Hi Jeremy,

[EMAIL PROTECTED] wrote On 05/03/07 05:06,:

Hi,

I am expriencing weird NFS problem recently. We mount a NFS export directory (let say: nfserver:/exportfs) on a client with 2 IP address on the same VLAN( one physical address and one Service Ip address: 168.192.22.50 and 168.192.22.51), you don't use the deprecated attribute and we don't use IPMP.

On the NFS server we only allow the physical address to access the FS. The FS is mounted on the client (/importfs) Recently, we see that access problem on a specific directory within the mounting point (/importfs/depot/incoming). The command ls does not give any answer and hangs. No error in any logs (server and client). So I wonder if the fact that we have 2 adresses on the same VLAN have any impact on the access list of the NFS server?

It certainly could. If your server is blocking one of the two IP addresses, and the client happens to be issueing the request with a source address of the one blocked, NFS would not work.

For outbound connections, IP will do things that might not seem obvious to you, and it will not necessarily choose a source address for the outbound request that is the IP address of the physical interface. And since both are on the same subnet, there is little for IP to make a decision on (as it might if one were on a different, "farther away" subnet). This has been the behavior if IP since we introduced logical interfaces many years ago.

Firewalls and the use logical interfaces tend to exibit this.

Steffen


Client is a Solaris 10 update1, does anyone has an other idea I would be glad to know it :)

Remove the firewall rule that blocks a subset of IP addresses on the remote system. You have said one system has two IP addresses on the same subnet. You must treat them equally.

With zones, and the forcoming IP Instances in Solaris 10 7/07, you will be able to control this behavior better. But it does not sound like you are using zones.

Steffen



Thx
Jeremy


This message and any attachments (the "message") is
intended solely for the addressees and is confidential. If you receive this message in error, please delete it and immediately notify the sender. Any use not in accord with its purpose, any dissemination or disclosure, either whole or partial, is prohibited except formal approval. The internet can not guarantee the integrity of this message. BNP PARIBAS (and its subsidiaries) shall (will) not therefore be liable for the message if modified.
                ---------------------------------------------

Ce message et toutes les pieces jointes (ci-apres le "message") sont etablis a l'intention exclusive de ses destinataires et sont confidentiels. Si vous recevez ce message par erreur, merci de le detruire et d'en avertir immediatement l'expediteur. Toute utilisation de ce message non conforme a sa destination, toute diffusion ou toute publication, totale ou partielle, est interdite, sauf autorisation expresse. L'internet ne permettant pas d'assurer l'integrite de ce message, BNP PARIBAS (et ses filiales) decline(nt) toute responsabilite au titre de ce message, dans l'hypothese ou il aurait ete modifie.



------------------------------------------------------------------------

_______________________________________________
networking-discuss mailing list
[email protected]
_______________________________________________
networking-discuss mailing list
[email protected]

Reply via email to