IDS on RHEL derivatives
Posted in 2009
Problem: on Linux distros (notably CentOS 5.2 and other RHEL derivatives) /etc/hosts maps the machine's own hostname to 127.0.0.1, so IDS using that name in sqlhosts listens only on loopback and remote clients can't connect; the poster found that editing /etc/hosts on CentOS seemed to break networking (slow sendmail startup, ssh sessions dropping). Advice given: check /etc/host.conf and /etc/resolv.conf resolution order, and keep 127.0.0.1 for localhost only while listing the hostname (optionally with FQDN) against the real LAN IP — reported working on genuine RHEL 4 and RHEL 5 with the server name used in sqlhosts. The poster's CentOS 5.2 trouble was not definitively resolved; he suggested trying version 4.
Auto-generated by DrWatson from the posts below — may be imperfect; read the full thread.
Topics: Networking & sqlhosts Configuration, Platform-Specific Issues
If I want to set up a server called, for instance, fred, at an IP address of, say, 10.9.8.7 then I'd expect every node on the network to recognise that as being the IP address for fred irrespective of whether it's obtained from a DNS server or /etc/hosts. But these days it seems that if fred is a Linux box it will by default be set up in /etc/hosts to have a different IP address for fred: 127.0.0.1. If the box is standalone this is reasonable but on a network ISTM both wrong and unnecessary as there's an accepted name for that address, localhost. If IDS is set up on such a server using the server name in sqlhosts it means that IDS offers connections on the loopback port instead of the physical network connection and other nodes can't connect. For some distros it's possible to override this in /etc/hosts but when I tried this on Centos 5.2, an RHEL derivative, the network failed to work reliably and when I tried Startcom, another RHEL derivative, it looked as if it was going to show similar problems. Given that IDS is compiled for RHEL what approach is used to handle this? Does genuine RHEL act differently? Is there some tweak to get round it? Should the IP address be hard-coded into sqlhosts? Should some other line be put into hosts, e.g. 10.9.8.7 self and this name used in sqlhosts? How are RHEL users handling this? -- Ian Hotmail is for spammers. Real mail address is igoddard at nildram co uk
Whoa!
Lets stop for a second.
You have DNS and you have /etc/hosts.
Going from memory, under bind8, you can set up which gets used first for ip/name lookup.
The trouble is when your network domain is foo.com and you have an entry of fred.foo.com and fred in your /etc/hosts where there are two different ip addresses.
If you're already on fred, then I think your first ip address for fred would be its loopback address. (Sorry I should know this but its been a while since I've configured a box.)
To add to this twist, you can have a hostname of fred, but you can also have interfaces with different names. This is kind of a good thing if you want to use a second nic card for a private network between servers. This will cut down on congestion. With multiple nic cards you could have one network for your database servers for ER, one network for database to web servers, and then the public interface to the internet.
But to make sure your traffice uses the correct interface, you need to set up static routes.
Getting back to your question...
If you're setting up fred, then yes the name automatically gets configured in your /etc/hosts. You can then modify /etc/hosts and you can also modify how your machine uses /etc/hosts and your DNS queries. (Don't quote me on this but check out /etc/hosts.conf and /etc/resolv.conf.
Since my dog freaks out during storms and I don't trust my memory after a night of no sleep, I did a quick google.
Check out: http://www.comptechdoc.org/os/linux/usersguide/linux_ugdns.html
This should help you get things straight....
To answer your second issue of $INFORMIXDIR/etc/sqlhosts
I have a setup
#DBSERVERNAME CONNECTIONTYPE HOSTNAME SERVICE OPTIONS
foo onsoctcp foo ifmx01
Where foo is the machine name and also the dbservername.
(I'm sure I broke some naming convention ...)
I'm using IDS 10.x on SuSE Linux 10.x without a problem with internet connections.
HTH
-G
> Date: Mon, 6 Apr 2009 14:09:59 +0100
> From: goddai01@hotmail.co.uk
> Subject: IDS on RHEL derivatives
> To: informix-list@iiug.org
>
> If I want to set up a server called, for instance, fred, at an IP
> address of, say, 10.9.8.7 then I'd expect every node on the network to
> recognise that as being the IP address for fred irrespective of whether
> it's obtained from a DNS server or /etc/hosts. But these days it seems
> that if fred is a Linux box it will by default be set up in /etc/hosts
> to have a different IP address for fred: 127.0.0.1. If the box is
> standalone this is reasonable but on a network ISTM both wrong and
> unnecessary as there's an accepted name for that address, localhost. If
> IDS is set up on such a server using the server name in sqlhosts it
> means that IDS offers connections on the loopback port instead of the
> physical network connection and other nodes can't connect.
