<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Node XXXX is refusing Serviceguard communication in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/node-xxxx-is-refusing-serviceguard-communication/m-p/3678272#M699604</link>
    <description>Hi Paul,&lt;BR /&gt;Did you use revert-action script to undo bastellie changes. If not then this will happen. &lt;BR /&gt;Simply removing bactille software won't help.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;&lt;BR /&gt;</description>
    <pubDate>Thu, 24 Nov 2005 05:18:34 GMT</pubDate>
    <dc:creator>Bharat Katkar</dc:creator>
    <dc:date>2005-11-24T05:18:34Z</dc:date>
    <item>
      <title>Node XXXX is refusing Serviceguard communication</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/node-xxxx-is-refusing-serviceguard-communication/m-p/3678271#M699603</link>
      <description>Hello.&lt;BR /&gt;&lt;BR /&gt;I'm getting the error below when trying to build a new serviceguard cluster, 2 RP3440 nodes, SG version 11.16. This error occors when using check, apply or query commands. I tried creating the conf file fom another 11.16 cluster file and applying it but it still errors.&lt;BR /&gt;&lt;BR /&gt;Error Is...&lt;BR /&gt;&lt;BR /&gt;Checking nodes ... Done&lt;BR /&gt;Checking existing configuration ... Done&lt;BR /&gt;Warning: Unable to get configuration for cluster bacstel.&lt;BR /&gt;Error: Node ira70043 is refusing Serviceguard communication.&lt;BR /&gt;Please make sure that the proper security access is configured on node&lt;BR /&gt;ira70043 through either file-based access (pre-A.11.16 version) or role-based&lt;BR /&gt;access (version A.11.16 or higher) and/or that the host name lookup&lt;BR /&gt;on node ira70043 resolves the IP address correctly.&lt;BR /&gt;cmapplyconf : Failed to gather configuration information&lt;BR /&gt;&lt;BR /&gt;I have...&lt;BR /&gt;1. created a cmcmnodelist&lt;BR /&gt;2. created a /.rhosts.&lt;BR /&gt;3. added all required entries to the /etc/hosts&lt;BR /&gt;4. checked an nslookup resolved the hostames OK - it does.&lt;BR /&gt;5. Tested a traceroute for both the nodes - no probs.&lt;BR /&gt;&lt;BR /&gt;Ive build clusters before and not had this problem. The only 'new' thing here is that we have applied bastille to this server, although I have now reverted the bastille changes suspecting them as the cause. I have an ignite recovery tape taken p[rior to the bastile install so may revert the system to that worst case.&lt;BR /&gt;&lt;BR /&gt;Any suggestion would be great!&lt;BR /&gt;Paul</description>
      <pubDate>Thu, 24 Nov 2005 04:49:28 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/node-xxxx-is-refusing-serviceguard-communication/m-p/3678271#M699603</guid>
      <dc:creator>Paul Condren</dc:creator>
      <dc:date>2005-11-24T04:49:28Z</dc:date>
    </item>
    <item>
      <title>Re: Node XXXX is refusing Serviceguard communication</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/node-xxxx-is-refusing-serviceguard-communication/m-p/3678272#M699604</link>
      <description>Hi Paul,&lt;BR /&gt;Did you use revert-action script to undo bastellie changes. If not then this will happen. &lt;BR /&gt;Simply removing bactille software won't help.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 24 Nov 2005 05:18:34 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/node-xxxx-is-refusing-serviceguard-communication/m-p/3678272#M699604</guid>
      <dc:creator>Bharat Katkar</dc:creator>
      <dc:date>2005-11-24T05:18:34Z</dc:date>
    </item>
    <item>
      <title>Re: Node XXXX is refusing Serviceguard communication</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/node-xxxx-is-refusing-serviceguard-communication/m-p/3678273#M699605</link>
      <description>I ran the revert script and then rebooted to revert the kernel. Also ran the undo permission channges script.&lt;BR /&gt;&lt;BR /&gt;Is bastile a no go with serviceguard?</description>
