Recent Posts
 
*
Welcome, Guest. Please login or register.
Did you miss your activation email?
August 21, 2008, 08:53:36 PM


Login with username, password and session length


Pages: [1] 2 3 ... 10
 1 
 on: Today at 06:47:24 PM 
Started by rein8 - Last post by rein8
I'm trying to update my AIX OpenBeta with fixpacks from AIX 6.1 and get the following error:

aix cannot load instsecattr
symbol resolution failed symbol __pthread (number 138) is not exported from dependent module libpthreads.a(shr_xpg5.o)

The command is used for storing hash data in a security database, which I don't really care about because it's a home development and learning machine.

Is there a way to get around this?


 2 
 on: Today at 04:36:36 PM 
Started by HRH_H_Crab - Last post by Michael
There are two ways to take care of this. (Actually three, see last comment, but I doubt it is useful for you).
1) Use the ASMI interface to reset the system LED
2) Use a HMC Service Tool to do the same. (I dont have access to an HMC right now, or I would give you the exact name of the Service Tool)

Note: Power Off/Power On does NOT reset the flashing System Indicator (HMC Warning) - only a Factory Reset, or one of the two methods above will stop the flashing.

 3 
 on: Today at 06:12:58 AM 
Started by Toth - Last post by Toth
Hi!
I want to filter just some ports, and don't want change any others.
Thanks for your reply!
Toth

 4 
 on: Yesterday at 03:58:13 PM 
Started by HRH_H_Crab - Last post by HRH_H_Crab
We recently experienced an unplanned power outage in our data center and have had a few issues as a result.
Fortunately, as far as I can tell the only components of the system that were affected were the TSM tape library and the HMC, and perhaps a fiber channel switch connecting the tape library to the TSM server (which is extremely lucky).

I have halted and restarted TSM which can now see the library and appears to be using it happily so Im pretty sure that that side of things is o.k.

In my HMC I can see a couple of exclamation mark warnings for each of the P570s.
I checked the SFP and there were a couple of issues: one referred to a communications fault between the service processors and the HMC (not surprising considering it lost power!) and the other was an error stating that too many fiber channel errors had been received (again not surprising as the tape library had lost power).

Now, I have closed both of those down in the SFP, but the yellow exclamation marks remain. Is it the case that I need to reboot the p570s before these are cleared down or is that wishful thinking?

Should I continue to look for problems and escalate to IBM as appropriate?

 5 
 on: August 19, 2008, 01:11:22 PM 
Started by Toth - Last post by Michael
Glad you got it working - especially using SMIT. I have only used SMIT for configuring the bos.net.ipsec filesets. Your command layout looks quite different from what I am used to.

On my server I have a layout looking like this:

lsfilt -v4 -O
1|permit|0.0.0.0|0.0.0.0|0.0.0.0|0.0.0.0|no|udp|eq|4001|eq|4001|both|both|no|all packets|0|all
2|*** Dynamic filter placement rule for IKE tunnels ***|no
3|permit|192.168.129.0|255.255.255.0|192.168.129.0|255.255.255.0|no|all|any|0|any|0|both|both|no|all packets|0|en0
4|permit|192.168.129.0|255.255.255.0|0.0.0.0|0.0.0.0|no|tcp/ack|any|0|any|0|local|outbound|no|all packets|0|en0
5|permit|0.0.0.0|0.0.0.0|192.168.129.0|255.255.255.128|no|tcp/ack|any|0|any|0|local|inbound|no|all packets|0|en0
6|permit|192.168.129.121|255.255.255.0|192.168.129.121|255.255.255.0|no|tcp|eq|22|any|0|both|both|no|all packets|0|en0
7|permit|192.168.129.121|255.255.255.128|192.168.129.121|255.255.255.128|no|tcp|any|0|eq|22|both|both|no|all packets|0|en0
8|permit|192.168.129.121|255.255.255.128|192.168.129.121|255.255.255.128|no|tcp|any|0|any|0|both|both|no|all packets|0|en0
9|permit|AAA.BBB.127.0|255.255.0.0|192.168.129.121|255.255.255.255|yes|tcp|gt|1023|eq|25|local|inbound|no|all packets|0|en0
10|permit|AAA.BBB.24.0|255.255.255.0|192.168.129.121|255.255.255.255|yes|tcp|gt|1023|eq|25|local|inbound|no|all packets|0|en0
11|permit|192.168.129.121|255.255.255.255|0.0.0.0|255.255.255.255|yes|tcp|eq|25|gt|1023|local|outbound|no|all packets|0|en0
12|permit|AAA.BBB.73.0|255.255.255.0|192.168.129.121|255.255.255.255|no|tcp|gt|1023|eq|25|local|inbound|no|all packets|0|en0
13|permit|AAA.BBB.202.28|255.255.255.255|0.0.0.0|0.0.0.0|no|tcp|gt|1023|eq|25|local|inbound|yes|all packets|0|en0
14|permit|AAA.BBB.175.114|255.255.255.255|192.168.129.121|255.255.255.255|no|tcp|gt|1023|eq|25|local|inbound|yes|all packets|0|en0
15|permit|AAA.BBB.29.65|255.255.255.192|192.168.129.121|255.255.255.255|no|tcp|any|0|eq|25|both|both|yes|all packets|0|en0
16|deny|0.0.0.0|0.0.0.0|0.0.0.0|0.0.0.0|no|tcp|any|0|eq|25|both|inbound|yes|all packets|0|all
17|permit|0.0.0.0|0.0.0.0|0.0.0.0|0.0.0.0|no|tcp/ack|any|0|any|0|local|outbound|no|all packets|0|en0
18|permit|0.0.0.0|0.0.0.0|0.0.0.0|0.0.0.0|no|tcp|any|0|any|0|local|inbound|yes|all packets|0|en0
19|permit|0.0.0.0|0.0.0.0|0.0.0.0|0.0.0.0|yes|all|any|0|any|0|both|both|no|all packets|0|en0
0|deny|0.0.0.0|0.0.0.0|0.0.0.0|0.0.0.0|yes|all|any|0|any|0|both|both|no|all packets|0|all


