Views

Server can ping client, client can ping server, but the backup fails with "no NetWorker servers can be found." Why?

This Wiki is brought to you by Backup Central, where you can find the Mr. Backup Blog, Forums, and a mailing list for each forum!

Backup FAQs Service Providers Backup Software Backup Hardware Backup Book Wiki Free Stuff Miscellaneous


"no NetWorker servers can be found."  Why?

Q. From the client I can ping my Legato server using its translated IP address. From the server I can ping the client using its IP address and its netbios name. But when I try to start a backup from the clients "networker client" it says "no networker servers can be found". A. fg posted (28 April 2000): You also have to have forward and reverse DNS entries for the server and client that resolve accurately and symmetrically. You can use client aliases to help DNS problems but the requirement is strict. You must be successful with DNS in both directions. I always make my Admins do DNS correctly and don't depend on aliases to fix DNS problems so I don't know how far you can bend things with client aliases. The reason I do this is because when I didn't, it would work and then break, get fixed and then break... My rule is clear: pick a name for the A record and have PTR record to match it. After that you can have all the CNAME records you like. You should also be aware that Legato is a TCP application and ping is not. I'd test with telnet or ftp instead of ping. This is verified, in part, by an earlier post by Michael Cole (10 Sept 1999): Also, ports on the clients were restricted (through Networker Admin) to the same range as the firewall ports (keeping in mind that "between" does not include the boundary numbers, i.e. 7936). The things that broke this loose for us was getting the ports on the firewall bi-directional (thanks, Elmar) and restricting the ports on the clients (thanks, Jerry). Q. The manual states that the software requires at least nine designated ports to backup a server. Isn't this large number of ports a security risk? A. James G. Rohrich shared this response (3 May 2000) from the Checkpoint mailing list:


  1. I have a single backup system on the LAN but I put a much smaller backup system in my DMZ's for backing DMZ servers. Additional cost, but worth it.
  2. Spoofing IP addresses is reasonably simple. Someone could in theory, crash your Legato server through DOS attacks spoofing your DMZ servers as source.