NTP reverts to local 127.127.1.0 (VMware)

HI. I am experiencing an issue with a LAB deployment of CISCO ISE. I cannot get the NTP to sync and the DB services to start. See output below. Any help will be appreciated
iselab/admin# sh ntp
Configured NTP Servers:
172.16.0.101
synchronised to local net at stratum 11
time correct to within 11 ms
polling server every 1024 s
remote refid st t when poll reach delay offset jitter
==============================================================================
*127.127.1.0 .LOCL. 10 l 26 64 377 0.000 0.000 0.001
172.16.0.101 172.16.0.253 2 u 1630 1024 0 0.000 0.000 0.000
* Current time source, + Candidate
Warning: Output results may conflict during periods of changing synchronization.

The clock sync can take up to 20 minutes to complete.  You may also want to ensure that the ESXi server is also using the same NTP server as your ISE VM.  Since 127.127.1.0 is the local clock, having the ESXi configured this way will help to ensure the correct time in your VM.
The following quote is taken from the page linked below it:
"For example, NTP uses a pseudo IP address 127.127.8.n to access a Meinberg radio clock installed at the local computer. To access its own system clock, also called the local clock , NTP uses the pseudo IP address 127.127.1.0. This IP address must not be mixed up with 127.0.0.1, which is the IP of the localhost, i.e. the computer's loopback interface."
http://www.meinbergglobal.com/english/info/ntp.htm
Please let me know if this fixes your issue.  If it does, please rate this answer and mark your question as Answered.
Charles Moreton

Similar Messages

  • Rescue and Recovery 4.5 Incremental backup reverts to LOCAL when i have 2nd hard drive

    I have 2 hard drives.
    Installed R & R 4.50.
    Set 2nd hard drive as Store Location.
    Initial "scheduled" full back up goes to my D drive. (This does NOT use the windows task scheduler).
    During next Incremental  backup (set by the back up at this time setting), it reverts back to local drive,
    and does another FULL backup to my C drive  folder RRbackups.
    Problem is windows Task Scheduler is NOT set, under TVT folder  task, to backup up to 2nd hard drive.
    I edited Task Scheduler to change folder TVT, task launchRnR, actions  from:
    start a program %R%/rrcmd.exe BACKUP location=L name=Scheduled   scheduled
    to:
    start a program %R%/rrcmd.exe BACKUP location=S name=Scheduled   scheduled
    otherwise, all works fine. Such a Major bug. Anyone else having this problem?
    Solved!
    Go to Solution.

    I recently Reinstalled R and R 4.50. Same bug as i noted.  The entry in the  windows task scheduler is INCORRECT.
    For those backing up to a 2nd hard drive, use my Solution.  The initial BASE backup will go to the correct
    backup location.  Subsequent Incrementals use the Task scheduler to kick off the backup .. I do not know what
    the parmeter is to point to a USB drive.  Location = S is the correct parmeter to back up to a 2nd hard drive. 
    Control Panel>Administrative tools>task scheduler>tvt folder
    Entry "LaunchRnR" select this entry.  Right click this entry. Properties.  Choose the Actions tab. Then EDIT.
    You will see ADD arguments(optional);  entry block will contain
    BACKUP location=L name=Scheduled scheduled
    Change location=L to location=S.  Click OK.  Next run should go to 2nd hard drive. Major Flaw!
    ===
    During Initial 1st time run of R&R, it will ask. you have NOT taken a backup, back up now?  Reply NO.
    If you reply YES, it will go to your C drive, since you have not changed your backup location.
    If you replied YES, you have a base backup on your C drive.  If this happens, Delete the base back up.
    Go to set schedule parm, choose time and day, and location 2nd drive.  It will then ask do you want to back up.
    Reply YES, IT will go to the 2nd hard drive.  THEN the bug shows up when incrementals start.
     Change windows task scheduler as noted above.  

  • Why does iCloud keychain become empty and revert to local  login?

    i finally was able to get iCloud keychain to work.  After a month or so, after I booted my computer, each email address came up wanting the password. I knew this meant the keychain was not providing the passwords, so I checked iCloud and the Keychain was unchecked and the iCloud keychain in Keychain Access was empty with name "local items"  I had to reset the keychain, and now this problem has happened 4-5 times I have researched support articles, but have found no answers. How can I stop this?

    Back up all data before proceeding.
    This procedure will unlock all your user files (not system files) and reset their ownership, permissions, and access controls to the default. If you've intentionally set special values for those attributes on any of your files, they will be reverted. In that case, either stop here, or be prepared to recreate the settings if necessary. Do so only after verifying that those settings didn't cause the problem. If none of this is meaningful to you, you don't need to worry about it, but you do need to follow the instructions below.
    Step 1
    If you have more than one user, and the one in question is not an administrator, then go to Step 2.
    Triple-click anywhere in the following line on this page to select it:
    sudo find ~ $TMPDIR.. -exec chflags -h nouchg,nouappnd,noschg,nosappnd {} + -exec chown -h $UID {} + -exec chmod +rw {} + -exec chmod -h -N {} + -type d -exec chmod -h +x {} + 2>&-
    Copy the selected text to the Clipboard by pressing the key combination command-C.
    Launch the built-in Terminal application in any of the following ways:
    ☞ Enter the first few letters of its name into a Spotlight search. Select it in the results (it should be at the top.)
    ☞ In the Finder, select Go ▹ Utilities from the menu bar, or press the key combination shift-command-U. The application is in the folder that opens.
    ☞ Open LaunchPad. Click Utilities, then Terminal in the icon grid.
    Paste into the Terminal window by pressing command-V. I've tested these instructions only with the Safari web browser. If you use another browser, you may have to press the return key after pasting.
    You'll be prompted for your login password, which won't be displayed when you type it. Type carefully and then press return. You may get a one-time warning to be careful. If you don’t have a login password, you’ll need to set one before you can run the command. If you see a message that your username "is not in the sudoers file," then you're not logged in as an administrator.
    The command may take several minutes to run, depending on how many files you have. Wait for a new line ending in a dollar sign ($) to appear, then quit Terminal.
    Step 2 (optional)
    Take this step only if you have trouble with Step 1, if you prefer not to take it, or if it doesn't solve the problem.
    Start up in Recovery mode. When the OS X Utilities screen appears, select
              Utilities ▹ Terminal
    from the menu bar. A Terminal window will open. In that window, type this:
    res
    Press the tab key. The partial command you typed will automatically be completed to this:
    resetpassword
    Press return. A Reset Password window will open. You’re not going to reset a password.
    Select your startup volume ("Macintosh HD," unless you gave it a different name) if not already selected.
    Select your username from the menu labeled Select the user account if not already selected.
    Under Reset Home Directory Permissions and ACLs, click the Reset button.
    Select
               ▹ Restart
    from the menu bar.

  • Recommended NTP Settings for virtual 2008 R2 PDC (on VMWare)

    Hi,
    Can someone peer-check my settings please for my PDC. We have had time slip issues and this is my proposal:
    Read articles and some blogs from Ace Fekay.
    http://blogs.msdn.com/b/w32time/archive/2009/02/02/group-policy-settings-explained.aspx
    http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&cmd=displayKC&externalId=1318
    http://support.microsoft.com/kb/816042
    Environment
    Domain / Forest FL 2003
    All RWDC's / RODC's are 2008 R2
    PDC is virtual running on VMware. It is not syncing with ESX host, it is an NTP server syncing extrernally. All other DC's / Clients using NT5DS (Domain hierarchy). Incidentily the ESX host sync with external time source also.
    PDC Registry Settings:
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\Parameter\
    Type: NTP
    NtpServer : 1.ntp.org,0x8 2.us.pool.ntp.org,0x8
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\TimeProviders\NtpServer
    Enabled : 1
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\Config
    MaxPosPhaseCorrection : 3600 (1 hour)
    MaxNegPhaseCorrection : 3600 (1 hour)
    AnnounceFlags : 5
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\TimeProviders\NtpClient\SpecialPollInterval
    set at 900 (15 min)
    Run on the PDC:
    w32tm /config /manualpeerlist:1.us.pool.ntp.org,0x8 2.us.pool.ntp.org,0x8 /syncfromflags:manual /reliable:yes /update
    H:\>w32tm /query /status
    Leap Indicator: 0(no warning)
    Stratum: 3 (secondary reference - syncd by (S)NTP)
    Precision: -6 (15.625ms per tick)
    Root Delay: 0.1389195s
    Root Dispersion: 0.0470948s
    ReferenceId: 0xAE85A8C2 (source IP:  174.133.168.194)
    Last Successful Sync Time: 14/10/2011 10:37:18
    Source: 2.us.pool.ntp.org,0x8
    Poll Interval: 9 (512s)
    Run on DC's
    w32tm /config /syncfromflags:domhier /update (then start / stop time service)
    run on clients
    w32tm /resync
    How does this look?

