<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic TCPIP5.4 ECO6 and failSAFE IP in Operating System - OpenVMS</title>
    <link>https://community.hpe.com/t5/operating-system-openvms/tcpip5-4-eco6-and-failsafe-ip/m-p/3946159#M53816</link>
    <description>I have recently installed ECO 6 to our TCPIP 5.4 VMS7.3-2 4-node cluster with failSAFE IP. Since then we have, intermittently, started getting connection problems with FTP. We think the problem is that our firewall needed all IP addresses used by our nodes.This was not a problem before eco6. Since the changes to firewall the connectivity has improved but there are still some sites that we are having problems with  - but that could be due to those sites not having updated their firewalls.&lt;BR /&gt;Has anyone else come across this? There is nothing in ECO 6 release notes.</description>
    <pubDate>Fri, 16 Feb 2007 10:12:54 GMT</pubDate>
    <dc:creator>Zahid Ghani</dc:creator>
    <dc:date>2007-02-16T10:12:54Z</dc:date>
    <item>
      <title>TCPIP5.4 ECO6 and failSAFE IP</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/tcpip5-4-eco6-and-failsafe-ip/m-p/3946159#M53816</link>
      <description>I have recently installed ECO 6 to our TCPIP 5.4 VMS7.3-2 4-node cluster with failSAFE IP. Since then we have, intermittently, started getting connection problems with FTP. We think the problem is that our firewall needed all IP addresses used by our nodes.This was not a problem before eco6. Since the changes to firewall the connectivity has improved but there are still some sites that we are having problems with  - but that could be due to those sites not having updated their firewalls.&lt;BR /&gt;Has anyone else come across this? There is nothing in ECO 6 release notes.</description>
      <pubDate>Fri, 16 Feb 2007 10:12:54 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/tcpip5-4-eco6-and-failsafe-ip/m-p/3946159#M53816</guid>
      <dc:creator>Zahid Ghani</dc:creator>
      <dc:date>2007-02-16T10:12:54Z</dc:date>
    </item>
    <item>
      <title>Re: TCPIP5.4 ECO6 and failSAFE IP</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/tcpip5-4-eco6-and-failsafe-ip/m-p/3946160#M53817</link>
      <description>Back out ECO6 and see if the behavior changes?&lt;BR /&gt;&lt;BR /&gt;I'd almost assume this isn't ECO6, but stranger things have happened.&lt;BR /&gt;&lt;BR /&gt;Backing the ECO out would confirm or deny the  theory that some change(s) within ECO6 were involved here.&lt;BR /&gt;&lt;BR /&gt;I would certainly assume that a firewall would have to know which host addresses and ports would receive an incoming FTP connection -- hopefully in a DMZ.  FTP itself is particularly ugly at the firewall, which is where the passive transfer mechanism arose.  Most folks now use or are migrating to ftps or sftp, or a VPN-based link.&lt;BR /&gt;&lt;BR /&gt;The first of many hits on a Google search for:&lt;BR /&gt;&lt;BR /&gt;ftp firewall passive &lt;BR /&gt;&lt;BR /&gt;are all around getting this stuff to work, and around security discussions.  You're not alone here, by any stretch.&lt;BR /&gt;&lt;BR /&gt;Start here:&lt;BR /&gt;&lt;A href="http://slacksite.com/other/ftp.html" target="_blank"&gt;http://slacksite.com/other/ftp.html&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://www.ncftp.com/ncftpd/doc/misc/ftp_and_firewalls.html" target="_blank"&gt;http://www.ncftp.com/ncftpd/doc/misc/ftp_and_firewalls.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;IP network and routing problems seldom fit within the confines of the ITRC forums 46x16 text input box.  Various organizations around -- full disclosure: Hoffmanlabs is one -- can assist with these situations and with OpenVMS and TCP/IP Services networking.&lt;BR /&gt;&lt;BR /&gt;Stephen Hoffman&lt;BR /&gt;HoffmanLabs</description>
      <pubDate>Fri, 16 Feb 2007 10:24:19 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/tcpip5-4-eco6-and-failsafe-ip/m-p/3946160#M53817</guid>
      <dc:creator>Hoff</dc:creator>
      <dc:date>2007-02-16T10:24:19Z</dc:date>
    </item>
    <item>
      <title>Re: TCPIP5.4 ECO6 and failSAFE IP</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/tcpip5-4-eco6-and-failsafe-ip/m-p/3946161#M53818</link>
      <description>Hell Zahid,&lt;BR /&gt;&lt;BR /&gt;First - prove that ECO06 didn't cause the problem. Fire up a spare Alpha with the previous configuration if you can. That way you won't affect a production environment.&lt;BR /&gt;&lt;BR /&gt;Second, if you still have trouble then use the spare Alpha to diagnose what's happening if you can. You may need to hang a network analyser off the switch to see what's really going on. Depending on how "failsafe IP" is working in terms of flipping the IP address between physical interfaces you might also need to check how the switch (or switches) are configured.&lt;BR /&gt;&lt;BR /&gt;Lots of "fun".&lt;BR /&gt;&lt;BR /&gt;Cheers, Colin (&lt;A href="http://www.xdelta.co.uk)." target="_blank"&gt;www.xdelta.co.uk).&lt;/A&gt;</description>
      <pubDate>Sat, 17 Feb 2007 09:32:15 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/tcpip5-4-eco6-and-failsafe-ip/m-p/3946161#M53818</guid>
      <dc:creator>Colin Butcher</dc:creator>
      <dc:date>2007-02-17T09:32:15Z</dc:date>
    </item>
  </channel>
</rss>