      <pubDate>Thu, 24 Nov 2005 05:48:24 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/node-xxxx-is-refusing-serviceguard-communication/m-p/3678273#M699605</guid>
      <dc:creator>Paul Condren</dc:creator>
      <dc:date>2005-11-24T05:48:24Z</dc:date>
    </item>
    <item>
      <title>Re: Node XXXX is refusing Serviceguard communication</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/node-xxxx-is-refusing-serviceguard-communication/m-p/3678274#M699606</link>
      <description>Hi Paul,&lt;BR /&gt;I have never used Bastile with SG but it seems it's a critical job to go with. Currently don't know what all ports remained blocked on your nodes but i found out the ports that MC/serviceguard is using. See if you can check and free those ports for communication.&lt;BR /&gt;Also refer to this links below:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=944107" target="_blank"&gt;http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=944107&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=729393" target="_blank"&gt;http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=729393&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Port Requirements: &lt;BR /&gt;----------------- &lt;BR /&gt;&lt;BR /&gt;ServiceGuard uses the ports listed below. &lt;BR /&gt;Before installing, check /etc/services and be sure no other program has reserved these ports.&lt;BR /&gt;&lt;BR /&gt;clvm-cfg 1476/tcp HA LVM Configuration&lt;BR /&gt;hacl-qs 1238/tcp HA Quorum Server&lt;BR /&gt;hacl-hb 5300/tcp High Availability (HA) Cluster heartbeat&lt;BR /&gt;hacl-hb 5300/udp High Availability (HA) Cluster heartbeat&lt;BR /&gt;hacl-gs 5301/tcp HA Cluster General Services&lt;BR /&gt;hacl-cfg 5302/tcp HA Cluster TCP configuration&lt;BR /&gt;hacl-cfg 5302/udp HA Cluster UDP configuration &lt;BR /&gt;hacl-probe 5303/tcp HA Cluster TCP probe &lt;BR /&gt;hacl-probe 5303/udp HA Cluster UDP probe&lt;BR /&gt;hacl-local 5304/tcp HA Cluster commands&lt;BR /&gt;hacl-test 5305/tcp HA Cluster test&lt;BR /&gt;hacl-dlm 5408/tcp HA Cluster distributed lock manager&lt;BR /&gt;&lt;BR /&gt;In addition, ServiceGuard also uses dynamic ports (typically in the range 49152-65535) for some cluster services. If you have adjusted the dynamic port range using kernel tunable parameters alter your rules accordingly.&lt;BR /&gt;&lt;BR /&gt;  &lt;BR /&gt;System Firewalls &lt;BR /&gt; &lt;BR /&gt;&lt;BR /&gt;When using a system firewall such as HP-UX IPFilter with ServiceGuard, specific communications must be allowed to ensure proper cluster operation. Specific IPFilter rules required by ServiceGuard are documented in the HP-UX IPFilter Release Notes, available from &lt;A href="http://www.docs.hp.com" target="_blank"&gt;http://www.docs.hp.com&lt;/A&gt; -&amp;gt; Internet and Security Solutions.&lt;BR /&gt;&lt;BR /&gt;General guidelines for using a system firewall with ServiceGuard are listed below.&lt;BR /&gt;&lt;BR /&gt;To enable intra-cluster communications, each HEARTBEAT_IP network on every node within the cluster must allow the following communications in both directions with all other nodes in the cluster:&lt;BR /&gt;&lt;BR /&gt;tcp on port numbers 5300-5304, and 5408 - and allow only packets with the SYN flag&lt;BR /&gt;udp on port numbers 5300 and 5302&lt;BR /&gt;tcp and udp on dynamic ports (typically 49152-65535)&lt;BR /&gt;&lt;BR /&gt;If your ServiceGuard configuration uses a quorum server, all nodes within the cluster must allow the following communication to the quorum server IP address:&lt;BR /&gt;tcp on port 1238 - and allow only packets with the SYN flag&lt;BR /&gt;Any node providing quorum service for another cluster must allow the following communication from that &lt;BR /&gt;cluster's nodes:&lt;BR /&gt;tcp on port 1238 - and allow only packets with the SYN flag&lt;BR /&gt;Running the cmscancl command requires the "shell" port be open.