Hi Jeremy,
[EMAIL PROTECTED] wrote On 05/03/07 05:06,:
Hi,
I am expriencing weird NFS problem recently. We mount a NFS export
directory (let say: nfserver:/exportfs) on a client with 2 IP address on
the same VLAN( one physical address and one Service Ip address:
168.192.22.50 and 168.192.22.51), you don't use the deprecated attribute
and we don't use IPMP.
On the NFS server we only allow the physical address to access the FS.
The FS is mounted on the client (/importfs) Recently, we see that access
problem on a specific directory within the mounting point
(/importfs/depot/incoming). The command ls does not give any answer and
hangs. No error in any logs (server and client). So I wonder if the fact
that we have 2 adresses on the same VLAN have any impact on the access
list of the NFS server?
It certainly could. If your server is blocking one of the two IP addresses,
and the client happens to be issueing the request with a source address of
the one blocked, NFS would not work.
For outbound connections, IP will do things that might not seem obvious to
you, and it will not necessarily choose a source address for the outbound
request that is the IP address of the physical interface. And since both
are on the same subnet, there is little for IP to make a decision on (as it
might if one were on a different, "farther away" subnet). This has been the
behavior if IP since we introduced logical interfaces many years ago.
Firewalls and the use logical interfaces tend to exibit this.
Steffen
Client is a Solaris 10 update1, does anyone has an other idea I would be
glad to know it :)
Remove the firewall rule that blocks a subset of IP addresses on the remote
system. You have said one system has two IP addresses on the same subnet.
You must treat them equally.
With zones, and the forcoming IP Instances in Solaris 10 7/07, you will be
able to control this behavior better. But it does not sound like you are
using zones.
Steffen
Thx
Jeremy
This message and any attachments (the "message") is
intended solely for the addressees and is confidential.
If you receive this message in error, please delete it and
immediately notify the sender. Any use not in accord with
its purpose, any dissemination or disclosure, either whole
or partial, is prohibited except formal approval. The internet
can not guarantee the integrity of this message.
BNP PARIBAS (and its subsidiaries) shall (will) not
therefore be liable for the message if modified.
---------------------------------------------
Ce message et toutes les pieces jointes (ci-apres le
"message") sont etablis a l'intention exclusive de ses
destinataires et sont confidentiels. Si vous recevez ce
message par erreur, merci de le detruire et d'en avertir
immediatement l'expediteur. Toute utilisation de ce
message non conforme a sa destination, toute diffusion
ou toute publication, totale ou partielle, est interdite, sauf
autorisation expresse. L'internet ne permettant pas
d'assurer l'integrite de ce message, BNP PARIBAS (et ses
filiales) decline(nt) toute responsabilite au titre de ce
message, dans l'hypothese ou il aurait ete modifie.
------------------------------------------------------------------------
_______________________________________________
networking-discuss mailing list
[email protected]
_______________________________________________
networking-discuss mailing list
[email protected]