perfsonar-user - RE: [perfsonar-user] Changing PerfSonar boxen IP addresses (different subnet)
Subject: perfSONAR User Q&A and Other Discussion
List archive
- From: "Garnizov, Ivan (RRZE)" <>
- To: "" <>, "" <>
- Subject: RE: [perfsonar-user] Changing PerfSonar boxen IP addresses (different subnet)
- Date: Tue, 4 Aug 2015 14:01:53 +0000
- Accept-language: en-GB, de-DE, en-US
Hi Winnie, In fact you are missing a lot of ports there: Bandwidth:
TCP 8090 (oppd) Latency:
TCP 8090 (oppd) Access to MA:
Traceroute:
In fact other ports should not be considered unimportant since DNS resolution, ICMP (ping) and time synchronization services are also vital. So it all depends on your deployment and configuration. Please note that initial setup of perfSONAR produces a FW configuration for you on iptables. AND from your post: The red ones you need as incoming only if you are providing the LS service. LAT: 443 (https), 861 (owampd), 8090 (oppd), 8096 (lookup), 61617 (lookup) BW: 443 (https), 4823 (bwctld), 8090 (oppd),
8096 (lookup), 61617 (lookup) Best regards, Ivan -----Original Message----- Ok, I realize now the problem. (why not before - hectic/chaotic**N) On the former subnet, all ports > 1024 were un-firewalled by our Institute; we requested only a few ports < 1024 to be open for LAT + BW perfsonar boxen in site firewall. On the new subnet, all ports are firewalled. D'oh! as they say. I have tried to grok page http://www.perfsonar.net/deploy/security-considerations/ which seems to be the only page listing ports for perfsonar. So now, may one ask if these are the right ports on the right boxen to request to be opened in Institute Firewall: LAT: 443 (https), 861 (owampd), 8090 (oppd), 8096 (lookup), 61617 (lookup) BW: 443 (https), 4823 (bwctld), 8090 (oppd), 8096 (lookup), 61617 (lookup) NOTHING ELSE Confirmed? If not please correct. In partic, don't need 80 open, right? VERY Grateful for your patient & kind advice!! Winnie Lacesso / Bristol University Particle Physics Computing Systems HH Wills Physics Laboratory, Tyndall Avenue, Bristol, BS8 1TL, UK |
- Re: [perfsonar-user] Changing PerfSonar boxen IP addresses (different subnet), Winnie Lacesso, 08/03/2015
- Re: [perfsonar-user] Changing PerfSonar boxen IP addresses (different subnet), Shawn McKee, 08/03/2015
- Re: [perfsonar-user] Changing PerfSonar boxen IP addresses (different subnet), Winnie Lacesso, 08/04/2015
- RE: [perfsonar-user] Changing PerfSonar boxen IP addresses (different subnet), Garnizov, Ivan (RRZE), 08/04/2015
- Re: [perfsonar-user] Changing PerfSonar boxen IP addresses (different subnet), Shawn McKee, 08/04/2015
- Re: [perfsonar-user] Changing PerfSonar boxen IP addresses (different subnet), Winnie Lacesso, 08/04/2015
- Re: [perfsonar-user] Changing PerfSonar boxen IP addresses (different subnet), Winnie Lacesso, 08/04/2015
- Re: [perfsonar-user] Changing PerfSonar boxen IP addresses (different subnet), Shawn McKee, 08/03/2015
Archive powered by MHonArc 2.6.16.