    Hi,
    Thanks for posting here.
    So have you got any problem with current settings in virtualization environment?
    Maybe you can take look the blog post below, some suggestions on how to set NTP service on domain controller in virtualization environment have been discussed in that
    for reference :
    Virtualization of Domain Controllers part Deux
    http://blogs.technet.com/b/janelewis/archive/2008/06/20/virtualization-of-domain-controllers-part-deux.aspx
    Virtual Domain Controllers and Time Synchronisation
    http://blogs.technet.com/b/pfe-ireland/archive/2008/05/08/virtual-domain-controllers-and-time-synchronisation.aspx
    Thanks.
    Tiger Li
    Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.

  • Revert back to Local certificate

    Hello All
    After installing the third party certificate in the WLC, is there anyway to revert to local again ..?
    Considering the situation where DNS server in network is not having entry for virtual host name. Hence clients cannot redirect to the web redirect page.
    KVS

    Well you only need to upload a new certificate if its a 3rd party and that's when you have to have the dns name specified on the VIP.  Ifyou are using the wlc self signed, you don't need to specify a dns name.
    Thanks,
    Scott
    Help out other by using the rating system and marking answered questions as "Answered"

  • Linux ntp server with cisco 3850

    hi all
    i'm trying to make sync with linux ntp with cisco 3850  here is the what i did
    linux centos 6.5 (on the ucs virtual machin) . this is a ntp server
    ip 10.1.1.251
    ===================================================
    For more information about this file, see the man pages
    # ntp.conf(5), ntp_acc(5), ntp_auth(5), ntp_clock(5), ntp_misc(5), ntp_mon(5).
    driftfile /var/lib/ntp/drift
    # Permit time synchronization with our time source, but do not
    # permit the source to query or modify the service on this system.
    restrict default kod nomodify notrap nopeer noquery
    restrict -6 default kod nomodify notrap nopeer noquery
    # Permit all access over the loopback interface.  This could
    # be tightened as well, but to do so would effect some of
    # the administrative functions.
    restrict 127.0.0.1
    restrict -6 ::1
    # Hosts on local network are less restricted.
    restrict 10.1.1.0 mask 255.255.255.0 nomodify notrap
    # Use public servers from the pool.ntp.org project.
    # Please consider joining the pool (http://www.pool.ntp.org/join.html)
    #server 1.centos.pool.ntp.org iburs
    #server 2.centos.pool.ntp.org iburst
    #server 3.centos.pool.ntp.org iburst
    server 127.127.1.0
    fudge 127.127.1.0 stratum 2
    #broadcast 192.168.1.255 autokey        # broadcast server
    #broadcastclient                        # broadcast client
    #broadcast 224.0.1.1 autokey            # multicast server
    #multicastclient 224.0.1.1              # multicast client
    #manycastserver 239.255.254.254         # manycast server
    #manycastclient 239.255.254.254 autokey # manycast client
    # Enable public key cryptography.
    #crypto
    includefile /etc/ntp/crypto/pw
    # Key file containing the keys and key identifiers used when operating
    # with symmetric key cryptography.
    keys /etc/ntp/keys
    # Specify the key identifiers which are trusted.
    #trustedkey 4 8 42
    # Specify the key identifier to use with the ntpdc utility.
    #requestkey 8
    # Specify the key identifier to use with the ntpq utility.
    #controlkey 8
    # Enable writing of statistics records.
    #statistics clockstats cryptostats loopstats peerstats
    and cisco 3850  configured this one
    ntp server 10.1.1.241
    and
    show ntp status
    clock is unsynchronized, stratum 16, reference is null
    why...didn't work.. somebody help me..

    Is there a typo in your post or configuration? You show the NTP server IP address as 10.1.1.251, but the router configured to use 10.1.1.241.
    Regards

  • Running Python locally on Mountain Lion

    I have my local environment set up to run MySQL and PHP. I'm beginning to branch into other languages and trying to get Java, Python, and Ruby to run in my local web server.  All of the languages are installed correctly but apache is not recognizing them or giving me permission issues.
    I've started with Python and after many issues getting apache to recognize the .mod I am now getting a 403 error when I go to that page.
    I'm not sure what the next step is in trying to get this to work correctly.
    403 Forbidden
    Forbidden
    You don't have permission to access / on this server.
    <VirtualHost *:80>
              DocumentRoot "/Library/Webserver/Documents/python-mn"
              ServerName python.local
              ServerAlias www.python.local
              WSGIScriptAlias / /Library/WebServer/Documents/python-mn/wsgi.py
              <Directory /Library/Webserver/Documents/python-mn>
                    #Options Indexes FollowSymLinks MultiViews
                    Options Indexes FollowSymLinks Includes ExecCGI
                    AllowOverride All
                    Order allow,deny
                    allow from all
              </Directory> 
    </VirtualHost>
    Here are some results from terminal:
    tail -f /var/log/apache2/error_log
    [Fri Sep 06 15:30:51 2013] [error] [client 127.0.0.1] mod_hfs_apple: Mis-cased URI or unacceptable Unicode in URI: /Library/WebServer/Documents/python-mn/wsgi.py, wants: /Library/Webserver/Documents/python-mn/
    ping python.local
    PING python.local (127.0.0.1): 56 data bytes
    64 bytes from 127.0.0.1: icmp_seq=0 ttl=64 time=0.041 ms
    64 bytes from 127.0.0.1: icmp_seq=1 ttl=64 time=0.054 ms
    64 bytes from 127.0.0.1: icmp_seq=2 ttl=64 time=0.153 ms
    64 bytes from 127.0.0.1: icmp_seq=3 ttl=64 time=0.159 ms
    64 bytes from 127.0.0.1: icmp_seq=4 ttl=64 time=0.130 ms
    64 bytes from 127.0.0.1: icmp_seq=5 ttl=64 time=0.134 ms
    64 bytes from 127.0.0.1: icmp_seq=6 ttl=64 time=0.054 ms
    64 bytes from 127.0.0.1: icmp_seq=7 ttl=64 time=0.073 ms
    64 bytes from 127.0.0.1: icmp_seq=8 ttl=64 time=0.135 ms
    64 bytes from 127.0.0.1: icmp_seq=9 ttl=64 time=0.111 ms
    64 bytes from 127.0.0.1: icmp_seq=10 ttl=64 time=0.130 ms
    64 bytes from 127.0.0.1: icmp_seq=11 ttl=64 time=0.131 ms
    64 bytes from 127.0.0.1: icmp_seq=12 ttl=64 time=0.133 ms
    64 bytes from 127.0.0.1: icmp_seq=13 ttl=64 time=0.136 ms
    64 bytes from 127.0.0.1: icmp_seq=14 ttl=64 time=0.132 ms
    64 bytes from 127.0.0.1: icmp_seq=15 ttl=64 time=0.140 ms
    64 bytes from 127.0.0.1: icmp_seq=16 ttl=64 time=0.136 ms
    64 bytes from 127.0.0.1: icmp_seq=17 ttl=64 time=0.105 ms
    64 bytes from 127.0.0.1: icmp_seq=18 ttl=64 time=0.052 ms
    64 bytes from 127.0.0.1: icmp_seq=19 ttl=64 time=0.074 ms

    Additional information and links.
    Parallels
    VirtualBox
    VM Fusion
    Snow Leopard server for use with the above. Call 1-800-692-7753 and order part number MC588Z/A. Cost is $19.99 + sales tax and shipping.

