This post is more than 5 years old
26 Posts
0
1382
NDMP thru Firewall
EMC docs say port 10000 is the only port NDMP server uses. Although, I am getting conflicting information elsewhere that says the initial session establishment uses port 10000, but all subsequent session traffic will be on a port from a dynamic port range.
Can anyone clarify/validate Celerra NDMP port # usage ?
Thanks.
Can anyone clarify/validate Celerra NDMP port # usage ?
Thanks.
Rainer_EMC
8.6K Posts
0
May 6th, 2008 14:00
◆ The Celerra Network Server uses port 10000 for NDMP operations. NDMP
three-way backups and restores use dynamic port allocation from the Data
Mover, starting with ports 10001-10004.
what is the conflicting information you are getting ?
telenoiz
26 Posts
0
May 7th, 2008 12:00
can be found at http://www.ndmp.org/download/sdk_v4/
5. Security
NDMP through firewalls is problematic if the data and tape services reside in the interior of separate firewalls such that an NDMP data connection must originate from the exterior of one firewall. If only a single firewall exists, the NDMP Server inside the firewall SHOULD originate the connection as firewalls generally allow any outbound connection.
NDMP Server implementations SHOULD resolve the two firewall problem by providing configurable control over the port number range that will be used for NDMP data connection listens. This control SHOULD be used by system administrators to constrain NDMP Servers to a limited range of TCP ports that correspond to ports the firewall will allow inbound connections on.
NDMP is incompatible with Network Address Translation (NAT) firewalls because IP address and TCP port information is conveyed as payload data between NDMP peers (connect_addr in NDMP_MOVER_LISTEN & NDMP_DATA_LISTEN replies).
Although, after reading this, I believe it refers to a 3-way NDMP session, where the server and tape service are on two different hosts(datamovers). And from the excerpt you provided from the EMC NDMP manual, it appears EMC has already limited this port range for 3-way NDMP to use 10001 thru 10004.
Rainer_EMC
8.6K Posts
1
May 7th, 2008 13:00
In your case of a tape drive directly attached to the data mover it is (in NDMP speak) acting both as a data server and a tape server
telenoiz
26 Posts
0
May 14th, 2008 14:00
dynamox
1 Rookie
1 Rookie
•
20.4K Posts
0
May 15th, 2008 13:00
please mark correct/helpfull answers, this will help other users querying for similar questions.