MDNS/Bonjour switchs randomly between multiple NICs

Dear Community,
I have a problem with a MacServer and multiple NICs...lets name it MSERV
NIC1 goes into the WWW (194.x.x.x) (Protected with ASA firewall)
NIC2 goes into LAN (172.x.x.x) (no firewall)
I need the WWW NIC for ProfileManager and also the LAN NIC for filesharing and TMB.
Both IPs are reachable from our LAN. DNS is good (nslookup shows up as expected) but mDNS/Bonjour makes some problems:
If I do ping MSERV.local sometimes it resolves the 194 and sometimes the 172 address.
This is a big problem for our time machine server backups! When clients choose the 194-path when they discover their backup target on the server, we generate a HUGE load on our ASA firewall.
How can I force Bonjour only to use the 172er LAN NIC.
Or did I get something dramatically wrong?
Any suggestions?

Tearjerker wrote:
Thank you for your reply!
So you mean to disable Bonjour on the server and set up DNS name as TM target?
Problem is here: How can I do this? Only way I know to connect to my backup server on clients is
System Prefs. -> TM -> Choose Disk. And as far as I know is this a Bonjour connection, right?
When I disable Bonjour service on the server (already tried!) my clients are unable to connect to their target.
Any thoughts?
You should not need to disable Bonjour. Bonjour aka. mDNS uses the .local domain suffix if you use a hostname like MSERV.local it will use Bonjour to try and find the TCP/IP address. (We will ignore the possibility someone might use the .local domain in an Active Directory setup.)
If your using a full-blown DNS e.g. server.domain.com then this is nothing to do with Bonjour and where it will point to is up to your DNS server. In this case you would point it to the 172.x.x.x IP address of the server.
As you want the same server to be contactable via the WAN interface as well for the rest of the work to access what you will want to do is have a 'split-horizon' DNS setup. With this the internal machines use an internal DNS server which points to the internal IP address of the server. You will also have the same domain hosted externally and the same server name but pointing to the external WAN IP address. What you do then have to be careful about is to ensure that all the external host names in that domain are defined also on the internal DNS server even if they are servers hosted externally. For example if you have a www.domain.com server hosted externally so it only has an external (public) IP address then you will still need to define this on your internal DNS server so your internal machines know where to find it, since your internal machines will be using your internal DNS server. If you fail to do this then while the outside world using an external DNS server may be able to access your www server, your internal machines would not be able to because your internal DNS server would otherwise say it does not exist.

Similar Messages

  • Satellite P10 switching randomly between Battery and AC

    I have a satellite P10 that's been having some strange power issues for about a year now.
    My laptop will switch over to battery power even when plugged in. I will then either use the computer until the battery drains and have it shut down or hibernate before the battery will charge.
    I thought I had fixed it by downloading and installing a new Bios from the toshiba website, which seemed to work for a while but now it the problem seems to have returned.
    I have also bought a new battery and power bar, thinking this was the problem...but this did not solve the problem.
    Anyone else out there with similar problems or a method of fixing this?
    any thoughts would be great.

    Hi Greg,
    I suffered this phenomenon on my SA30-141, and by trial and error I found it to be a poor contact between the AC socket on the notebook and the AC plug on the adapter cable. Using the technique that Dennis described I tried waggling the power plug when it was connected and found that I could induce the notebook to switch to battery power following which it would not return to AC power without a complete re-boot.
    I resolved this problem by anchoring the AC cable to the back of the notebook with a small strip of plastic wrapped around the cable and then clamped to one of the nuts on the back panel of the notebook with a spare bolt. This stopped any lateral movement of the AC plug when it was connected even if the notebook was moved about.
    regards,

  • Fastest way you switch between multiple images (CS3) ?