>
> For some distros it's possible to override this in /etc/hosts but when I
> tried this on Centos 5.2, an RHEL derivative, the network failed to work
> reliably and when I tried Startcom, another RHEL derivative, it looked
> as if it was going to show similar problems.
>
> Given that IDS is compiled for RHEL what approach is used to handle
> this? Does genuine RHEL act differently? Is there some tweak to get
> round it? Should the IP address be hard-coded into sqlhosts? Should
> some other line be put into hosts, e.g.
> 10.9.8.7 self
> and this name used in sqlhosts?
>
> How are RHEL users handling this?
>
> --
> Ian
>
> Hotmail is for spammers. Real mail address is igoddard
> at nildram co uk
> _______________________________________________
> Informix-list mailing list
> Informix-list@iiug.org
> http://www.iiug.org/mailman/listinfo/informix-list
_________________________________________________________________
Quick access to your favorite MSN content and Windows Live with Internet Explorer 8.
http://ie8.msn.com/microsoft/internet-explorer-8/en-us/ie8.aspx?ocid=B037MSN55C0701A
Ian Michael Gumby wrote:
> Whoa!
>
> Lets stop for a second.
>
> You have DNS and you have /etc/hosts.
Agreed. In fact I'm just using /etc/hosts for addresses on the LAN &
the ISP's DNS servers for the internet.
> Going from memory, under bind8, you can set up which gets used first for
> ip/name lookup.
Your memory does not deceive.
> The trouble is when your network domain is foo.com and you have an entry
> of fred.foo.com and fred in your /etc/hosts where there are two
> different ip addresses.
I deliberately gave a 10.x.x.x address because such addresses don't get
routed so we don't need to consider domains.
> If you're already on fred, then I think your first ip address for fred
> would be its loopback address. (Sorry I should know this but its been a
> while since I've configured a box.)
localhost used to be the loopback address. When I've configured boxes
in the past I've always just left it at that and set up the eth0 as the
hostname as that's what everything else would use. It makes for
consistency. What I often used to do was set up "self" as an extra name
on eth0 (I could then get into the habit of typing "ping self" without
having to remember what box I was on!).
> To add to this twist, you can have a hostname of fred, but you can also
> have interfaces with different names. This is kind of a good thing if
> you want to use a second nic card for a private network between servers.
> This will cut down on congestion. With multiple nic cards you could have
> one network for your database servers for ER, one network for database
> to web servers, and then the public interface to the internet.
Yup, but not an issue here. This is just a small box on my home network
set up partly to keep my hand in now I've retired.
> But to make sure your traffice uses the correct interface, you need to
> set up static routes.
>
> Getting back to your question...
>
> If you're setting up fred, then yes the name automatically gets
> configured in your /etc/hosts. You can then modify /etc/hosts and you
> can also modify how your machine uses /etc/hosts and your DNS queries.
> (Don't quote me on this but check out /etc/hosts.conf and /etc/resolv.conf.
>
> Since my dog freaks out during storms and I don't trust my memory after
> a night of no sleep, I did a quick google.
>
> Check out: http://www.comptechdoc.org/os/linux/usersguide/linux_ugdns.html
> This should help you get things straight....
Thanks, I'll look at that.
> To answer your second issue of $INFORMIXDIR/etc/sqlhosts
> I have a setup
> #DBSERVERNAME CONNECTIONTYPE HOSTNAME SERVICE OPTIONS
> foo onsoctcp foo ifmx01>
> Where foo is the machine name and also the dbservername.
> (I'm sure I broke some naming convention ...)
Not my convention! It's pretty well what I'd do.
> I'm using IDS 10.x on SuSE Linux 10.x without a problem with internet
> connections.
This is the crux of the matter. This will also work with Debian & its
children. ATM I've got Ubuntu running but a full Ubuntu installation
over the top so I'll change it to something else.
But if you're in the RHEL family and hack /etc/hosts to make foo
anything other than loopback its networking falls apart. I can't
remember the exact messages it was posting into the logs but the
symptoms were sendmail took an age to start up (no problem, don't need
it so take it out of init.d) and ssh would only work if a Gnome session
was logged on at the console - log out and any ssh session closed a
minute or so later. Don't hack it and IDS is running on loopback. So
how does it get set up on those systems? IDS documentation more or less
says RTFM for the OS.