&lt;BR /&gt;&lt;BR /&gt;There are additional firewall considerations to enable execution of ServiceGuard commands from nodes outside the cluster, such as those listed in cmclnodelist. To allow execution of ServiceGuard commands, follow the guidelines below.&lt;BR /&gt;&lt;BR /&gt;All nodes in the cluster must allow the following communications:&lt;BR /&gt;&lt;BR /&gt;From the remote nodes:&lt;BR /&gt;tcp on ports 5302 - and allow only packets with the SYN flag&lt;BR /&gt;udp on port 5302 &lt;BR /&gt;To the remote nodes:&lt;BR /&gt;tcp and udp on port numbers 49152-65535&lt;BR /&gt;&lt;BR /&gt;The remote nodes must allow the following communications:&lt;BR /&gt;From the cluster nodes:&lt;BR /&gt;tcp and udp on port numbers 49152-65535 &lt;BR /&gt;&lt;BR /&gt;To the cluster nodes&lt;BR /&gt;tcp on ports 5302 - and allow only packets with the SYN flag&lt;BR /&gt;udp on port 5302&lt;BR /&gt;&lt;BR /&gt;Hope that helps,&lt;BR /&gt;Regards,&lt;BR /&gt;</description>
      <pubDate>Thu, 24 Nov 2005 08:13:10 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/node-xxxx-is-refusing-serviceguard-communication/m-p/3678274#M699606</guid>
      <dc:creator>Bharat Katkar</dc:creator>
      <dc:date>2005-11-24T08:13:10Z</dc:date>
    </item>
    <item>
      <title>Re: Node XXXX is refusing Serviceguard communication</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/node-xxxx-is-refusing-serviceguard-communication/m-p/3678275#M699607</link>
      <description>More details regarding cluster communication can be found here:&lt;BR /&gt;&lt;A href="http://docs.hp.com/en/B3935-90068/ch01s03.html" target="_blank"&gt;http://docs.hp.com/en/B3935-90068/ch01s03.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;</description>
      <pubDate>Thu, 24 Nov 2005 08:21:28 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/node-xxxx-is-refusing-serviceguard-communication/m-p/3678275#M699607</guid>
      <dc:creator>Bharat Katkar</dc:creator>
      <dc:date>2005-11-24T08:21:28Z</dc:date>
    </item>
    <item>
      <title>Re: Node XXXX is refusing Serviceguard communication</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/node-xxxx-is-refusing-serviceguard-communication/m-p/3678276#M699608</link>
      <description>Hi Paul &lt;BR /&gt;&lt;BR /&gt;What's the O/S here if 11.23 let me know, otherwise I'd initailly be checking : &lt;BR /&gt;&lt;BR /&gt;grep identd inetd.conf&lt;BR /&gt;grep auth /etc/services&lt;BR /&gt;netstat -an | grep 113&lt;BR /&gt;syslogs yield any clues here ? &lt;BR /&gt;nsswitch.conf ?&lt;BR /&gt;debug inetd -i ? &lt;BR /&gt; &lt;BR /&gt;in case this is an authentication issue of some sort ?</description>
      <pubDate>Thu, 24 Nov 2005 09:00:42 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/node-xxxx-is-refusing-serviceguard-communication/m-p/3678276#M699608</guid>
      <dc:creator>Alex Glennie</dc:creator>
      <dc:date>2005-11-24T09:00:42Z</dc:date>
    </item>
    <item>
      <title>Re: Node XXXX is refusing Serviceguard communication</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/node-xxxx-is-refusing-serviceguard-communication/m-p/3678277#M699609</link>
      <description>Hi Paul,&lt;BR /&gt;&lt;BR /&gt;This is a known issue for serviceguard 11.16.&lt;BR /&gt;Has nothing to do with bastille.&lt;BR /&gt;You need to install some patches i know 2&lt;BR /&gt;PHSS_32733 PHSS_32732. But i thing there are more.&lt;BR /&gt;What sometimes did the trick was rebooting the servers. &lt;BR /&gt;&lt;BR /&gt;grtz. Mark</description>
      <pubDate>Thu, 24 Nov 2005 09:09:55 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/node-xxxx-is-refusing-serviceguard-communication/m-p/3678277#M699609</guid>
      <dc:creator>Mark Nieuwboer</dc:creator>
      <dc:date>2005-11-24T09:09:55Z</dc:date>
    </item>
    <item>
