Informix Instance inventory
Posted in 2011
Topics: Installation, Setup & Upgrades, Licensing & Editions
Hi, My client recently upgraded his license entitlements to Informix 11.7 an has asked us to make shure he is compliant. The main problem is my client is a national institution and has several "IT" departaments that not allways share the installed base info and has 2 outsourced and several in-house data centers. So, what tool can I use to do a scan for Informix instances? I want to be informed of candidates and later we will do a manual verification on the instance so we can have an acurate mesure of license use. I tryed to do this in a lab environment using nmap but this tool didn't found any of the instances I set up for the test. If any of you has used this tool can you tell me how you did it? Thanks in advance. Javier Hernández
2011/4/28 JAVIER HERNáNDEZ <javier_hdzt@yahoo.com.mx>
> My client recently upgraded his license entitlements to Informix 11.7 an
> has
> asked us to make sure he is compliant.
>
> The main problem is my client is a national institution and has several
> "IT"
> departments that not always share the installed base info and has 2
> outsourced and several in-house data centers.
>
> So, what tool can I use to do a scan for Informix instances? I want to be
> informed of candidates and later we will do a manual verification on the
> instance so we can have an accurate measure of license use.
>
> I tried to do this in a lab environment using nmap but this tool didn't
> found
> any of the instances I set up for the test. If any of you has used this
> tool
> can you tell me how you did it?
>
For a given machine, you can usually use 'onstat -g dis' as root or informix
to get a lot of information about instances that are or have been on the
machine. If /INFORMIXTMP exists, that is a give-away that an IDS instance
has been run on the machine at some time.
I'm intrigued that nmap did not find the instances. Of course, if the
instance is not configured with network access, then nmap is not going to
spot it, but these days it is a rare instance that does not have a network
alias.
Did nmap spot open ports for which it could not identify the program with
the port open? One of the problems with Informix is that we're really
unfussy about which port you use - it was only a few years ago that we got
official IANA port numbers allocated. Any open ports for which nmap cannot
identify the software could be Informix ports. You could manufacture an
sqlhosts file entry to connect to that port on that machine and see what
happens when you connect to it. You could reasonably expect that your
servername (column 1 in sqlhosts) is going to be wrong (unless you have a
system for naming Informix instances), so you might well get a connection
refused message because the server name doesn't match any server alias, but
that's a giveaway that Informix is hiding behind the port. If you get a
completely bogus message, or the connection simply disconnects, then you are
more likely to have some other piece of software that is confused by the
Informix connection message because it doesn't match the other program's
expected opening exchange of information.
I believe it is possible to train nmap to identify new protocols, so in
theory, you could train it to recognize Informix. I'm not sure that's
sensible in practice - but it would be the best long term solution. I've
toyed with the idea for a couple of years, but found too many other things
to keep me busy.
--
Jonathan Leffler <jonathan.leffler@gmail.com> #include <disclaimer.h>
Guardian of DBD::Informix - v2008.0513 - http://dbi.perl.org
"Blessed are we who can laugh at ourselves, for we shall never cease to be
amused."
--001636cd74af4a012504a1fef814
In the lab I set up I have one server with 2 instances one listening on port 1525 and the other in port 9088, the SO is Linux (CentOS 5 update 5) with the firewall dissabled and run a port scan on the external interface and on localhost (127.0.0.1) and get no indication of the informix instances, if I scan the specific ports I get filtered unknown response for both ports so was the basis of my post. Currently I'm digging more on the nmap tool and aparentely we can use the scripting engine to do the probing but as I'm not proficient will take more time that the I have planned to use. If/when I have the script ready will post here. Thanks for you input.