perfsonar-user - Re: [perfsonar-user] Perfsonar ports - tracepath blocked
Subject: perfSONAR User Q&A and Other Discussion
List archive
- From: Brian Candler <>
- To: Andrew Lake <>, "" <>
- Subject: Re: [perfsonar-user] Perfsonar ports - tracepath blocked
- Date: Tue, 16 Feb 2016 14:56:39 +0000
- Domainkey-signature: a=rsa-sha1; c=nofws; d=pobox.com; h=subject:to :references:from:message-id:date:mime-version:in-reply-to :content-type; q=dns; s=sasl; b=if1YxXeI7yLlx/cT9OXcTBI7ckuJOSF6 ISCvBuWR3Z6g2M6gW3eWPKZt3ohL/xankkghYwoMiXHh/F+xUy5TXnmm8wuoCuiN wgW0q9KoilKTWkB5UpyBDHywbCjOHLjzEKmmEnjFEz8FL4Sj3HfssHiO+osJ7+Zf AxtWWZpocmE=
On 16/02/2016 13:56, Andrew Lake wrote:
1. I have several perfsonar boxes behind firewalls 2. I opened up all the ports which the documentation said should be opened 3. Firewall logs showed that box A was periodically trying to talk to box B on UDP ports 44445 upwards, and the firewall was blocking these packets and logging them. The problem is that I don't like seeing lots of rejects in my firewall logs - it means something isn't right :-( 4. Mapping the ephemeral source port used by A with netstat showed that it was a tracepath process at the other side which was generating the packets 5. Checking the iptables rules for perfsonar shows that traceroute (33434 upwards) is enabled, but not tracepath. My conclusions: either - perfsonar developers forgot about the tracepath ports (in iptables, and in the documentation) or - tracepath doesn't really need the last hop (e.g. if you're only concerned about the MTU of intervening hops) or - tracepath is happy with an ICMP "Admin Prohibited" response (I haven't checked if perfsonar's use of iptables generates that) or - something else that I don't understand Regards, Brian. |
- Re: [perfsonar-user] Perfsonar ports - tracepath blocked, (continued)
- Re: [perfsonar-user] Perfsonar ports - tracepath blocked, Brian Candler, 02/16/2016
- RE: [perfsonar-user] Perfsonar ports - tracepath blocked, Garnizov, Ivan (RRZE), 02/16/2016
- Re: [perfsonar-user] Perfsonar ports - tracepath blocked, Andrew Lake, 02/16/2016
- Re: [perfsonar-user] Perfsonar ports - tracepath blocked, Brian Candler, 02/16/2016
- Re: [perfsonar-user] Perfsonar ports - tracepath blocked, Andrew Lake, 02/16/2016
- Re: [perfsonar-user] Perfsonar ports - tracepath blocked, Brian Candler, 02/16/2016
- Re: [perfsonar-user] Perfsonar ports - tracepath blocked, Andrew Lake, 02/16/2016
- Re: [perfsonar-user] Perfsonar ports - tracepath blocked, Andrew Lake, 02/16/2016
- Re: [perfsonar-user] Perfsonar ports - tracepath blocked, Brian Candler, 02/18/2016
- Re: [perfsonar-user] Perfsonar ports - tracepath blocked, Andrew Lake, 02/18/2016
- Re: [perfsonar-user] Perfsonar ports - tracepath blocked, Andrew Lake, 02/16/2016
Archive powered by MHonArc 2.6.16.