but since the primary is behind the
firewall, I can't get to it from the target.
The question is, since I'm only going to replicate data from the
primary server to the target server, shouldn't this be possible?
Thanks in advance,
Zandy
Sent via Deja.com
http://www.deja.com/
ER tries to establish a connection from both servers. Of course only one
of these connections has to be successful.
I'm not that familar with firewalls, so I'm not sure of the problems that
you would encounter. However, I do know that the connection between two
servers is attempted to be established from both of the two servers. I
would make sure that the CDRid of the primary server is the lower number of
the two.
Lyzander Marantal wrote:
> Hi!
>
> I'm trying to set up a Primary-Target replication involving two
> servers. The issue is that the Primary server is behind the firewall. I
> can get to the target from the primary without inputting the username
> and password using dbaccess but since the primary is behind the
> firewall, I can't get to it from the target.
>
> The question is, since I'm only going to replicate data from the
> primary server to the target server, shouldn't this be possible?
>
> Thanks in advance,
>
> Zandy
>
> Sent via Deja.com
> http://www.deja.com/
Thanks for your reply Madison.
Unfortunately, it seems that its not at all possible. I've changed the
CDRid as you've suggested, but still, to no avail.
Here's the command I used to intialize CDR on the target server(ran
this on the primary server):
xeasmtst>cdr define server --connect imoss_net --init --sync g_xeasmtst
g_xeasmdev
I got this error:
command failed -- unable to connect to server specified (5)
And here's the log from the target database:
17:20:58 Building 'syscdr' database ...
17:21:03 'syscdr' database built successfully.
17:21:05 CDR queuer initialization complete
17:21:09 Checkpoint Completed: duration was 1 seconds.
17:23:05 CDR connection to server lost, id 50, name <g_xeasmtst>Reason: Connect failed reason: -908
17:23:05 CDR GC: operation sync connect failed (error 5).
17:23:05 CDR GC: synchronization failed (sync abort, shutting down CDR)
17:23:05 CDR NIF Shutdown: connections all shutdown.
17:23:05 CDR The NIF sub-component has shut down.
17:23:05 CDR shutdown complete
It seems that the target server is trying to connect to the primary
behind the firewall on its own, which of course, it wasn't able to do.
Any ideas?
Thanks again,
Zandy
In article <3A37937B.81892E94@home.com>,
Madison Pruet <mpruet@home.com> wrote:
> ER tries to establish a connection from both servers. Of course only
one
> of these connections has to be successful.
>
> I'm not that familar with firewalls, so I'm not sure of the problems
that
> you would encounter. However, I do know that the connection between
two
> servers is attempted to be established from both of the two servers.
I
> would make sure that the CDRid of the primary server is the lower
number of
> the two.
>
> Lyzander Marantal wrote:
>
> > Hi!
> >
> > I'm trying to set up a Primary-Target replication involving two
> > servers. The issue is that the Primary server is behind the
firewall. I
> > can get to the target from the primary without inputting the
username
> > and password using dbaccess but since the primary is behind the
> > firewall, I can't get to it from the target.
> >
> > The question is, since I'm only going to replicate data from the
> > primary server to the target server, shouldn't this be possible?
> >
> > Thanks in advance,
> >
> > Zandy
> >
> > Sent via Deja.com
> > http://www.deja.com/
>
>
Sent via Deja.com
http://www.deja.com/
You could try to reverse the order and define the target server first, then
sync your primary to it.
The define server must be executed on the server being defined. All of the
other commands can be executed on any non-leaf server.
Lyzander Marantal wrote:
> Thanks for your reply Madison.
>
> Unfortunately, it seems that its not at all possible. I've changed the
> CDRid as you've suggested, but still, to no avail.
>
> Here's the command I used to intialize CDR on the target server(ran
> this on the primary server):
> xeasmtst>cdr define server --connect imoss_net --init --sync g_xeasmtst
> g_xeasmdev
> I got this error:
> command failed -- unable to connect to server specified (5)
>
> And here's the log from the target database:
>
> 17:20:58 Building 'syscdr' database ...
> 17:21:03 'syscdr' database built successfully.
> 17:21:05 CDR queuer initialization complete
> 17:21:09 Checkpoint Completed: duration was 1 seconds.
> 17:23:05 CDR connection to server lost, id 50, name <g_xeasmtst>> Reason: Connect failed reason: -908
> 17:23:05 CDR GC: operation sync connect failed (error 5).
> 17:23:05 CDR GC: synchronization failed (sync abort, shutting down CDR)
> 17:23:05 CDR NIF Shutdown: connections all shutdown.