  • Netstat Shows Strange Services Running on iPhone Local Sockets

    Hi all,
    I've downloaded and run Netstat from the App Store on my iPhone 5S (iOS 8.1.1). My device is not jailbroken.
    In analyzing Netstat's output, I am concerned regarding several local 127.0.0.1 sockets being used by unfamiliar services as listed below. 1) do you know what these services are, 2) do you see similar connections on your device, and 3) are these services safe?
    2014-12-07 12:13:14 EST
    tcp4
    127.0.0.1
    1.0.0.127
    8021
    intu-ec-client
    0
    LISTEN
    2014-12-07 12:13:14 EST
    tcp4
    127.0.0.1
    1.0.0.127
    1084
    ansoft-lm-2
    0
    LISTEN
    2014-12-07 12:13:14 EST
    tcp4
    127.0.0.1
    1.0.0.127
    1083
    ansoft-lm-1
    0
    LISTEN
    2014-12-07 12:13:14 EST
    tcp4
    127.0.0.1
    1.0.0.127
    1082
    amt-esd-prot
    0
    LISTEN
    2014-12-07 12:13:14 EST
    tcp4
    127.0.0.1
    1.0.0.127
    1081
    pvuniwien
    0
    LISTEN
    2014-12-07 12:13:14 EST
    tcp4
    127.0.0.1
    1.0.0.127
    1080
    socks
    0
    LISTEN
    Thanks so much for any help!

    Hi Tech,
    its safe my netstat show me the same sockets every Time.

  • Local share ask password

    Hi all,
    I have two servers:
    SERVER1 - W2K8R2 Running solution of record security cams.
    SERVER2 - W2KR2 Windows shared, storage recorded files.
    SERVER2 will died, and I'll transfer all recorded files to SERVER1... The solution use \\SERVER2\FILES with reference to find old records.
    Due to this I need access path \\SERVER2\FILES on SERVER1. I created  one share FILES and two entries in host files on SERVER1
    # localhost name resolution is handled within DNS itself.
    # 127.0.0.1       localhost
    # ::1             localhost
    127.0.0.1 SERVER2.mydom.local
    127.0.0.1 SERVER2
    So when I run \\SERVER2\FILES in SERVER1 password are asked.
    I need access this path without password, like a normal share.
    Douglas Filipe http://douglasfilipe.wordpress.com

    Hi,
    Did you try the six methods in the article Ravikumar P mentioned above? You mentioned when you run command \\server2\files in server1 password are ask. Please check if you have permissions to access the local share on server1.
    Best Regards,
    Mandy
    If you have any feedback on our support, please click
    here .
    We
    are trying to better understand customer views on social support experience, so your participation in this
    interview project would be greatly appreciated if you have time.
    Thanks for helping make community forums a great place.

  • Published F4v video and html plays locally but not online...

    I am running Windows 7/64 and Master Collection. I've created a clip of DV NTSC footage to test F4V publishing. Done this many times with CS3 and flv files but this has me stumped. I can successfully view the video and web page locally in IE and Netscape but on upload to my server I have the menu and placement right but no video appears. I created the clip in Premiere Pro CS5 and exported to F4V/FLV best quality. Opened an Actionscript Media DV NTSC template in Flash Pro CS5 and imported the video which I had pre-placed in my root web folder locally. I then exported the swf and saved the fla. All files were then in my root folder and the scrpts in the scripts folder. In Live View in Dreamweaver CS5 all looked fine. In each browser locally the video played as expected. Once all files were uploaded the video was not visible.
    The file is located here...
    http://www.goodmangraphic.com/2010vid.htm
    in the root directory are... Sequence 01_1.f4v, minimaflatcustomcolorall.swf, 2010movie.swf, 2010movie.fla and in the scripts folder, expressinstall.swf and swfobject_modified.js.
    Thanks in advance for any guidance on what I may be doing wrong.
    John

    Ross,
    As you suggested I checked the fla and indeed the local path was there so I changed it to it's relative path, then re exported the swf and saved the fla, re-uploading the files. No luck on ability to see online or even local preview. So I then reset the file location to use the actual URL online and that would not work and even in fla showed an error it could not connect to the file. So I reverted to local naming of the file again to test and sure enough it previewed fine locally in both browsers but again reverting to a relative path or http, failed to sucessfully see the video.
    I am not having these issues with flv format, just the f4v. As an example here is the flv version using the url in the fla file attributes...
    http://www.goodmangraphic.com/2010vid_b.htm
    BTW - I simply renamed the extension after duplicatng the file for the video in this example.
    Appreciate the help.
    John

  • DMP failure on NTP setup

    We've tried to configure our DMP 4400G v 5.2 with NTP against a local server via IP-address. When we hit Apply, we get the message "Contacting ...".
    We cannot login in from any other computer and it never stops. The only way to get the control back is by restarting the DMP. Meanwhile, the DMP continues to show its videos as normal. We've tried using the NTP-server from our laptops without any problem. The network is isolated from the internet and has no DNS.
    /Björn

    /Björn,
    The DMS Suite 5.2 requires DNS.  The issue you are most likely experiencing is the
    DMP is failing DNS requests.  If you snoop the wire (wireshark) of the DMP, you will
    probably see the DMP initiating a Reverse DNS lookup.
    Try adding a Freeware DNS Server in your setup to just test.. this should
    resolve the issue.
    Cheers!
    T.
    DNS Server Now Necessary
    5.2 Requires a present DNS server.
    DMS 5.2 exchanges certificates between Show and Share and Digital Media Manager.
    DNS was recommended, but not necessary (Host file could be manually configured with IP)
    Not possible with 5.2. Certificates require FQDN
    Example DNS Servers: Dedicated server “may not” be required.
    BIND
    PowerDNS
    Simple DNS Plus