--
Ian
Hotmail is for spammers. Real mail address is igoddard
at nildram co uk
Ian Goddard wrote: > Ian Michael Gumby wrote: >> Check out: >> http://www.comptechdoc.org/os/linux/usersguide/linux_ugdns.html >> This should help you get things straight.... > > Thanks, I'll look at that. I did. It sets out to document Bind 8. Bind 9 is current. And his example of an /etc/hosts is just what freaks out Centos :-( -- Ian Hotmail is for spammers. Real mail address is igoddard at nildram co uk
> Date: Mon, 6 Apr 2009 17:57:41 +0100 > From: goddai01@hotmail.co.uk > Subject: Re: IDS on RHEL derivatives > To: informix-list@iiug.org > But if you're in the RHEL family and hack /etc/hosts to make foo > anything other than loopback its networking falls apart. I can't > remember the exact messages it was posting into the logs but the > symptoms were sendmail took an age to start up (no problem, don't need > it so take it out of init.d) and ssh would only work if a Gnome session > was logged on at the console - log out and any ssh session closed a > minute or so later. Don't hack it and IDS is running on loopback. So > how does it get set up on those systems? IDS documentation more or less > says RTFM for the OS. > > -- > Ian > You shouldn't have to 'hack' it. Just make sure you have your entries in etc/hosts set up correctly, and then look at the /etc/hosts.conf and /etc/resolv.conf. Since you've got a 'small' network, you could set it to resolve names against the /etc/hosts first and then go out to your forwarder. (You're not running DNS for your local network, so you just need to forward your unresolved names to your ISP's DNS server.) This should speed up your sendmail issues. I would also recommend a couple of things.... 1) Switch to OpenSuSE since its also free and the distros are easy to set up. 2) Switch from sendmail to postfix. Try dovecot, which again isn't too hard to set up and its got a pretty active following. Unless you have hundreds of users, sendmail can be a royal pain to setup/configure/maintain... HTH -G _________________________________________________________________ Quick access to your favorite MSN content and Windows Live with Internet Explorer 8. http://ie8.msn.com/microsoft/internet-explorer-8/en-us/ie8.aspx?ocid=B037MSN55C0701A
Ian Michael Gumby wrote: > > > > Date: Mon, 6 Apr 2009 17:57:41 +0100 > > From: goddai01@hotmail.co.uk > > Subject: Re: IDS on RHEL derivatives > > To: informix-list@iiug.org > > > But if you're in the RHEL family and hack /etc/hosts to make foo > > anything other than loopback its networking falls apart. I can't > > remember the exact messages it was posting into the logs but the > > symptoms were sendmail took an age to start up (no problem, don't need > > it so take it out of init.d) and ssh would only work if a Gnome session > > was logged on at the console - log out and any ssh session closed a > > minute or so later. Don't hack it and IDS is running on loopback. So > > how does it get set up on those systems? IDS documentation more or less > > says RTFM for the OS. > > > > -- > > Ian > > > > You shouldn't have to 'hack' it. "Edit" if you prefer or "fine-tune". Whatever. > Just make sure you have your entries in etc/hosts set up correctly, and What's "correctly" *on RHEL*? > then look at the /etc/hosts.conf and /etc/resolv.conf. Done that. > Since you've got a 'small' network, you could set it to resolve names > against the /etc/hosts first and then go out to your forwarder. > (You're not running DNS for your local network, so you just need to > forward your unresolved names to your ISP's DNS server.) This should > speed up your sendmail issues. That's exactly what I do - except I don't need to run sendmail or any other MTA on this box. sendmail just comes with some distros out of the box. The point I was making is that it's a symptom of a network problem under these circumstances. > I would also recommend a couple of things.... > > 1) Switch to OpenSuSE since its also free and the distros are easy to > set up. I don't need to switch to OpenSuSE as Ubuntu works. I wasn't looking for a recommendation for a distro. What I was asking was, given that RHEL is what IDS is compiled against, how is this oddity in its, i.e. RHEL's, networking dealt with by people who actually use it? > 2) Switch from sendmail to postfix. Try dovecot, which again isn't too > hard to set up and its got a pretty active following. Unless you have > hundreds of users, sendmail can be a royal pain to > setup/configure/maintain... I don't need to run sendmail or any other MTA on this box. sendmail just comes with some distros out of the box. The point I was making is that it's a symptom of a network problem under these circumstances. -- Ian Hotmail is for spammers. Real mail address is igoddard at nildram co uk