> 17:23:05 CDR The NIF sub-component has shut down.
> 17:23:05 CDR shutdown complete>
> It seems that the target server is trying to connect to the primary
> behind the firewall on its own, which of course, it wasn't able to do.
>
> Any ideas?
>
> Thanks again,
> Zandy
>
> In article <3A37937B.81892E94@home.com>,
> Madison Pruet <mpruet@home.com> wrote:
> > ER tries to establish a connection from both servers. Of course only
> one
> > of these connections has to be successful.
> >
> > I'm not that familar with firewalls, so I'm not sure of the problems
> that
> > you would encounter. However, I do know that the connection between
> two
> > servers is attempted to be established from both of the two servers.
> I
> > would make sure that the CDRid of the primary server is the lower
> number of
> > the two.
> >
> > Lyzander Marantal wrote:
> >
> > > Hi!
> > >
> > > I'm trying to set up a Primary-Target replication involving two
> > > servers. The issue is that the Primary server is behind the
> firewall. I
> > > can get to the target from the primary without inputting the
> username
> > > and password using dbaccess but since the primary is behind the
> > > firewall, I can't get to it from the target.
> > >
> > > The question is, since I'm only going to replicate data from the
> > > primary server to the target server, shouldn't this be possible?
> > >
> > > Thanks in advance,
> > >
> > > Zandy
> > >
> > > Sent via Deja.com
> > > http://www.deja.com/
> >
> >
>
> Sent via Deja.com
> http://www.deja.com/
Thank you! Thank you! Thank you!
Madison, You're da man! That worked.
I called Tech-support about this problem before posting here but got
the reply that it is not at all possible. They told me that both
servers need to talk to each other. What a bunch of ********!
Again, a million thanks,
Zandy
In article <3A380900.A86C8823@home.com>,
Madison Pruet <mpruet@home.com> wrote:
> You could try to reverse the order and define the target server
first, then
> sync your primary to it.
>
> The define server must be executed on the server being defined. All
of the
> other commands can be executed on any non-leaf server.
>
> Lyzander Marantal wrote:
>
> > Thanks for your reply Madison.
> >
> > Unfortunately, it seems that its not at all possible. I've changed
the
> > CDRid as you've suggested, but still, to no avail.
> >
> > Here's the command I used to intialize CDR on the target server(ran
> > this on the primary server):
> > xeasmtst>cdr define server --connect imoss_net --init --sync
g_xeasmtst
> > g_xeasmdev
> > I got this error:
> > command failed -- unable to connect to server specified (5)
> >
> > And here's the log from the target database:
> >
> > 17:20:58 Building 'syscdr' database ...
> > 17:21:03 'syscdr' database built successfully.
> > 17:21:05 CDR queuer initialization complete
> > 17:21:09 Checkpoint Completed: duration was 1 seconds.
> > 17:23:05 CDR connection to server lost, id 50, name <g_xeasmtst>> > Reason: Connect failed reason: -908
> > 17:23:05 CDR GC: operation sync connect failed (error 5).
> > 17:23:05 CDR GC: synchronization failed (sync abort, shutting down
CDR)
> > 17:23:05 CDR NIF Shutdown: connections all shutdown.
> > 17:23:05 CDR The NIF sub-component has shut down.
> > 17:23:05 CDR shutdown complete> >
> > It seems that the target server is trying to connect to the primary
> > behind the firewall on its own, which of course, it wasn't able to
do.
> >
> > Any ideas?
> >
> > Thanks again,
> > Zandy
> >
> > In article <3A37937B.81892E94@home.com>,
> > Madison Pruet <mpruet@home.com> wrote:
> > > ER tries to establish a connection from both servers. Of course
only
> > one
> > > of these connections has to be successful.
> > >
> > > I'm not that familar with firewalls, so I'm not sure of the
problems
> > that
> > > you would encounter. However, I do know that the connection
between
> > two
> > > servers is attempted to be established from both of the two
servers.
> > I
> > > would make sure that the CDRid of the primary server is the lower
> > number of
> > > the two.
> > >
> > > Lyzander Marantal wrote:
> > >
> > > > Hi!
> > > >
> > > > I'm trying to set up a Primary-Target replication involving two
> > > > servers. The issue is that the Primary server is behind the
> > firewall. I
> > > > can get to the target from the primary without inputting the
> > username
> > > > and password using dbaccess but since the primary is behind the
> > > > firewall, I can't get to it from the target.
> > > >
> > > > The question is, since I'm only going to replicate data from the
> > > > primary server to the target server, shouldn't this be possible?