  • Nexus 1KV TACACS+ Not Working

    I have been trying to get my Nexus 1KV working with AAA/TACACS+ and I'm stumped.
    The short version is that I see where the issue is, but can't seem to resolve it.
    When I try to log in using TACACS, it fails.  The ACS server reports InvalidPassword.
    The CLI on the Nexus shows:
    2011 Sep  9 16:37:13 NY_nexus1000v %TACACS-3-TACACS_ERROR_MESSAGE: All servers failed to respond
    2011 Sep  9 16:37:14 NY_nexus1000v %AUTHPRIV-3-SYSTEM_MSG: pam_aaa:Authentication failed for user gtopf from 192.168.20.151 - sshd[15675]
    2011 Sep  9 16:37:23 NY_nexus1000v %DAEMON-3-SYSTEM_MSG: error: PAM: Authentication failure for illegal user gtopf from 192.168.20.151 - sshd[15672]
    And an AAA test from the nexus fails.
    I have good connectivity between the two boxes, I can ping, and obviously the failed login showing on ACS shows that it's talking, but it's just not working.
    My config is below (omitted ethernet port configs)
    !Command: show running-config
    !Time: Fri Sep  9 16:45:49 2011
    version 4.2(1)SV1(4a)
    no feature telnet
    feature tacacs+
    feature lacp
    username admin password 5 $1$Q50UpgN/$4eu39QmZHLTf3FAkwwdOF1  role network-admin
    banner motd #Nexus 1000v Switch#
    ssh key rsa 2048
    ip domain-lookup
    ip domain-lookup
    ip name-server 192.168.20.10
    tacacs-server timeout 30
    tacacs-server host 192.168.20.30 key 7 "j3gp0"
    aaa group server tacacs+ TacServer
        server 192.168.20.30
        deadtime 15
        use-vrf management
        source-interface mgmt0
    hostname NY_nexus1000v
    ntp server 192.168.20.10
    aaa authentication login default group TacServer
    aaa authentication login console group TacServer
    aaa authentication login error-enable
    tacacs-server directed-request
    vrf context management
      ip route 0.0.0.0/0 192.168.240.1
    vlan 1,20,40,240
    lacp offload
    port-channel load-balance ethernet source-mac
    port-profile default max-ports 32
    port-profile type ethernet Unused_Or_Quarantine_Uplink
      vmware port-group
      shutdown
      description Port-group created for Nexus1000V internal usage. Do not use.
      state enabled
    port-profile type vethernet Unused_Or_Quarantine_Veth
      vmware port-group
      shutdown
      description Port-group created for Nexus1000V internal usage. Do not use.
      state enabled
    port-profile type ethernet system-uplink
      vmware port-group
      switchport mode trunk
      switchport trunk allowed vlan 20,40,240
      channel-group auto mode active
      no shutdown
      system vlan 240
      description "System profile for critical ports"
      state enabled
    port-profile type vethernet data20
      vmware port-group
      switchport mode access
      switchport access vlan 20
      no shutdown
      description "Data profile for VM traffic 20 VLAN"
      state enabled
    port-profile type vethernet data40
      vmware port-group
      switchport mode access
      switchport access vlan 40
      no shutdown
      description "Data profile for VM traffic 40 VLAN"
      state enabled
    port-profile type vethernet data240
      vmware port-group
      switchport mode access
      switchport access vlan 240
      no shutdown
      description "Data profile for VM traffic 240 VLAN"
      state enabled
    port-profile type vethernet system-upilnk
      description "Uplink profile for VM traffic"
    vdc NY_nexus1000v id 1
      limit-resource vlan minimum 16 maximum 2049
      limit-resource monitor-session minimum 0 maximum 2
      limit-resource vrf minimum 16 maximum 8192
      limit-resource port-channel minimum 0 maximum 768
      limit-resource u4route-mem minimum 32 maximum 32
      limit-resource u6route-mem minimum 16 maximum 16
      limit-resource m4route-mem minimum 58 maximum 58
      limit-resource m6route-mem minimum 8 maximum 8
    interface port-channel1
      inherit port-profile system-uplink
      vem 3
    interface port-channel2
      inherit port-profile system-uplink
      vem 4
    interface port-channel3
      inherit port-profile system-uplink
      vem 5
    interface port-channel4
      inherit port-profile system-uplink
      vem 6
    interface mgmt0
      ip address 192.168.240.10/24
    interface control0
    line console
    boot kickstart bootflash:/nexus-1000v-kickstart-mz.4.2.1.SV1.4a.bin sup-1
    boot system bootflash:/nexus-1000v-mz.4.2.1.SV1.4a.bin sup-1
    boot kickstart bootflash:/nexus-1000v-kickstart-mz.4.2.1.SV1.4a.bin sup-2
    boot system bootflash:/nexus-1000v-mz.4.2.1.SV1.4a.bin sup-2
    svs-domain
      domain id 500
      control vlan 240
      packet vlan 240
      svs mode L2 
    svs connection vcenter
      protocol vmware-vim
      remote ip address 192.168.20.127 port 80
      vmware dvs uuid "52 8b 1d 50 44 9d d7 1f-b6 25 76 f1 f7 97 d8 5e" datacenter-name 28th St Datacenter
      max-ports 8192
      connect
    vsn type vsg global
      tcp state-checks
    vnm-policy-agent
      registration-ip 0.0.0.0
      shared-secret **********
      log-level

    FYI...
    I was able to get TACACS+ auth working using the commands in the Original Post (without the two additional suggestions) as follows...
    1000v# conf t
    1000v(config)# feature tacacs+
    1000v(config)# tacacs-server host 192.168.1.1 key 0
    1000v(config)# aaa group server tacacs+ TacServer
    1000v(config-tacacs+)# server 192.168.1.1
    1000v(config-tacacs+)# use-vrf management
    1000v(config-tacacs+)# source-interface mgmt 0
    1000v(config-tacacs+)# aaa authentication login default group TacServer local
    1000v(config)# aaa authentication login error-enable
    1000v(config)# tacacs-server directed-request
    I guess the OP had some other problem (perhaps incorrect shared secret??)

  • Sap to non sap connection ( program not registered/cpic-call

    Hi all,
        Im trying to connect sap to siebel system.IN TCP/IP connections iv selected register program id & passed the parameters ...program id,gateway host and gateway service
    i followed michal krawczyk steps & also checked in smgw
    transaction also but program id is not registered there
            im getting error like program sapprog not registerd cpic/call
    <b>Detailed error</b>
         <b>Error</b> - program sapprog is not registsred
         <b>location</b> - sap gateway on host saple / sapgw01
         <b>detail</b> - Tp sapprog is not register
         <b>component</b> - gateway
         <b>counter</b> - 387
        <b> module</b> -gwr3cpic
         <b>line-</b> 1621
         <b>return code</b> - 679
         <b>subrc</b>  - 0
               please try to help me out in this issue. all inputs r rewarded. 
      Regards,
      Lavanya

    Hi
    Thanks prince,iv checked entries in sm59,  i checked smgw tranaction(gateway monitor) for logged on clients
    its showing like this
    number/luname/tpname/sys.type/hostname/hostaddres/last req
    0 /sapnav/sapgw00/local_r3/sapnav.sapdomain.com/192.158.3.219
    if i double click on above...
    read/write socket = 4
    handle = 4
    time = tue jan 26 16:54:13 2006
    socket = 1652
    stat = ni_connected
    type = stream ipv4
    out = 1122 messages 64 bytes
    in = 1 messages 64 bytes
    local =127.0.0.1:3300
    remote = 127.0.0.1:1848
    options =
    lu = sapnav
    tp = sapgw00
    lon lu = sapnav
    long tp = sapgw00
    ext program = 0
    no conversation = 24
    appc version = 6
    hostaddr[0] =
    hostaddr[1] = 127.0.0.1
    offset in = 0
    timeouts in = 0
    connected = tue jan 24
    last req = mon jan
    request block number in= -1
    connection out = -1
    target out = -1
    offset out = 0
    restlen out = 0
    timeouts out = 0
    request block number out = -1
    accept info = einfo
    snc forced = 0
    <b>just see gateway monitor 4 sapnav/parameters & attributes</b>Profile
    parameter              Value
    gw/max_sleep           20
    gw/conn_disconnect     900
    gw/conn_pending        60
    gw/gw_disconnect       1800
    gw/req_stack_size      30
    gw/max_conn            500
    gw/max_wp              0
    gw/max_conn_per_wp     10
    gw/cpic_timeout        20
    gw/deallocate_timeout  600
    gw/reg_timeout         60
    gw/reg_lb_level        1
    gw/reg_lb_default      20
    gw/side_info    C:\usr\sap\D01\DVMGS00\data\sideinfo.DAT
    gw/sec_info     C:\usr\sap\D01\DVMGS00\data\secinfo.DAT
    gw/startup     C:\usr\sap\D01\DVMGS00\data\gwstartup.DAT
    gw/stat                0
    gw/tcp_security        1
    gw/cpic_security       1
    gw/max_sys             300
    gw/max_shm_req         50
    gw/max_shm_req_per_conn 10
    gw/max_overflow_size    5000000
    gw/max_overflow_usage   10
    gw/keepalive            300
    gw/reg_keepalive        300
    gw/compatibility        0
    gw/monitor              1
    gw/netstat_once         1
    gw/close_routes         120
    gw/timeout              0
    gw/internal_timeout     0
    gw/nitrace              0
    gw/accept_remote_trace_level 1
    gw/resolve_timeout      0
    rdisp/max_gateways      100
    rdisp/max_comm_entries  500
    rdisp/sna_gateway       sapnav
    rdisp/sna_gw_service    sapgw00
    rdisp/TRACE_LOGGING     OFF
    gw/rem_start            REMOTE_SHELL
    gw/remsh rsh
    exe/gwrd           C:\usr\sap\D01\SYS\exe\run\gwrd.EXE
    snc/enable               0
    snc/permit_insecure_start 0
    Attributes
    Release 640
    Release no 6400
    internal version 2
    start time Tue Jan 24 16:53:47 2006
    build time Aug 17 2004 23:33:51
    build with Unicode TRUE
    build with Threads TRUE
    gateway hostname sapnav
    gateway service sapgw00
    req_sync_limit 24
    appc_ca_blk_size 34396
    gwreq_ln 34588
    appcdata_ln 34316
    overflow_size_limit 500000
    overflow_use 0
    trace level 1
    trace level external programs 2
    PID Gateway Reader 4952
    internal version 2
    Shared memory Sizes in bytes
    CONN_TBL entry 1748
    CONN_TBL total 874000
    STATISTIC area 1392
      iv changed some values for my safety.plz check it and let me know the error to register program id. Hope ull solve my issue this time.
    Thanks in advance,
    Lavanya.