    I'm originally a Fireworks user (from 2001) and am starting to learn Photoshop as it is in my CS3 set and it's superiority in image editing.
    BUT, I was suprised/shocked/P.O.-ed to notice Photoshop doesn't have tabs to easily switch between images like Fireworks has had for the last 7 years.
    (Yes, I realize CS4 has that option now, but I'm not willing to dole out another $600 bucks for another upgrade )
    Anyway, enough ********.
    My question is:
    "Can you tell me how you switch between multiple images opened in Photoshop CS3?"
    I'm assuming there must be a keyboard shortcut I can't find, or something besides having to shrink down the images and routing through them . . .
    Thank you for your time and help,
    Brad

    Hi again My,
    Thanks for the reply on my other post as well.
    Ctrl+Tab
    Got it. Thank you.
    Quick and easy enough. I'm happy :-)
    Brad

  • Bonjour not finding anything from PC with Multiple NICs

    We have two Network Interface Cards in each workstation at work to access two separate Physical Networks. Both networks provide access to ZeroConf (Bonjour) IP Printers.
    Bonjour discovery fails intermittently on the two different networks. Occasionally Printers on one network, the other network, both or neither are visible from various workstations.
    Is mDNSResponder aware of multiple NICs? Is there a way to force mDNSResponder to only search for printers on a particular subnet?

    The second  network adapter was installed after the VPC, indeed.
    In the dropdown menu in the VPC networking settings there was only one network adapter to chose because the description for both physical network cards were the same. Therefore I cannot assign for virtual NICs different physical network adapters.
    Finally I coped with the problem:
    - I uninstalled one of the adapters (removing the drivers, too),
    - edited the INF file in the adapter drivers and changed the description of the adapter
    - I reinstalled the adapter with the altered driver (with the INF file changed).
    Then, in the VPC networking settings both physical adapters appeared (one with the altered description).
    I Wonder if that will cause any problems later ;)
    Thanks for your replies :)

  • Switching between multiple input languages.

    I use English, Korean and Google Japanese. I used to use Windows with the same set of languages and it was even more difficult than in OS X, because each IME may have multiple languages (for example, Korean IME has both Korean and English mode). Now in OS X it is better than Windows because each IME has only single language, but still there are some troubles.
    I use long command + shift. It shows the list in the middle of the screen, but the order is change depending on the current IME. And it only has text, no flag icon, so it is difficult to get the IME I want without carefully watching the screen.
    It looks like OS X does not support assinging a shortcut for each langauge. For example, if I could assign F1 for English, F2 for Korean and F3 for Japanese it would be much easier. Or if only the popup language screen had flag icons...
    Is there any third-party app that helps switching between multiple IMEs?

    If you stop holding down the keys so long, the list should not appear.  Instead, use the flag icons at the top right of the screen to tell which keyboard is active.  If you don't see those icons, go to system prefs/language & text/input sources and check the box for Show Input Menu in Menu Bar.
    I don't know of any way to use keyboard shortcuts in general for this, but the app Nisus Writer has preference settings that let you set that up for that app.

  • Switching between multiple libraries

    So heres the deal. I have a 30G Video and my father has a 30G Video also. He likes his music the way it is and I do too. I have heard that you can create multiple libraries so you dont have to create different Login names (windows, we both share one computer.) So the thing is, how do you switch between those libraries? I tried just opening the library but all that does is add my library to the current one.
    How can I swith between multiple libraries with ease and without messing any of the music in them up.

    I downloaded a program that allows me to use it, thanks

  • Switching between multiple tabs?

    I am currently running Safari 3.2.1, haven't updated to 4 yet...Does anyone know a keyboard shortcut to switch between multiple tabs? Like you can "command+tab" to switch between multiple applications...If I have 2,3,4, etc tabs open in a single window, is there a command to switch between those multiple tabs without using my mouse???

    Simpatico wrote:
    it´s such a pity that Safari cannot abide by industry practice (IE, Chrome, Firefox) some command key + no of tab, instead of associating that to bookmarks.
    What happens after 9 tabs? I regularly have 15+ open.