      <title>Re: Node XXXX is refusing Serviceguard communication</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/node-xxxx-is-refusing-serviceguard-communication/m-p/3678278#M699610</link>
      <description>Shalom Paul,&lt;BR /&gt;&lt;BR /&gt;inetd.conf&lt;BR /&gt;&lt;BR /&gt;May need new options:&lt;BR /&gt;&lt;BR /&gt;example.&lt;BR /&gt;&lt;BR /&gt;hacl-probe  stream  tcp    nowait  root  /opt/cmom/lbin/cmomd /opt/cmom/lbin/cmomd -i -f /var/opt/cmom/cmomd.log -r /var/opt/cmom&lt;BR /&gt;#registrar stream tcp nowait root /etc/opt/resmon/lbin/registrar /etc/opt/resmon/lbin/registrar&lt;BR /&gt;hacl-cfg    dgram   udp    wait    root  /usr/lbin/cmclconfd cmclconfd -p&lt;BR /&gt;hacl-cfg    stream  tcp    nowait  root  /usr/lbin/cmclconfd cmclconfd -c -i&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Thu, 24 Nov 2005 09:13:17 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/node-xxxx-is-refusing-serviceguard-communication/m-p/3678278#M699610</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2005-11-24T09:13:17Z</dc:date>
    </item>
    <item>
      <title>Re: Node XXXX is refusing Serviceguard communication</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/node-xxxx-is-refusing-serviceguard-communication/m-p/3678279#M699611</link>
      <description>Hello, Paul,&lt;BR /&gt;&lt;BR /&gt;User "root" user for cmgetconf, cmappyconf, etc.&lt;BR /&gt;&lt;BR /&gt;Sguard A.11.16 not use security cmclnodelist or .rhosts: use "security roles"&lt;BR /&gt;&lt;BR /&gt;Install utility "  SG-Manager            A.05.00        Serviceguard Java GUI" for hpux&lt;BR /&gt;&lt;BR /&gt;Salud</description>
      <pubDate>Fri, 25 Nov 2005 05:45:28 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/node-xxxx-is-refusing-serviceguard-communication/m-p/3678279#M699611</guid>
      <dc:creator>rariasn</dc:creator>
      <dc:date>2005-11-25T05:45:28Z</dc:date>
    </item>
    <item>
      <title>Re: Node XXXX is refusing Serviceguard communication</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/node-xxxx-is-refusing-serviceguard-communication/m-p/3678280#M699612</link>
      <description>Hi All.&lt;BR /&gt;&lt;BR /&gt;Thanks for all the help and suggestions.&lt;BR /&gt;&lt;BR /&gt;First up Roles and access - according to the book I dont need to set up roles etc to create a cluster fropm the command line as root - these are just for admin afterwards and setting up no root users with things like view only access. We have some 50 odd serviceguard clusters here and we've never had to do this in the past with 11.16&lt;BR /&gt;&lt;BR /&gt;Next - reverting Bastille. I ran the bastile -r and also the revert permission changes cript. Still no joy. I also ran thru some suggestion from Alex but due to the traditional unrealistic project deadlines and timescales I was under pressure to complete the build - not having access to their app on the SG disks was upsetting the developers!&lt;BR /&gt;&lt;BR /&gt;So, I luckily had an ignite taked just before the application of the bastille config. I revered to this and the cluster checked and applied first time with no issues. I have sice build the package and applied this and taken another ignite.&lt;BR /&gt;&lt;BR /&gt;Ive have now applied bastille again today and everythings fine. ALl the serviceguard commands still work with no issues.&lt;BR /&gt;&lt;BR /&gt;I can only conclude that if your applying bastille to a serviceguard environment than you need to do this after installing and building the cluster. There could be something in bastille that detects servicegard and afects its changes.</description>
      <pubDate>Tue, 29 Nov 2005 06:54:11 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/node-xxxx-is-refusing-serviceguard-communication/m-p/3678280#M699612</guid>
      <dc:creator>Paul Condren</dc:creator>
      <dc:date>2005-11-29T06:54:11Z</dc:date>
    </item>
  </channel>
</rss>