  • Connection Errors

    I'm running 10.4 server (currently 10.4.2 but I've had the same problems on 10.4.4 and 10.4.7) as an internet gateway and content filter. I'm running DNS, DHCP, NAT, Squid Proxy Server and Dan's Guardian content filter. Starting recently, I've been having this problem: after boot up, the server runs fine for a few hours (2-4). Then trying to connect to it by ssh, remote desktop, or Server Admin either takes an extrodinarily long time (10+ minutes) or just times out. If you go to the physical machine it takes forever to log into it (if it ever finishes at all), and takes forever to launch apps. Server Admin gives me errors stating it's not able to communicate with various services, such as DHCP and web (which isn't even running). I've tried rebuilding the server several times, running all the updates, not running the updates, tweaking the DG and Squid configuraton, and nothing seems to make any difference. Right now I'm just running Squid, with DG turned off, still the same results. The system log has various errors in it - servermgrd frequently crashes, ard says there's no admin user, bootpd constantly announces the server's ip addresses and hostname. Below is an edited version of my log. I've taken out the dhcp ack and requests, because they're probably irrevelant to this issue, and I've edited out my host name and ip addresses for the sake of privacy. Does anyone have any ideas as to what the problem might be? I've searched on other forums, and found people with similar problems, but no solutions. Any help would be greatly appreciated.
    Aug 10 03:14:58 gateway cp: error processing extended attributes: Operation not permitted
    Aug 10 03:14:59 gateway cp: error processing extended attributes: Operation not permitted
    Aug 10 03:14:59 gateway 700.daily.server.cyrus: Error: /etc/MailServicesOther.plist postfix does not contain a dictionary with key logrollingdays.
    Aug 10 03:14:59 gateway cp: error processing extended attributes: Operation not permitted
    Aug 10 03:30:27 gateway launchd: com.apple.servermgrd: exited abnormally: Broken pipe
    Aug 10 03:30:27 gateway launchd: com.apple.servermgrd: 9 more failures without living at least 60 seconds will cause job removal
    Aug 10 03:34:38 gateway bootpd[1477]: interface en0: ip <external ip> mask 255.255.25.0
    Aug 10 03:34:38 gateway bootpd[1477]: interface en1: ip <internal ip1> mask 255.255.224.0
    Aug 10 03:34:38 gateway bootpd[1477]: interface en1: ip <internal ip2> mask 255.255.224.0
    Aug 10 03:34:38 gateway bootpd[1477]: server name <my server's hostname>\
    Aug 10 03:53:35 gateway launchd: com.apple.servermgrd: exited abnormally: Broken pipe
    Aug 10 03:53:35 gateway launchd: com.apple.servermgrd: 9 more failures without living at least 60 seconds will cause job removal
    Aug 10 04:02:43 gateway ipfw: limit 1000 reached on entry 1030
    Aug 10 04:04:20 gateway bootpd[1480]: interface en0: ip <external ip> mask 255.255.25.0
    Aug 10 04:04:20 gateway bootpd[1480]: interface en1: ip <internal ip1> mask 255.255.224.0
    Aug 10 04:04:20 gateway bootpd[1480]: interface en1: ip <internal ip2> mask 255.255.224.0
    Aug 10 04:04:20 gateway bootpd[1480]: server name <my server's hostname>
    Aug 10 04:17:13 gateway launchd: com.apple.servermgrd: exited abnormally: Broken pipe
    Aug 10 04:17:13 gateway launchd: com.apple.servermgrd: 9 more failures without living at least 60 seconds will cause job removal
    Aug 10 04:30:53 gateway bootpd[1484]: interface en0: ip <external ip> mask 255.255.25.0
    Aug 10 04:30:53 gateway bootpd[1484]: interface en1: ip <internal ip1> mask 255.255.224.0
    Aug 10 04:30:53 gateway bootpd[1484]: interface en1: ip <internal ip2> mask 255.255.224.0
    Aug 10 04:30:53 gateway bootpd[1484]: server name <my server's hostname>
    Aug 10 04:41:11 gateway launchd: com.apple.servermgrd: exited abnormally: Broken pipe
    Aug 10 04:41:11 gateway launchd: com.apple.servermgrd: 9 more failures without living at least 60 seconds will cause job removal
    Aug 10 04:55:37 gateway bootpd[1487]: interface en0: ip <external ip> mask 255.255.25.0
    Aug 10 04:55:37 gateway bootpd[1487]: interface en1: ip <internal ip1> mask 255.255.224.0
    Aug 10 04:55:37 gateway bootpd[1487]: interface en1: ip <internal ip2> mask 255.255.224.0
    Aug 10 04:55:37 gateway bootpd[1487]: server name <my server's hostname>
    Aug 10 05:03:44 gateway bootpd[1488]: interface en0: ip <external ip> mask 255.255.25.0
    Aug 10 05:03:44 gateway bootpd[1488]: interface en1: ip <internal ip1> mask 255.255.224.0
    Aug 10 05:03:44 gateway bootpd[1488]: interface en1: ip <internal ip2> mask 255.255.224.0
    Aug 10 05:03:44 gateway bootpd[1488]: server name <my server's hostname>
    Aug 10 05:05:34 gateway launchd: com.apple.servermgrd: exited abnormally: Broken pipe
    Aug 10 05:05:34 gateway launchd: com.apple.servermgrd: 9 more failures without living at least 60 seconds will cause job remova
    Aug 10 05:23:29 gateway bootpd[1491]: interface en0: ip <external ip> mask 255.255.25.0
    Aug 10 05:23:29 gateway bootpd[1491]: interface en1: ip <internal ip1> mask 255.255.224.0
    Aug 10 05:23:29 gateway bootpd[1491]: interface en1: ip <internal ip2> mask 255.255.224.0
    Aug 10 05:23:29 gateway bootpd[1491]: server name <my server's hostname>
    Aug 10 05:30:27 gateway launchd: com.apple.servermgrd: exited abnormally: Broken pipe
    Aug 10 05:30:27 gateway launchd: com.apple.servermgrd: 9 more failures without living at least 60 seconds will cause job removal
    Aug 10 05:33:26 gateway bootpd[1494]: interface en0: ip <external ip> mask 255.255.25.0
    Aug 10 05:33:26 gateway bootpd[1494]: interface en1: ip <internal ip1> mask 255.255.224.0
    Aug 10 05:33:26 gateway bootpd[1494]: interface en1: ip <internal ip2> mask 255.255.224.0
    Aug 10 05:33:26 gateway bootpd[1494]: server name <my server's hostname>
    Aug 10 05:50:20 gateway bootpd[1495]: interface en0: ip <external ip> mask 255.255.25.0
    Aug 10 05:50:20 gateway bootpd[1495]: interface en1: ip <internal ip1> mask 255.255.224.0
    Aug 10 05:50:20 gateway bootpd[1495]: interface en1: ip <internal ip2> mask 255.255.224.0
    Aug 10 05:50:20 gateway bootpd[1495]: server name <my server's hostname>
    Aug 10 05:55:41 gateway launchd: com.apple.servermgrd: exited abnormally: Broken pipe
    Aug 10 05:55:41 gateway launchd: com.apple.servermgrd: 9 more failures without living at least 60 seconds will cause job removal
    Aug 10 06:00:40 gateway bootpd[1511]: interface en0: ip <external ip> mask 255.255.25.0
    Aug 10 06:00:40 gateway bootpd[1511]: interface en1: ip <internal ip1> mask 255.255.224.0
    Aug 10 06:00:40 gateway bootpd[1511]: interface en1: ip <internal ip2> mask 255.255.224.0