  • ISE 1.2 - Multiple NICs/Load Balancing for DHCP Probe

    Hello guys
    Just prepping an ISE 1.2 patch 8 setup in our organization. I am going for the virtual appliances with multiple NICs. It will be a distributed deployment with 4 x PSNs behind a load balancer and there is no requirement for wireless or guest user at the moment. I've got 2 points I will like to get some guidance on:
    Our DC has a dedicated mgmt network and I plan to IP the gig0 interface of the PANs, MNTs and PSNs from this subnet. All device admin, clustering, config replication, etc will be over this interface. However, RADIUS/probe/other user traffic to the ISE PSNs will be over the gig1 interface which will be addressed from another L3 network. Is this a supported configuration in ISE?
    I intend to use the DHCP probe as part of device profiling and will ideally like to have just an additional ip helper to add to our switch SVI config. Also, it will appear that WLCs can only be configured for 2 DHCP servers for a given network so another consideration for when we bringing our WLAN in scope. We however use ACE load balancers within our DC and from what I have read, they do not support DHCP load balancing. Are there any workarounds to using the DHCP probe with multiple PSNs without having to add each node as an ip helper/DHCP server on the NADs?
    Thanks in advance
    Sayre

    Hello Sayre-
    For Question #1:
    Management is restricted to GigabitEthernet 0 and that cannot be changed so you should be good there
    You can configure Radius and Profiling to be enabled on other interfaces
    Even though you are not using guest services yet, you can dedicate an interface just for that. As a result, you can separate guest traffic completely from your production network
    Take a look at this link for more info:
    http://www.cisco.com/c/en/us/td/docs/security/ise/1-2/installation_guide/ise_ig/ise_app_c-ports.html
    For Question #2
    If you are using a Cisco WLC and running code 7.4 and newer you don't need to mess with the IP helper configurations. 
    The controller can be configured to act as a collector for client profiling and interact with the DHCP thread along with the RADIUS accounting task that is running on the controller. The controller receives a copy of the DHCP request packet sent from the DHCP thread and parses the DHCP packet for two options:
    –Option 12—HostName of the client
    –Option 60—The Vendor Class Identifier
    After this information is gathered from the DHCP_REQUEST packet, a message is formed by the controller with these option fields and is sent to the RADIUS accounting thread, which is in turn transmitted to the ISE in the form of an interim accounting message.
    Both DHCP and HTTP profiling settings are located under the "Advanced" configuration tab in the WLC
    On the other hand, you can also use Anycast for profiling. You can check out some of Cisco Live's sessions for more info on that. Here is one that is from a couple of years (There are more recent ones that are available as well):
    http://www.alcatron.net/Cisco%20Live%202013%20Melbourne/Cisco%20Live%20Content/Security/BRKSEC-3040%20%20Advanced%20ISE%20and%20Secure%20Access%20Deployment.pdf
    I hope this helps!
    Thank you for rating helpful posts!

  • Any improvements in sharing an iPhoto Library between multiple users?

    It is possible and Apple Approved to share an iPhoto Library between multiple users, but the Library must be stored on a drive or disk image that ignores permissions:
    http://tech.kateva.org/2008/10/apple-supports-multi-user-iphoto.html
    This doesn't work for me. Has Apple changed anything with iLife '09 to make it easier to share a Library? For example, have they changed from the prior Package format?
    Message was edited by: jfaughnan

    Alternatives to a trip to the Terminal:
    If you want the other user to be able to see the pics, but not add to, change or alter your library, then enable Sharing in your iPhoto (Preferences -> Sharing), leave iPhoto running and use Fast User Switching to open the other account. In that account, enable 'Look For Shared Libraries'. Your Library will appear in the other source pane.
    Any user can drag a pic from the Shared Library to their own in the iPhoto Window.
    Remember iPhoto must be running in both accounts for this to work.
    If you want the other user to have the same access to the library as you: to be able to add, edit, organise, keyword etc. The problem here is that OS X works very hard to keep your data safe and secure from the other users. You're trying to beat what's built in to the system. So, to beat the system
    Quit iPhoto in both accounts
    Move the iPhoto Library Folder to an external HD set to ignore permissions. You could also use a Disk Image or even partition your Hard Disk.
    In each account in turn: Hold down the option (or alt) key and launch iPhoto. From the resulting dialogue, select 'Choose Library' and navigate to the new library location. From that point on, this will be the default library location. Both accounts will have full access to the library, in fact, both accounts will 'own' it.
    However, there is a catch with this system and it is a significant one. iPhoto is not a multi-user app., it does not have the code to negotiate two users simultaneously writing to the database, and trying will cause db corruption. So only one user at a time, and back up, back up back up.
    Lastly: This method seems a little clunky at first, but works very well. Most importantly, it uses the System to do the job for you.
    Create a new Account on your Mac, call it Media. Create an iPhoto Library there. (BTW: This will work for iTunes too.)
    Enable Sharing on the Library:(Preferences -> Sharing), leave iPhoto running and use Fast User Switching to open the other accounts. In those accounts, enable 'Look For Shared Libraries'. The Library will appear in the other source pane.
    This means that both users will be able to see the pics. If you want to use a pic then simply drag it from the shared Library to your own in the iPhoto Window. This means that each user can have their own edits.
    If you want to add photos to the Library: Log into the Media account for that purpose.
    To make it all seamless: Set your Mac to log into the Media Account automatically. Set iPhoto to launch on log-in. Then switch to your own account using Fast User Switching.
    Net result: a Library that's permanently available to all users but also protected. Each user can have their own versions of the pics if they want.
    No partitioning, no permissions issues. Uses no extra disk space. What's not to like?
    Regards
    TD