> > > >
> > > > Thanks in advance,
> > > >
> > > > Zandy
> > > >
> > > > Sent via Deja.com
> > > > http://www.deja.com/
> > >
> > >
> >
> > Sent via Deja.com
> > http://www.deja.com/
>
>
Sent via Deja.com
http://www.deja.com/
In the year of Our Lord Thu, 14 Dec 2000 15:25:48 GMT, Lyzander Marantal <zandy@my-deja.com> broke a vow of silence to utter: >Thank you! Thank you! Thank you! > >Madison, You're da man! That worked. If he wasn't, I'd be bloody worried!! :0)
Don't be too hard on tech support. Technically they were right. It's just
that both sides will attempt to establish the connection.
If you attempt multiple target servers, you will need to bypass the firewall
while establishing ER on the server.
Lyzander Marantal wrote:
> Thank you! Thank you! Thank you!
>
> Madison, You're da man! That worked.
>
> I called Tech-support about this problem before posting here but got
> the reply that it is not at all possible. They told me that both
> servers need to talk to each other. What a bunch of ********!
>
> Again, a million thanks,
>
> Zandy
>
> In article <3A380900.A86C8823@home.com>,
> Madison Pruet <mpruet@home.com> wrote:
> > You could try to reverse the order and define the target server
> first, then
> > sync your primary to it.
> >
> > The define server must be executed on the server being defined. All
> of the
> > other commands can be executed on any non-leaf server.
> >
> > Lyzander Marantal wrote:
> >
> > > Thanks for your reply Madison.
> > >
> > > Unfortunately, it seems that its not at all possible. I've changed
> the
> > > CDRid as you've suggested, but still, to no avail.
> > >
> > > Here's the command I used to intialize CDR on the target server(ran
> > > this on the primary server):
> > > xeasmtst>cdr define server --connect imoss_net --init --sync
> g_xeasmtst
> > > g_xeasmdev
> > > I got this error:
> > > command failed -- unable to connect to server specified (5)
> > >
> > > And here's the log from the target database:
> > >
> > > 17:20:58 Building 'syscdr' database ...
> > > 17:21:03 'syscdr' database built successfully.
> > > 17:21:05 CDR queuer initialization complete
> > > 17:21:09 Checkpoint Completed: duration was 1 seconds.
> > > 17:23:05 CDR connection to server lost, id 50, name <g_xeasmtst>> > > Reason: Connect failed reason: -908
> > > 17:23:05 CDR GC: operation sync connect failed (error 5).
> > > 17:23:05 CDR GC: synchronization failed (sync abort, shutting down
> CDR)
> > > 17:23:05 CDR NIF Shutdown: connections all shutdown.
> > > 17:23:05 CDR The NIF sub-component has shut down.
> > > 17:23:05 CDR shutdown complete> > >
> > > It seems that the target server is trying to connect to the primary
> > > behind the firewall on its own, which of course, it wasn't able to
> do.
> > >
> > > Any ideas?
> > >
> > > Thanks again,
> > > Zandy
> > >
> > > In article <3A37937B.81892E94@home.com>,
> > > Madison Pruet <mpruet@home.com> wrote:
> > > > ER tries to establish a connection from both servers. Of course
> only
> > > one
> > > > of these connections has to be successful.
> > > >
> > > > I'm not that familar with firewalls, so I'm not sure of the
> problems
> > > that
> > > > you would encounter. However, I do know that the connection
> between
> > > two
> > > > servers is attempted to be established from both of the two
> servers.
> > > I
> > > > would make sure that the CDRid of the primary server is the lower
> > > number of
> > > > the two.
> > > >
> > > > Lyzander Marantal wrote:
> > > >
> > > > > Hi!
> > > > >
> > > > > I'm trying to set up a Primary-Target replication involving two
> > > > > servers. The issue is that the Primary server is behind the
> > > firewall. I
> > > > > can get to the target from the primary without inputting the
> > > username
> > > > > and password using dbaccess but since the primary is behind the
> > > > > firewall, I can't get to it from the target.
> > > > >
> > > > > The question is, since I'm only going to replicate data from the
> > > > > primary server to the target server, shouldn't this be possible?
> > > > >
> > > > > Thanks in advance,
> > > > >
> > > > > Zandy
> > > > >
> > > > > Sent via Deja.com
> > > > > http://www.deja.com/
> > > >
> > > >
> > >
> > > Sent via Deja.com
> > > http://www.deja.com/
> >
> >
>
> Sent via Deja.com
> http://www.deja.com/