    Aug 10 06:00:40 gateway bootpd[1511]: server name <my server's hostname>
    Aug 10 06:17:57 gateway bootpd[1512]: interface en0: ip <external ip> mask 255.255.25.0
    Aug 10 06:17:57 gateway bootpd[1512]: interface en1: ip <internal ip1> mask 255.255.224.0
    Aug 10 06:17:57 gateway bootpd[1512]: interface en1: ip <internal ip2> mask 255.255.224.0
    Aug 10 06:17:57 gateway bootpd[1512]: server name <my server's hostname>
    Aug 10 06:17:57 gateway bootpd[1512]: DHCP REQUEST [en1]: 1,0:14:a5:73:ba:4c
    Aug 10 06:17:57 gateway bootpd[1512]: ACK sent <no hostname> 10.1.123.3 pktsize 300
    Aug 10 06:21:19 gateway launchd: com.apple.servermgrd: exited abnormally: Broken pipe
    Aug 10 06:21:19 gateway launchd: com.apple.servermgrd: 9 more failures without living at least 60 seconds will cause job removal
    Aug 10 06:22:27 gateway bootpd[1512]: DHCP REQUEST [en1]: 1,0:a:95:f3:cf:ac <D.PowerBook.Bean>
    Aug 10 06:22:27 gateway bootpd[1512]: ACK sent D.PowerBook.Bean 10.1.123.10 pktsize 342
    Aug 10 06:26:11 gateway bootpd[1512]: DHCP REQUEST [en1]: 1,0:14:a5:73:ba:4c
    Aug 10 06:26:11 gateway bootpd[1512]: ACK sent <no hostname> 10.1.123.3 pktsize 300
    Aug 10 06:32:50 gateway bootpd[1515]: interface en0: ip <external ip> mask 255.255.25.0
    Aug 10 06:32:50 gateway bootpd[1515]: interface en1: ip <internal ip1> mask 255.255.224.0
    Aug 10 06:32:50 gateway bootpd[1515]: interface en1: ip <internal ip2> mask 255.255.224.0
    Aug 10 06:32:50 gateway bootpd[1515]: server name <my server's hostname>
    Aug 10 06:47:27 gateway launchd: com.apple.servermgrd: exited abnormally: Broken pipe
    Aug 10 06:47:27 gateway launchd: com.apple.servermgrd: 9 more failures without living at least 60 seconds will cause job removal
    Aug 10 06:49:50 gateway bootpd[1524]: interface en0: ip <external ip> mask 255.255.25.0
    Aug 10 06:49:50 gateway bootpd[1524]: interface en1: ip <internal ip1> mask 255.255.224.0
    Aug 10 06:49:50 gateway bootpd[1524]: interface en1: ip <internal ip2> mask 255.255.224.0
    Aug 10 06:49:50 gateway bootpd[1524]: server name <my server's hostname>
    Aug 10 07:02:32 gateway bootpd[1525]: interface en0: ip <external ip> mask 255.255.25.0
    Aug 10 07:02:32 gateway bootpd[1525]: interface en1: ip <internal ip1> mask 255.255.224.0
    Aug 10 07:02:32 gateway bootpd[1525]: interface en1: ip <internal ip2> mask 255.255.224.0
    Aug 10 07:02:32 gateway bootpd[1525]: server name <my server's hostname>
    Aug 10 07:13:56 gateway launchd: com.apple.servermgrd: exited abnormally: Broken pipe
    Aug 10 07:13:56 gateway launchd: com.apple.servermgrd: 9 more failures without living at least 60 seconds will cause job removal
    Aug 10 07:20:09 gateway natd[261]: failed to write packet back (No route to host)
    Aug 10 07:20:09 gateway natd[261]: failed to write packet back (Host is down)
    Aug 10 07:20:09 gateway natd[261]: failed to write packet back (Host is down)
    Aug 10 07:20:09 gateway natd[261]: failed to write packet back (Host is down)
    Aug 10 07:26:06 gateway natd[261]: failed to write packet back (No route to host)
    Aug 10 07:26:06 gateway natd[261]: failed to write packet back (Host is down)
    Aug 10 07:26:07 gateway natd[261]: failed to write packet back (Host is down)
    Aug 10 07:26:07 gateway natd[261]: failed to write packet back (Host is down)
    Aug 10 07:26:07 gateway natd[261]: failed to write packet back (Host is down)
    Aug 10 07:26:07 gateway natd[261]: failed to write packet back (Host is down)
    Aug 10 07:32:14 gateway bootpd[1546]: interface en0: ip <external ip> mask 255.255.25.0
    Aug 10 07:32:14 gateway bootpd[1546]: interface en1: ip <internal ip1> mask 255.255.224.0
    Aug 10 07:32:14 gateway bootpd[1546]: interface en1: ip <internal ip2> mask 255.255.224.0
    Aug 10 07:32:14 gateway bootpd[1546]: server name <my server's hostname>
    Aug 10 07:40:49 gateway launchd: com.apple.servermgrd: exited abnormally: Broken pipe
    Aug 10 07:40:49 gateway launchd: com.apple.servermgrd: 9 more failures without living at least 60 seconds will cause job removal
    Aug 10 07:55:31 gateway bootpd[1550]: interface en0: ip <external ip> mask 255.255.25.0
    Aug 10 07:55:31 gateway bootpd[1550]: interface en1: ip <internal ip1> mask 255.255.224.0
    Aug 10 07:55:31 gateway bootpd[1550]: interface en1: ip <internal ip2> mask 255.255.224.0
    Aug 10 07:55:31 gateway bootpd[1550]: server name <my server's hostname>
    Aug 10 08:08:12 gateway launchd: com.apple.servermgrd: exited abnormally: Broken pipe
    Aug 10 08:08:12 gateway launchd: com.apple.servermgrd: 9 more failures without living at least 60 seconds will cause job removal
    Aug 10 08:10:36 gateway sshd[1554]: fatal: Timeout before authentication for 10.1.123.1
    Aug 10 08:25:11 gateway natd[261]: failed to write packet back (No route to host)
    Aug 10 08:25:11 gateway natd[261]: failed to write packet back (Host is down)
    Aug 10 08:25:12 gateway natd[261]: failed to write packet back (Host is down)
    Aug 10 08:25:12 gateway natd[261]: failed to write packet back (Host is down)
    Aug 10 08:25:12 gateway natd[261]: failed to write packet back (Host is down)
    Aug 10 08:25:12 gateway natd[261]: failed to write packet back (Host is down)
    Aug 10 08:26:51 gateway bootpd[1580]: interface en0: ip <external ip> mask 255.255.25.0
    Aug 10 08:26:51 gateway bootpd[1580]: interface en1: ip <internal ip1> mask 255.255.224.0
    Aug 10 08:26:51 gateway bootpd[1580]: interface en1: ip <internal ip2> mask 255.255.224.0
    Aug 10 08:26:51 gateway bootpd[1580]: server name <my server's hostname>
    Aug 10 08:35:56 gateway launchd: com.apple.servermgrd: exited abnormally: Broken pipe
    Aug 10 08:35:56 gateway launchd: com.apple.servermgrd: 9 more failures without living at least 60 seconds will cause job removal
    Aug 10 08:49:03 localhost kernel[0]: standard timeslicing quantum is 10000 us
    Aug 10 08:49:03 localhost lookupd[54]: lookupd (version 365) starting - Thu Aug 10 08:49:03 2006
    Aug 10 08:49:03 localhost kernel[0]: vmpagebootstrap: 509454 free pages
    Aug 10 08:49:03 localhost watchdogtimerd: Automatic reboot timer enabled.
    Aug 10 08:49:03 localhost kernel[0]: migtable_maxdispl = 70
    Aug 10 08:49:03 localhost kernel[0]: 90 prelinked modules
    Aug 10 08:49:03 localhost kernel[0]: Copyright (c) 1982, 1986, 1989, 1991, 1993
    Aug 10 08:49:03 localhost kernel[0]: The Regents of the University of California. All rights reserved.
    Aug 10 08:49:03 localhost kernel[0]: using 5242 buffer headers and 4096 cluster IO buffer headers
    Aug 10 08:49:03 localhost kernel[0]: DART enabled
    Aug 10 08:49:03 localhost kernel[0]: MacRISC4CPU: publishing BootCPU
    Aug 10 08:49:03 localhost kernel[0]: Enabling ECC Error Notifications