  • Switch-independent load-balancing NIC teaming on server-side and MAC/ARP flapping on L2/L3 switches

    Since active deployment of Windows Server 2012, our servers support team began to utilize new feature - switch-independent load-balancing NIC teaming. At first look it seems great - no additional network configuration is required and load balancing is performed by server itself by sending frames in round-robin or some hash algorithm out from different NICs (say two for simplicity) but with same MAC address. Theoretical bandwith is now grown up to 2Gbps (if we have two 1G NICs per server) against failover NIC teaming configuration, when one of two adapters is always down.
    But how does this affect (if does) switching and routing performance of network equipment? From point of view of L2 switch - it has to rewrite its CAM table each time a server sends frame from different NIC. Isn't it expensive operation? Won't it affect switching in a bad way? We see in our logs that same server make switches to change mac-to-port associations several times per second.
    Well, and how does it affect routing, if the switch to which server is connected is L3 switch an performs routing for the subnet server connected to? Will CEF operate well if ARP entry chages several times per second?
    Thank you.

    Since nobody answered here, we created service request and got the following answer (in short):
    L2 MAC flapping between ports is very bad and you must avoid such configurations as much as possible. There is one possible variant that can be considered in your situation - use port-channel (either L2 or L3), in this configuration port-channel will be treted as single port and there won't be flapping.
    Conversation example is here: https://ramazancan.wordpress.com/tag/best-practice/

  • Sharing custom display profiles between multiple users

    Hello,
    I'm brand new to Mountain Lion and I can't figure out how to share a custom display profile between multiple users on the same MBP. I'm a photographer and I have two users set up on my laptop - one personal and one for shooting. I'm using a Color Munki to calibrate my external monitor and the software creates a profile.
    Previously, I could go into my library, copy the profile and drag it into the colorsync folder for my other user, then switch to my other user and find that profile in system preferences/displays.
    I have no idea how to do this in Mountain Lion.

    Let me simplify this by refering to User A and User B to represent the two separate users I've created on my MBP.
    I've done some more digging and here's what I've found: In the Color Sync utility for User A my custom profile is in a user folder, represented by the name I gave the file when the profile was created. That's no problem
    When I switch to the User B, there are two profiles in the Color Sync Utility named "Display". The "Display" file was created at the same time my custom profile was created, however, the file names don't match and I don't know why there are two of them.
    I'm fairly certain that "Display" profile is the custom profile I want to use, but there's a problem coming down the road: what's going to happen when I profile my monitor again in 3 weeks.

  • Detecting multiple NIC's

    Hi,
    On Windows, a call to gethostname(), followed by
    the call to gethostbyname(), will return the hostent
    structure where the
    h_addr_list[0] .... [1] .. etc, will list all the NICS that
    were detected on the host system.
    I tried running the same program on Solaris 2.6 which has multiple NICS and the call returned with only a listing for h_addr_list[0] ... and nothing else.
    What might be the equivalent call that might do the same work on Solaris .... ?
    thanks,
    ritesh

    Hi Sir,
    Sorry for the dealy .
    Please run the following command to check what physical NIC was bound to external virtual switch:
    PS C:\Users\administrator.SERVERLAB> get-vmswitch
    Name SwitchType NetAdapterInterfaceDescription
    Internal Internal
    New Virtual Switch for andy Internal
    qostest Internal
    team2 Internal
    External External Intel(R) 82579LM Gigabit Network Connection
    Best Regards,
    Elton Ji
    Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Subscriber Support, contact [email protected] .

