Start a Conversation

This post is more than 5 years old

Solved!

Go to Solution

1382

May 6th, 2008 13:00

NDMP thru Firewall

EMC docs say port 10000 is the only port NDMP server uses. Although, I am getting conflicting information elsewhere that says the initial session establishment uses port 10000, but all subsequent session traffic will be on a port from a dynamic port range.

Can anyone clarify/validate Celerra NDMP port # usage ?

Thanks.

8.6K Posts

May 6th, 2008 14:00

From the "Configuring NDMP on Celerra manual":

◆ The Celerra Network Server uses port 10000 for NDMP operations. NDMP
three-way backups and restores use dynamic port allocation from the Data
Mover, starting with ports 10001-10004.

what is the conflicting information you are getting ?

26 Posts

May 7th, 2008 12:00

Excerpt from NDMP v4.0 Specifications
can be found at http://www.ndmp.org/download/sdk_v4/
5. Security
NDMP through firewalls is problematic if the data and tape services reside in the interior of separate firewalls such that an NDMP data connection must originate from the exterior of one firewall. If only a single firewall exists, the NDMP Server inside the firewall SHOULD originate the connection as firewalls generally allow any outbound connection.
NDMP Server implementations SHOULD resolve the two firewall problem by providing configurable control over the port number range that will be used for NDMP data connection listens. This control SHOULD be used by system administrators to constrain NDMP Servers to a limited range of TCP ports that correspond to ports the firewall will allow inbound connections on.
NDMP is incompatible with Network Address Translation (NAT) firewalls because IP address and TCP port information is conveyed as payload data between NDMP peers (connect_addr in NDMP_MOVER_LISTEN & NDMP_DATA_LISTEN replies).


Although, after reading this, I believe it refers to a 3-way NDMP session, where the server and tape service are on two different hosts(datamovers). And from the excerpt you provided from the EMC NDMP manual, it appears EMC has already limited this port range for 3-way NDMP to use 10001 thru 10004.

8.6K Posts

May 7th, 2008 13:00

I agree

In your case of a tape drive directly attached to the data mover it is (in NDMP speak) acting both as a data server and a tape server

26 Posts

May 14th, 2008 14:00

Thank you !

1 Rookie

 • 

20.4K Posts

May 15th, 2008 13:00

telenoiz,

please mark correct/helpfull answers, this will help other users querying for similar questions.
No Events found!

Top