    Aug 10 08:49:03 localhost kernel[0]: FireWire (OHCI) Apple ID 42 built-in now active, GUID 001124ff fe401f72; max speed s800.
    Aug 10 08:49:03 localhost kernel[0]: Security auditing service present
    Aug 10 08:49:03 localhost kernel[0]: BSM auditing present
    Aug 10 08:49:03 localhost kernel[0]: disabled
    Aug 10 08:49:03 localhost kernel[0]: rooting via boot-uuid from /chosen: 022D55F8-6B93-3998-98BF-77A1364E9099
    Aug 10 08:49:03 localhost kernel[0]: Waiting on <dict ID="0"><key>IOProviderClass</key><string ID="1">IOResources</string><key>IOResourceMatch</key><string ID="2">boot-uuid-media</string></dict>
    Aug 10 08:49:03 localhost kernel[0]: Got boot device = IOService:/MacRISC4PE/ht@0,f2000000/AppleMacRiscHT/pci@7/IOPCI2PCIBridge/k2-sat a-root@C/AppleK2SATARoot/k2-sata@0/AppleK2SATA/ATADeviceNub@0/IOATABlockStorageD river/IOATABlockStorageDevice/IOBlockStorageDriver/HDS728080PLA380 Media/IOApplePartitionScheme/AppleHFS_Untitled1@3
    Aug 10 08:49:03 localhost kernel[0]: BSD root: disk0s3, major 14, minor 2
    Aug 10 08:49:03 localhost kernel[0]: jnl: replay_journal: from: 6860800 to: 5859328 (joffset 0x267000)
    Aug 10 08:49:03 localhost kernel[0]: hfs mount: enabling extended security on Gateway
    Aug 10 08:49:03 localhost kernel[0]: HFS: Removed 2 orphaned unlinked files
    Aug 10 08:49:03 localhost kernel[0]: Jettisoning kernel linker.
    Aug 10 08:49:03 localhost kernel[0]: Resetting IOCatalogue.
    Aug 10 08:49:03 localhost kernel[0]: Matching service count = 0
    Aug 10 08:49:03 localhost kernel[0]: Matching service count = 10
    Aug 10 08:49:03 localhost kernel[0]: Matching service count = 10
    Aug 10 08:49:03 localhost kernel[0]: Matching service count = 10
    Aug 10 08:49:03 localhost kernel[0]: Matching service count = 10
    Aug 10 08:49:03 localhost kernel[0]: AppleRS232Serial: 44277020 80013020 chip base, virtual, physical
    Aug 10 08:49:03 localhost kernel[0]: IOPlatformControl::registerDriver Control Driver AppleSlewClock did not supply target-value, using default
    Aug 10 08:49:03 localhost kernel[0]: BCM5701Enet: Ethernet address 00:0d:93:9d:98:05
    Aug 10 08:49:03 localhost kernel[0]: BCM5701Enet: Ethernet address 00:0d:93:9d:98:06
    Aug 10 08:49:04 localhost diskarbitrationd[36]: disk0s3 hfs 022D55F8-6B93-3998-98BF-77A1364E9099 Gateway /
    Aug 10 08:49:04 localhost launchd: org.postfix.master: exited with exit code: 1
    Aug 10 08:49:04 localhost launchd: org.postfix.master: respawning too quickly! throttling
    Aug 10 08:49:04 localhost launchd: org.postfix.master: 9 more failures without living at least 60 seconds will cause job removal
    Aug 10 08:49:04 localhost launchd: org.postfix.master: will restart in 10 seconds
    Aug 10 08:49:04 localhost kernel[0]: AppleBCM5701Ethernet - en0 link active, 100-Mbit, full duplex, no flow control
    Aug 10 08:49:05 localhost servermgrd: servermgr_dns: Couldn't get the primary address
    Aug 10 08:49:05 gateway kernel[0]: AppleBCM5701Ethernet - en1 link active, 100-Mbit, full duplex, no flow control
    Aug 10 08:49:05 gateway configd[34]: setting hostname to "<my server's hostname>"
    Aug 10 08:49:05 gateway servermgrd: cupsd's bootstrap server port not found
    Aug 10 08:49:05 gateway servermgrd: cupsd's bootstrap server port not found
    Aug 10 08:49:05 gateway servermgrd: cupsd's bootstrap server port not found
    Aug 10 08:49:05 gateway servermgrd: cupsd's bootstrap server port not found
    Aug 10 08:49:06 gateway mDNSResponder: Adding browse domain local.
    Aug 10 08:49:06 gateway kernel[0]: AppleBCM5701Ethernet - en0 link active, 100-Mbit, full duplex, no flow control
    Aug 10 08:49:08 gateway kernel[0]: AppleBCM5701Ethernet - en1 link active, 100-Mbit, full duplex, no flow control
    Aug 10 08:49:08 gateway configd[34]: executing /System/Library/SystemConfiguration/Kicker.bundle/Contents/Resources/enable-net work
    Aug 10 08:49:08 gateway configd[34]: posting notification com.apple.system.config.network_change
    Aug 10 08:49:08 gateway lookupd[76]: lookupd (version 365) starting - Thu Aug 10 08:49:08 2006
    Aug 10 08:49:09 gateway squid[138]: Squid Parent: child process 141 started
    Aug 10 08:49:09 gateway servermgrd: servermgr_dns: Reloaded named
    Aug 10 08:49:10 gateway kernel[0]: ATY,Bugsy_A: vram [a8000000:08000000]
    Aug 10 08:49:11 gateway kernel[0]: ATY,Bugsy_B: vram [a0000000:08000000]
    Aug 10 08:49:11 gateway /System/Library/CoreServices/loginwindow.app/Contents/MacOS/loginwindow: Login Window Application Started
    Aug 10 08:49:11 gateway automount[197]: deferring user logout notification while init is in progress...
    Aug 10 08:49:11 gateway loginwindow[200]: Login Window Started Security Agent
    Aug 10 08:49:12 gateway automount[197]: reposting deferred logout notification.
    Aug 10 08:49:12 gateway servermgrd: servermgr_dns: Reloaded named
    Aug 10 08:49:16 gateway /usr/sbin/serialnumberd[190]: serialnumberd: Firewall rule #1 added to allow port 626.
    Aug 10 08:49:17 gateway ARDAgent [219]: ******ARDAgent Launched******
    Aug 10 08:49:17 gateway ARDAgent [219]: ******ARDAgent Ready******
    Aug 10 08:49:19 gateway ntpdate[88]: no server suitable for synchronization found
    Aug 10 08:49:20 gateway configd[34]: target=enable-network: disabled
    Aug 10 08:49:20 gateway /usr/sbin/serveradmin: servermgr_ipfilter:ipfw config:Notice:Disabled firewall
    Aug 10 08:49:20 gateway /usr/sbin/serveradmin: servermgr_ipfilter:ipfw config:Notice:Flushed rules
    Aug 10 08:49:21 gateway /usr/sbin/serveradmin: servermgr_nat: nat config:Notice:nat divert rule for interface 'en0' added to firewall
    Aug 10 08:49:21 gateway /usr/sbin/serveradmin: servermgr_ipfilter:ipfw config:Notice:Enabled firewall
    Aug 10 08:49:21 gateway /usr/sbin/serveradmin: servermgr_nat: nat config:Notice:natd launch requested
    Aug 10 08:49:21 gateway /usr/sbin/serveradmin: servermgr_nat: nat config:Notice:Deleted old NAT rule
    Aug 10 08:49:21 gateway /usr/sbin/serveradmin: servermgr_nat: nat config:Notice:nat divert rule for interface 'en0' added to firewall
    Aug 10 08:49:27 gateway /Applications/Server/Server Admin.app/Contents/MacOS/Server Admin: HTTPREQUESTFAILED: https://gateway.local:311/commands/servermgr_info: authorization required
    Aug 10 08:49:27 gateway /Applications/Server/Server Admin.app/Contents/MacOS/Server Admin: HTTPREQUESTFAILED: https://gateway.local:311/commands/servermgr_info: authorization required
    Aug 10 08:49:27 gateway /Applications/Server/Server Admin.app/Contents/MacOS/Server Admin: HTTPREQUESTFAILED: https://gateway.local:311/commands/servermgr_info: authorization required
