Title: Re: [SunRay-Users] Sunray FOG on Trusted Extensionspartially working
Update:
Did the "enableMulticast=false" on both server1 and server2. Strange behavior afterwards.
 
If I'm on server1 or server2 and do "utgstatus -s server1" or "utgstatus -s server1-srss", I get the following (like before the "enableMulticast"):
host        flags       interface       flags      interface        flags
                            176.1.0.0/16              192.168.110.0/24
------------------------    ----------------------------    ------------------------------
server1       TN      176.1.0.20     U--         192.168.110.11  UAM
 
However, if I'm on either server1 or server2, and do "utgstatus -s server2" or "utgstatus -s server2-srss", I get:
Error: Cound not get gstatus information from server server1
 
On server1, I do "utreplica -l" and get:
Sun Ray Core Services 4.1
Administration Failover Configuration
server1 is a primary server for:
server2
 
On server2, I do "utreplica -l" and get:
Sun Ray Core Services 4.1
Administration Failover Configuration
server2 is a secondary server
The primary server is: server1
 
Am going to reset "#enableMulticast=true" and do a "utrestart -c" and see what I get.
 
 
AJ Levy
IS Admin/Security Mgr
301-342-5707 work
240-925-8113 cell


From: Bob Doolittle
Sent: Wed 4/22/2009 1:01 PM
To: SunRay-Users mailing list
Subject: Re: [SunRay-Users] Sunray FOG on Trusted Extensionspartially working

I presume you've used "utadm -a e1000g1" to configure the network then?
No "utadm -A <subnet>" or "utadm -L on" to enable LAN?

Maybe you could send us "utadm -l" output when you get back into work.

-Bob

Alfred Levy wrote:
> Sorry this may not be complete, I'm at home sick today. But here goes:
>
> Interface e1000g0 is the global zone's physical interface, IP 176.1.x.x/16.
> Server names are server1 and server2 in the hosts file for these interfaces.
>
> Interface e1000g0:4 is the all-zone's logical interface, also 176.1.x.x/16.
>
> Interface e1000g1 is the SRSS physical interface, IP 192.168.110.x/24.
> Servers are named server1-srss and server2-srss in the hosts file for these
> interfaces. The two SRSS FOG servers connect their e1000g1 ports to the Sun
> Rays through a common switch. There's only Sun Rays and the FOG servers on
> this switch, and all are in the office space, no remote connections.
>
> The labeled zones in Trusted Extensions are e1000g2 - e1000g9, and each has
> its own switch as well. None of these use the 176.1.x.x or 192.168.110.x
> address schemes.
>
> The e1000g0 interfaces have a physically separate switch.
>
> All of the servers are in one location, with Cisco or Dell switches
> connecting them. So yes, I have a lot of switches in my cabinets. I work in
> a very stove-piped office.
>
> IIRC, ipv4 and ipv6 forwarding and routing are disabled
> (netservices-limited)
>
> I can give the auth.props Multicast a try tomorrow when back at work.
>
> There are no routers between any of the servers, except for on the e1000g0
> interface, I'm trying to route 176.1.x.x addresses to another setup.
>
> One thought: Could the replication be going through e1000g1 to the SRSS
> servers correctly, but the group management be trying e1000g0, incorrectly?
>
> Thanks!
>
> AJ Levy
>
>
> On 4/21/09 5:44 PM, "Bob Doolittle" <[email protected]> wrote:
>
>  
>> At this point I'm suspecting a strange network configuration. utgmtarget
>> is last resort, let's not go there yet because this may be a sign of
>> deeper problems.
>>
>> Can you tell us your subnet configurations for your server interfaces,
>> how your subnets are connected, and where your Sun Rays reside?
>>
>> Do you have an interconnect? Is it a single subnet (it needs to be in
>> order to use "utadm -a <intf>")?
>>
>> If your servers are on different subnets, is multicast IP routing
>> enabled on all the routers between them?
>> If they share a single subnet, try editing /etc/opt/SUNWut/auth.props
>> and set enableMulticast=false, then do a utrestart.
>>
>> -Bob
>>
>> A. J.. Levy wrote:
>>    
>>> Checked my gmSignature files, they matched, but I reset the sig
>>> anyway. Did a "utrestart -c" anyway, these two machines are not
>>> production yet.
>>>
>>> Shame that utgstatus does not have an option to show all servers and
>>> status, in addition to its current operation. Hmmmm.
>>> After utrestart, web page still does not show both systems.
>>> Would utgmtarget work for me instead?
>>>
>>> AJ Levy IS Admin/Security Mgr 301-342-5707 work 240-925-8113 cell
>>>
>>>
>>>
>>>
>>> From: Bob Doolittle
>>> Sent: Tue 4/21/2009 4:39 PM
>>> To: SunRay-Users mailing list
>>> Subject: Re: [SunRay-Users] Sunray FOG on Trusted Extensions partially
>>> working
>>>
>>>
>>> Bob Doolittle wrote:
>>>      
>>>> Check your /etc/opt/SUNWut/gmSignature files - if they're not
>>>> identical this is your problem. Correct it by running utgroupsig
>>>> (DON'T edit gmSignature directly!). Run it on both servers, and
>>>> specify the same password to both.
>>>>        
>>> I should mention that you'll have to run "utrestart" after making this
>>> change for utauthd/Group Manger to pick it up, and then wait a few
>>> seconds for the FOG to self-discover. You shouldn't need "utrestart
>>> -c" so you needn't disturb sessions.
>>>
>>> -Bob
>>>
>>> _______________________________________________
>>> SunRay-Users mailing list
>>> [email protected]
>>> http://www.filibeto.org/mailman/listinfo/sunray-users
>>>
>>> ___________________
>>> This email has been scanned for all viruses by Webroot Email Security
>>> System.  ___________________
>>> ___________________
>>> This email has been scanned for all viruses by Webroot Email Security
>>> System.  ___________________
>>>
>>> ------------------------------------------------------------------------
>>>
>>> _______________________________________________
>>> SunRay-Users mailing list
>>> [email protected]
>>> http://www.filibeto.org/mailman/listinfo/sunray-users
>>>  
>>>      
>> _______________________________________________
>> SunRay-Users mailing list
>> [email protected]
>> http://www.filibeto.org/mailman/listinfo/sunray-users
>>
>> ___________________
>> 
>> This email has been scanned for all viruses by Webroot Email
>> Security System.
>> ___________________
>>    
>
>
> ___________________

> This email has been scanned for all viruses by Webroot Email
> Security System. 
> ___________________
> _______________________________________________
> SunRay-Users mailing list
> [email protected]
> http://www.filibeto.org/mailman/listinfo/sunray-users
>  

_______________________________________________
SunRay-Users mailing list
[email protected]
http://www.filibeto.org/mailman/listinfo/sunray-users

___________________

This email has been scanned for all viruses by Webroot Email
Security System. 
___________________

_______________________________________________
SunRay-Users mailing list
[email protected]
http://www.filibeto.org/mailman/listinfo/sunray-users

Reply via email to