Ian, We run genuine RHEL4 with IDS and the hosts file looks like this (for the mythical box fred.foo.fonterra.com) : 127.0.0.1 localhost localhost.localdomain 10.17.14.110 fred fred.foo.fonterra.com ... Other entries The sqlhosts file then uses fred, not the IP address. Works fine... Works fine if you take the FQDN out as well. -----Original Message----- From: informix-list-bounces@iiug.org [mailto:informix-list-bounces@iiug.org] On Behalf Of Ian Goddard Sent: Tuesday, 7 April 2009 1:10 a.m. To: informix-list@iiug.org Subject: IDS on RHEL derivatives If I want to set up a server called, for instance, fred, at an IP address of, say, 10.9.8.7 then I'd expect every node on the network to recognise that as being the IP address for fred irrespective of whether it's obtained from a DNS server or /etc/hosts. But these days it seems that if fred is a Linux box it will by default be set up in /etc/hosts to have a different IP address for fred: 127.0.0.1. If the box is standalone this is reasonable but on a network ISTM both wrong and unnecessary as there's an accepted name for that address, localhost. If IDS is set up on such a server using the server name in sqlhosts it means that IDS offers connections on the loopback port instead of the physical network connection and other nodes can't connect. For some distros it's possible to override this in /etc/hosts but when I tried this on Centos 5.2, an RHEL derivative, the network failed to work reliably and when I tried Startcom, another RHEL derivative, it looked as if it was going to show similar problems. Given that IDS is compiled for RHEL what approach is used to handle this? Does genuine RHEL act differently? Is there some tweak to get round it? Should the IP address be hard-coded into sqlhosts? Should some other line be put into hosts, e.g. 10.9.8.7 self and this name used in sqlhosts? How are RHEL users handling this? -- Ian Hotmail is for spammers. Real mail address is igoddard at nildram co uk _______________________________________________ Informix-list mailing list Informix-list@iiug.org http://www.iiug.org/mailman/listinfo/informix-list DISCLAIMER: This email contains confidential information and may be legally privileged. If you are not the intended recipient or have received this email in error, please notify the sender immediately and destroy this email. You may not use, disclose or copy this email or its attachments in any way. Any opinions expressed in this email are those of the author and are not necessarily those of the Fonterra Co-operative Group. http://www.fonterra.com/
Jarrod Teale wrote: > Ian, > We run genuine RHEL4 with IDS and the hosts file looks like this (for > the mythical box fred.foo.fonterra.com) : > > 127.0.0.1 localhost localhost.localdomain > 10.17.14.110 fred fred.foo.fonterra.com > ... Other entries > > The sqlhosts file then uses fred, not the IP address. > > Works fine... > > Works fine if you take the FQDN out as well. > Thanks, Jarrod. Maybe it's a 4 vs 5 thing. I was looking at Centos 5.2. Maybe I should try 4. -- Ian Hotmail is for spammers. Real mail address is igoddard at nildram co uk
On Monday 06 April 2009 22:55:36 Ian Goddard wrote: > Jarrod Teale wrote: > > Ian, > > We run genuine RHEL4 with IDS and the hosts file looks like this (for > > the mythical box fred.foo.fonterra.com) : > > > > 127.0.0.1 localhost localhost.localdomain > > 10.17.14.110 fred fred.foo.fonterra.com > > ... Other entries > > > > The sqlhosts file then uses fred, not the IP address. > > > > Works fine... > > > > Works fine if you take the FQDN out as well. > > Thanks, Jarrod. Maybe it's a 4 vs 5 thing. I was looking at Centos > 5.2. Maybe I should try 4. On all Linux distros usually I check the content of /etc/hosts for entries like this: 127.0.0.1 tux localhost.localdomain localhost If such an entry exist which resolves the hostname 'tux' to localhost IP address I move 'tux' to the real IP address, e.g.: 127.0.0.1 localhost.localdomain localhost 192.168.0.100 tux tux.mydomain.org I'm sure I made this change for RHEL 5 also. Andreas -- Andreas Breitfeld; Informix Development Munich IBM Deutschland Research & Development GmbH; Vorsitzender des Aufsichtsrats: Martin Jetter; Geschaeftsfuehrung: Erich Baier; Sitz der Gesellschaft: Boeblingen; Registergericht: Amtsgericht Stuttgart, HRB 243294