1838282 Members
3031 Online
110125 Solutions
New Discussion

Re: HP remote logins

 
sims
New Member

HP remote logins

Dear All
Iam facing a problem in HP-UX networking..I have an L1000 server on which HP-UX 11.0 is loaded..it crashed yesterday due to root VG failure..I configured everything...everything works except people are un able to login from outside the physical network when they login from internet..They are unable to ping to my server also..whereas users from local network are able to telnet,rlogin to my server..I have checked all the configuration files ...Iam not using any DNS or NIS servers..users from outside logs into the NT firewall server ..once they are authenticated by the firewall server they are given the access to HP server..here they are able to ping ,get authenticated by firewall server ,after that they cannot connect / ping to the HP server..Please let me know What are the parameters and config files I should check...Unfortunately I don't have a root backup also..Please help me..

regds
SIMS
10 REPLIES 10
Balaji N
Honored Contributor

Re: HP remote logins

hi,
by any chance your gateway is the culprit. is your default gateway set properly?
-balaji
Its Always Important To Know, What People Think Of You. Then, Of Course, You Surprise Them By Giving More.
Robert-Jan Goossens
Honored Contributor

Re: HP remote logins

Hi,

have you added some routes in the past from the command line, Think you lost your routing table.

Robert-Jan.
melvyn burnard
Honored Contributor

Re: HP remote logins

Sounds like you are missinmg your default route/gateway.
Check what /etc/rc.config.d/netconf is configured for, also do netstat -r or netstat -rn
My house is the bank's, my money the wife's, But my opinions belong to me, not HP!
sims
New Member

Re: HP remote logins

Dear All
I have checked /etc/rc.config.d/netconf and default gateway is correct / intact..iam sure I have configured the gateway properly..Any other options please.

REgds
Sims
sims
New Member

Re: HP remote logins

Dear All
Is there any particular patch that I have to apply for allowing the remote users to telnet in ..

Regds
Sims
RAC_1
Honored Contributor

Re: HP remote logins

For logins from remote network all you need is ruote to that network. And appropriate settings on firewall if any.

Can Your remote users ping Firewall? if yes check settings on firewall.

Firewall log should give you some idea.

Before all this check you have appropriate route for the remote network.
There is no substitute to HARDWORK
sims
New Member

Re: HP remote logins

Dear All
Ping is disabled in Firewall..So we cannot test that..But all the outside users are getting authorized by the firewall..so I think there should not be any problem with the firewall..no settings has been changed in firewall and all the users were able to
telnet/ping to HP server before it crashed..I get a message "source quench recieved "when i try to ping to HP server from any of the local node even though i am able to telnet to it..

Regds
SIMS
RAC_1
Honored Contributor

Re: HP remote logins

Source quench received means buffer problems on card.

You can disable message with ndd set /dev/ip ip_send_source_quench

Also check is there any problem woth NIC speed. Is it same on NIC and switch/router side?

One more thing I noticed is that you said all users were able to telnet/ping to HP server. And now they are not able to ping because ping is disabled at firewall.

Then enable ping for testing. So that you can check if remote users are at least getting up to firewall or not?
There is no substitute to HARDWORK
sims
New Member

Re: HP remote logins

Dear
I have tried setting the value of ip_send_source_quench to "0" from "1"..now it gives "reply from 10.10.10.10 ttl..." as it is recieved for a normal ping..still I am unable to ping to the server...Only thing is that I could suppress the "source quench received " message..
Please help.
regds
SIMS
Steven E. Protter
Exalted Contributor

Re: HP remote logins

You need to conduct your testing on the same side of the firewall, even if you have to use a windows box.

You might need to run ioinit -c and recreate your terminal and psuedo terminal files.

run swverify \* and look for problems there. This could indicate patches that need to be reinstalled. NEVER reinstall PHKL_18543 the LITS patch, or patch of death as I like to call it.

It would be a wonderful idea to get the machine up to the December 2002 11.00 QPK. There are lots of problems solved by being current on patches.

With regards to your firewall, if port 23 is not open on it, users will never be able to telnet in.

You don't want to open it either, because telnet and ftp transmit passwords in clear text and passwords can be obtained by bad people.

If you want secure outside acess, see firewall admin about port 22. Thats Secure shell, and this can provide secure access to the public internet. Port 22/TCP will have to be open for that.

Just for grins here is a link to download secure shell, and I've attached a document that shows how to set it up.

https://payment.ecommerce.hp.com/cgi-bin/swdepot_parser.cgi/cgi/try.pl?productNumber=T1471AA&date=


I think its really important to take the firewall out of this picture. The firewall probably should have one interface on the same subnet as your HP box.

You should re-run your access tests after firewall administration temporarily allows pings and traffic on the ports you want to use. If it solves your problem, the issue is firewall configuration.

SEP
Steven E Protter
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com