ASG
IBM
Zystems
Cressida
Icon
Netflexity
 
  MQSeries.net
Search  Search       Tech Exchange      Education      Certifications      Library      Info Center      SupportPacs      LinkedIn  Search  Search                                                                   FAQ  FAQ   Usergroups  Usergroups
 
Register  ::  Log in Log in to check your private messages
 
RSS Feed - WebSphere MQ Support RSS Feed - Message Broker Support

MQSeries.net Forum Index » Clustering » HACMP auto cluster-sender channel firewall

Post new topic  Reply to topic
 HACMP auto cluster-sender channel firewall « View previous topic :: View next topic » 
Author Message
gerimqseries
PostPosted: Tue Jul 12, 2011 5:33 am    Post subject: HACMP auto cluster-sender channel firewall Reply with quote

Apprentice

Joined: 03 Aug 2009
Posts: 30

Dear Experts,

the situation is the following:
I have a QM1 QManager on a host which has two ip address, because of HACMP configuration, one is the host ip, one is the service ip, the service ip owns the QManager. I have another host in the HACMP, with QM2.
I set the QManager's listener's ip address to the service ip.
I made a full repository cluster with QM1 and QM2, it works well.

Now I have to connect a third host with QMFW to this full repository, but this is behind a firewall. My colleagues set the firewall rule to the service ip-s, but the auto cluster-sender channel can not start!

With "netstat" I see, that the connection wants to go out from the host ip, it should be the service ip! Sure I do not have fw rule to it (it should not to be)!
I can not set "locladdr" property to an auto cluster-sender channel.

What do You suggest?
How to force an auto cluster-sender channel to communicate from the service ip address?

Thank You.
Back to top
View user's profile Send private message
Vitor
PostPosted: Tue Jul 12, 2011 5:37 am    Post subject: Reply with quote

Grand High Poobah

Joined: 11 Nov 2005
Posts: 26093
Location: Texas, USA

What IP address is in the cluster receiver on QM1 & QM2? Is it the HACMP controlled service ip? If not, why not? What additional configuration have you on HACMP and/or WMQ to make that unnecessary?

Is the host ip fully forwarded to the service ip by HACMP?
_________________
Honesty is the best policy.
Insanity is the best defence.
Back to top
View user's profile Send private message
zpat
PostPosted: Tue Jul 12, 2011 5:40 am    Post subject: Reply with quote

Jedi Council

Joined: 19 May 2001
Posts: 5866
Location: UK

Can you set the LOCLADDR value for the channel? This will ensure the outbound IP address (and/or port) is the one you want.
Back to top
View user's profile Send private message
skoobee
PostPosted: Tue Jul 12, 2011 7:20 am    Post subject: Reply with quote

Acolyte

Joined: 26 Nov 2010
Posts: 52

It is not possible to set the LOCLADDR attribute on a CLUSSDR channel. It is always overwritten by the value on the CLUSRCVR.

To set the LOCLADDR you must use a channel auto-definition exit.
Back to top
View user's profile Send private message
gerimqseries
PostPosted: Wed Jul 13, 2011 2:25 am    Post subject: Reply with quote

Apprentice

Joined: 03 Aug 2009
Posts: 30

The "locladdr" for CLUSSDR has been already set.

If I set on QM1 CLUSRCVR "locladdr" value for it's service ip, on the other side for example QMFW the "Auto explicit cluster/sender channel" has that ip address in the "locladdr" parameter, which does not exist there
Sure I have "AMQ9248: The program could not bind to a TCP/IP socket" there.

Maybe the exit should be the solution, what skoobee wrote, or to add the host ip addresses to the firewall rules...

Thank You!
Back to top
View user's profile Send private message
RogerLacroix
PostPosted: Wed Jul 13, 2011 9:47 am    Post subject: Reply with quote

Jedi Knight

Joined: 15 May 2001
Posts: 3264
Location: London, ON Canada

gerimqseries wrote:
Maybe the exit should be the solution, what skoobee wrote, or to add the host ip addresses to the firewall rules...

If you are interested in a CHAD exit solution then have a look at: MQ Channel Auto Creation Manager (MQCACM). MQCACM can set/override most fields of a CLUSSDR channel including the connection name field.

Regards,
Roger Lacroix
Capitalware Inc.
_________________
Capitalware: Transforming tomorrow into today.
Connected to MQ!
Twitter
Back to top
View user's profile Send private message Visit poster's website
Display posts from previous:   
Post new topic  Reply to topic Page 1 of 1

MQSeries.net Forum Index » Clustering » HACMP auto cluster-sender channel firewall
Jump to:  



You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Protected by Anti-Spam ACP
 
 


Theme by Dustin Baccetti
Powered by phpBB © 2001, 2002 phpBB Group

Copyright © MQSeries.net. All rights reserved.