RE: Can I refuse all connections except replication?
Posted in 2003
Why don't use the Master-Secondary Configuration instead of Update Anywhere? The Secondary server would be in "Read Only" mode unless the Primary is working. And if you set the DRAUTO parameter to 1, the Secondary server switchover if the primary fails. And keep your DNS change procedure, but when the clients would try to connect to the secondary server after a recovery process, this server would be on "Read Only Mode". Or, if you have the money to buy HACMP that would be the best option (High Availability Cluster Multi-Processing) using it in cascade configuration. The HACMP software would be in charge of setting the Protected(Production) IP on the right server. And HACMP has a feature of masking the MAC Address , so you would not have the intermediate-cache-devices problem . Regards p.d.: My english is not so good, you can write me directly in spanish ... -----Mensaje original----- De: Fernando Ortiz [mailto:fortiz@lacorona.com.mx] Enviado el: Viernes, 26 de Septiembre de 2003 03:38 p.m. Para: dthacker@omnihotels.com; Informix-Discussion E-List (E-mail) Asunto: Re: Can I refuse all connections except replication? Hi Dave: I don't know in AIX but in linux you can use iptables to deny access to the server port to all incoming IP except the main server. # iptables -A INPUT -s <server ip> -p tcp --destination-port <port> -j ACCEPT # iptables -A INPUT -p tcp --destination-port <port> -j DENY You can check the AIX firewall. HTH ----- Original Message ----- From: <dthacker@omnihotels.com> To: <informix-list@iiug.org> Sent: Friday, September 26, 2003 1:05 PM Subject: Can I refuse all connections except replication? > Informix 9.30 running on AIX 4.3.3 > I have two instances running EDR in update anywhere mode. All > connections are usually made to the "primary" instance. The > transactions flow from the "primary" to the "backup" unless we declare > a disaster. We use internal DNS to control where the various clients > on our WAN "see" the primary server. When we run a DR drill, we > change the DNS entry for the "primary" to the "backup". When the > drill is over we flip the DNS entry back. Many servers cache the > "disaster mode" DNS and we've found they continue to connect to > "backup" after DNS is changed. > > I've been asked by management if there is a way to block all TCP/IP > connections to the database *except* for replication connections. When > we resume normal operations, we'd like the "backup" database to refuse > all connections except those sending replication transactions from > the primary server. > > I don't see a mode like this anwhere in the Administrators Guide, Is > there a way to do this? > > TIA > > Dave Thacker sending to informix-list sending to informix-list