Rules 3-8 are for local traffic, 9-16 are for SMTP traffic I permit, 16 is actually my deny all rule - so I could log attempts, 17-18 were test rules for setting up inbound and outbound traffic, and rule 19 was to log all other traffic - so I could find traffic I wanted to permit, but was not being caught in an earlier rule.
Rule 0 is the 'official' default rule.

Besides ipfiltering (based on AIX bos.net.ipsec, not a package named ipfilter), I also use a tool of John's that monitors failed logins, etc. to dynamically add rules for improper activity, and optionally delete the rules after a certain delay.

 6 
 on: August 19, 2008, 12:54:16 PM 
Started by MFITS - Last post by Michael
OK. Just checking - but I assume you mean the java based console session.

I do not know exactly which ports are being used, but I am told it is also using openssl in some way to keep the information encrypted (something the gui console did not do, by default, prior to HMC v7.X.

The quickest work around for now would be to have 'users' who need console access to login to the HMC and use the command vtmenu to select the managed system, and partition you want a console to attach to.

Hope this at least resolves the short term problem.

 7 
 on: August 19, 2008, 09:59:53 AM 
Started by MFITS - Last post by MFITS
Hi,

We have a problem with opening Terminals on HMC 7.3.*

We have the following configuration.

workstation(Windows with Firefox:10.76.12.1) -> (en0:10.76.12.2)CSM server(en1:192.168.133.1) -> (eth0:192.168.133.2) HMC (eth1: 10.0.0.1) -> (SP1:10.0.0.254)
   
Now we tunnel the HMC(443) through PUTTY with an ssh tunnel,
HMC 443 ->csm -> workstation 443.

We can open up almost everything.
ASM menu is working DLPAR is working, en HMC onfiguration is all working.

But we arent able to open a Terminal Window to a LPAR.

we tried forwarding port 9735(vtty) and 2302(5250 terminal).
but this doest work either.

Is there another port we are forgetting or is it not possible to tunnel the console.

Should we place the HMC in de 10.76.12 range aswel to get this working.
This is not what we want because the HMC should not be available directly. on the workstation LAN.

Hope you can help.

Greetings
Mark de Jong
M&F IT Solutions

 8 
 on: August 18, 2008, 06:15:32 AM 
Started by Toth - Last post by Toth
Hi!
I solved my problem. The working rules are in this rows below:
4   165    permit    remoteip   255.255.255.255   localip   255.255.255.255 y all any 0 eq    1414   all local both yes yes 0 no 0 patt_none
4   166    permit    remoteip   255.255.255.255   localip   255.255.255.255 y all any 0 eq    1415   all local both yes yes 0 no 0 patt_none
4   167   deny    0.0.0.0    0.0.0.0    localip   0.0.0.0 y all any 0 eq     1414   all both  both     yes yes 0 no 0 patt_none
4   168   deny    0.0.0.0    0.0.0.0    localip   0.0.0.0 y all any 0 eq     1415   all both  both     yes yes 0 no 0 patt_none

Thanks!
Toth

Yes I installed ipfilter from extension dvd, and use this menus:
smit/Communications Applications and Services/TCP/IP/Configure IP Security (IPv4)

 9 
 on: August 17, 2008, 03:12:59 PM 
Started by Toth - Last post by Michael
If it is only filtering, you could use bos.net.ipsec instead. However, if you need NAT functionality - I'll need to study as well.

p.s. I assume you mean ipfilter from the extension CD, or as a download.

 10 
 on: August 16, 2008, 05:59:45 AM 
Started by Toth - Last post by Toth
Hi!
I try use ipfilter under Aix 5.3 TL6. But I don't understand filter rules.
I want to filtering 1 ports packets.
First deny all packet to 1058 port number from all hosts, and allow connection from some host to 1058.
genfilt -v 4 -a P -s LOCALIP -m 255.255.255.255 -d REMOTEIP -M 255.255.255.255 -g Y-c all -o any -p 0 -O eq -P 1058 -r L -w O -l Y -f Y -i all
genfilt -v 4 -a D -s 0.0.0.0 -m 0.0.0.0 -d LOCALIP -M 0.0.0.0 -g Y -c any -o any -p 0 -O eq -P 1058 -r B -w B -l Y -f Y -i all

Please help me correct this rules!
Thanks!
Toth

Pages: [1] 2 3 ... 10
Powered by MySQL Powered by PHP Powered by SMF 1.1.2 | SMF © 2006-2007, Simple Machines LLC

Valid XHTML 1.0! Valid CSS! Dilber MC Theme by HarzeM



eXTReMe Tracker

Terms of Use and Privacy and Security Policies
Copyright 2001-2008 Michael Felt and ROOTVG.NET