  • Navigate Between Multiple Account Log-in and Log-out

    I have an iMac running 10.5.8. I have it set up with five user accounts. Each user has to log-in and log-out to navigate between uses. Is there a way to navigate between multiple users without the constant logging in and logging out by the users?

    Top right hand corner of the menu bar, right beside the Spotlight icon, is the Fast User Switching menu.

  • Firewall causes slow mDNS (Bonjour) Lookups

    I'm planning to upgrade our company's tiger server to leopard soon and for testing purposes I'm running Leopard server (10.5.5) on another machine. I've worked out most of the issues except for one major one.
    mDNS (Bonjour) lookups take about 60-90 seconds to resolve when the server's firewall is running. This is the same problem across lookups for any service (SSH via terminal, web, AFP). I don't plan to use mDNS on our network as the server will be running DNS for our LAN, but Time Machine backups always connect to the AFP share using the mDNS name rather than the server's Fully Qualified Domain Name. When this lookup takes such a long time it will more or less freeze the client system during this time.
    Client machines aren't running firewalls locally.
    This happens with both tiger and leopard clients.
    I have tried setting the firewall to allow all connections from "any" to "any" but it still doesn't work.
    I am not running DNS on the server but I have tried turning it on with still no luck.
    Here are the results from running "sudo ipfw list":
    00001 allow udp from any 626 to any dst-port 626
    01000 allow ip from any to any via lo0
    01010 deny log logamount 1000 ip from any to 127.0.0.0/8
    01020 deny log logamount 1000 ip from 224.0.0.0/4 to any in
    12300 allow tcp from any to any established
    12301 allow tcp from any to any out
    12302 allow udp from any to any out keep-state
    12303 allow tcp from any to any dst-port 53 out keep-state
    12303 allow udp from any to any dst-port 53 out keep-state
    12304 allow udp from any to any in frag
    12305 allow tcp from any to any dst-port 311
    12306 allow tcp from any to any dst-port 625
    12307 allow udp from any to any dst-port 626
    12308 allow icmp from any to any icmptypes 8
    12309 allow icmp from any to any icmptypes 0
    12310 allow igmp from any to any
    12311 allow esp from any to any
    12312 allow gre from any to any
    12313 allow udp from any to any dst-port 4500
    12314 allow ip from 192.168.15.0/24 to any via en0 keep-state
    12314 allow ip from 192.168.16.0/24 to any via en0 keep-state
    12315 allow udp from any 68 to any dst-port 67 via en0
    65534 deny log logamount 1000 ip from any to any
    65535 allow ip from any to any
    Note that this should block most services but allow machines on our internal subnets (192.168.15.0 and 192.168.16.0) to connect.
    Any help or advice will be greatly appreciated.
    Thanks.

    I have independently confirmed Baerner's results. Last week I installed ethereal and Wireshark from the fink project and traced the IPP data packets between my desktop client and the print server. Bonjour is definitely using IPV6 in Leopard for printing services.
    Reading the Wikipedia page, http://en.wikipedia.org/wiki/IPv6#Special_addresses, I used the ip6fw utility to add the firewall rule:
    *01101 allow ipv6 from fe80::/10 to fe80::/10*
    which allows link-local addresses to communicate with the server.
    Printing on the server works well with the new firewall rule. I just need to find out how to get the Server Admin tool to set the rule from the FireWall GUI.

  • Vm with multiple nic

    Most of the time I only add a second vNIC to multi-hone the VM so it can connect to two different subnets (i.e. one vNIC for backup traffic connected to a different vSwitch with different physical uplink than all connections for production VM traffic).
    As Rod said, it may prove more beneficial to only have one vNIC unless you somehow have so much traffic that the one vNIC is overloaded.  What version of VMWare are you running?  

    We have a switch with multiple vmmic (five), Is there any advantages os using multiple nic for vm to improve network performance ?
    This topic first appeared in the Spiceworks Community

Maybe you are looking for