    Aug 10 08:49:27 gateway /Applications/Server/Server Admin.app/Contents/MacOS/Server Admin: HTTPREQUESTFAILED: https://gateway.local:311/commands/servermgr_info: authorization required
    Aug 10 08:49:27 gateway /Applications/Server/Server Admin.app/Contents/MacOS/Server Admin: HTTPREQUESTFAILED: https://gateway.local:311/commands/servermgr_info: authorization required
    Aug 10 08:49:27 gateway /Applications/Server/Server Admin.app/Contents/MacOS/Server Admin: HTTPREQUESTFAILED: https://gateway.local:311/commands/servermgr_info: authorization required
    Aug 10 08:49:27 gateway /Applications/Server/Server Admin.app/Contents/MacOS/Server Admin: HTTPREQUESTFAILED: https://gateway.local:311/commands/servermgr_info: authorization required
    Aug 10 08:49:27 gateway /Applications/Server/Server Admin.app/Contents/MacOS/Server Admin: HTTPREQUESTFAILED: https://gateway.local:311/commands/servermgr_info: authorization required
    Aug 10 08:49:27 gateway /Applications/Server/Server Admin.app/Contents/MacOS/Server Admin: HTTPREQUESTFAILED: https://gateway.local:311/commands/servermgr_info: authorization required
    Aug 10 08:49:27 gateway /Applications/Server/Server Admin.app/Contents/MacOS/Server Admin: HTTPREQUESTFAILED: https://gateway.local:311/commands/servermgr_info: authorization required
    Aug 10 08:49:27 gateway /Applications/Server/Server Admin.app/Contents/MacOS/Server Admin: HTTPREQUESTFAILED: https://gateway.local:311/commands/servermgr_info: authorization required
    Aug 10 08:49:27 gateway /Applications/Server/Server Admin.app/Contents/MacOS/Server Admin: HTTPREQUESTFAILED: https://gateway.local:311/commands/servermgr_info: authorization required
    Aug 10 08:49:27 gateway /Applications/Server/Server Admin.app/Contents/MacOS/Server Admin: HTTPREQUESTFAILED: https://gateway.local:311/commands/servermgr_info: authorization required
    Aug 10 08:49:27 gateway /Applications/Server/Server Admin.app/Contents/MacOS/Server Admin: HTTPREQUESTFAILED: https://gateway.local:311/commands/servermgr_info: authorization required
    Aug 10 08:49:27 gateway /Applications/Server/Server Admin.app/Contents/MacOS/Server Admin: HTTPREQUESTFAILED: https://gateway.local:311/commands/servermgr_info: authorization required
    Aug 10 08:49:27 gateway /Applications/Server/Server Admin.app/Contents/MacOS/Server Admin: HTTPREQUESTFAILED: https://gateway.local:311/commands/servermgr_info: authorization required
    Aug 10 08:49:27 gateway /Applications/Server/Server Admin.app/Contents/MacOS/Server Admin: HTTPREQUESTFAILED: https://gateway.local:311/commands/servermgr_info: authorization required
    Aug 10 08:49:27 gateway /Applications/Server/Server Admin.app/Contents/MacOS/Server Admin: HTTPREQUESTFAILED: https://gateway.local:311/commands/servermgr_info: authorization required
    Aug 10 08:49:27 gateway /Applications/Server/Server Admin.app/Contents/MacOS/Server Admin: HTTPREQUESTFAILED: https://gateway.local:311/commands/servermgr_info: authorization required
    Aug 10 08:49:27 gateway /Applications/Server/Server Admin.app/Contents/MacOS/Server Admin: HTTPREQUESTFAILED: https://gateway.local:311/commands/servermgr_info: authorization required
    Aug 10 08:49:27 gateway /Applications/Server/Server Admin.app/Contents/MacOS/Server Admin: HTTPREQUESTFAILED: https://gateway.local:311/commands/servermgr_info: authorization required
    Aug 10 08:49:27 gateway /Applications/Server/Server Admin.app/Contents/MacOS/Server Admin: HTTPREQUESTFAILED: https://gateway.local:311/commands/servermgr_info: authorization required
    Aug 10 08:49:27 gateway /Applications/Server/Server Admin.app/Contents/MacOS/Server Admin: HTTPREQUESTFAILED: https://gateway.local:311/commands/servermgr_info: authorization required
    Aug 10 08:49:28 gateway DirectoryService[42]: Failed Authentication return is being delayed due to over five recent auth failures for username: admin.
    Aug 10 08:50:11 gateway servermgrd: servermgr_ipfilter:ipfw config:Notice:Disabled firewall
    Aug 10 08:50:11 gateway servermgrd: servermgr_ipfilter:ipfw config:Notice:Flushed rules
    Aug 10 08:50:12 gateway /usr/sbin/serveradmin: servermgr_nat: nat config:Notice:nat divert rule for interface 'en0' added to firewall
    Aug 10 08:50:12 gateway servermgrd: servermgr_ipfilter:ipfw config:Notice:Enabled firewall
    Aug 10 08:50:25 gateway sudo: admin : TTY=ttyp1 ; PWD=/Users/admin ; USER=root ; COMMAND=/usr/bin/killall dansguardian
    Aug 10 08:50:53 gateway kernel[0]: arp: 10.1.96.17 moved from 00:0d:93:69:7a:58 to 00:0d:93:69:78:58 on en1
    Aug 10 08:50:56 gateway bootpd[299]: interface en0: ip <external ip> mask 255.255.25.0
    Aug 10 08:50:56 gateway bootpd[299]: interface en1: ip <internal ip1> mask 255.255.224.0
    Aug 10 08:50:56 gateway bootpd[299]: interface en1: ip <internal ip2> mask 255.255.224.0
    Aug 10 08:50:56 gateway bootpd[299]: server name <my server's hostname>
    Aug 10 08:51:19 gateway /usr/sbin/serialnumberd[190]: serialnumberd: Firewall rule #1 added to allow port 626.
    Aug 10 09:01:21 gateway bootpd[362]: interface en0: ip <external ip> mask 255.255.25.0
    Aug 10 09:01:21 gateway bootpd[362]: interface en1: ip <internal ip1> mask 255.255.224.0
    Aug 10 09:01:21 gateway bootpd[362]: interface en1: ip <internal ip2> mask 255.255.224.0
    Aug 10 09:01:21 gateway bootpd[362]: server name <my server's hostname>
    Aug 10 09:20:03 gateway bootpd[471]: interface en0: ip <external ip> mask 255.255.25.0
    Aug 10 09:20:03 gateway bootpd[471]: interface en1: ip <internal ip1> mask 255.255.224.0
    Aug 10 09:20:03 gateway bootpd[471]: interface en1: ip <internal ip2> mask 255.255.224.0
    Aug 10 09:20:03 gateway bootpd[471]: server name <my server's hostname>
    Aug 10 09:26:44 gateway bootpd[514]: interface en0: ip <external ip> mask 255.255.25.0
    Aug 10 09:26:44 gateway bootpd[514]: interface en1: ip <internal ip1> mask 255.255.224.0
    Aug 10 09:26:44 gateway bootpd[514]: interface en1: ip <internal ip2> mask 255.255.224.0
    Aug 10 09:26:44 gateway bootpd[514]: server name <my server's hostname>
    Aug 10 10:00:46 gateway bootpd[711]: interface en0: ip <external ip> mask 255.255.25.0
    Aug 10 10:00:46 gateway bootpd[711]: interface en1: ip <internal ip1> mask 255.255.224.0
    Aug 10 10:00:46 gateway bootpd[711]: interface en1: ip <internal ip2> mask 255.255.224.0
    Aug 10 10:00:46 gateway bootpd[711]: server name <my server's hostname>
    Aug 10 10:11:06 gateway servermgrd: [47] error in getAndLockContext: flock(servermgr_netboot) FATAL time out
    Aug 10 10:11:06 gateway servermgrd: [47] process will force-quit to avoid deadlock
    Aug 10 10:11:06 gateway launchd: com.apple.servermgrd: exited with exit code: 1
    Aug 10 10:11:06 gateway launchd: com.apple.servermgrd: 9 more failures without living at least 60 seconds will cause job removal
    Aug 10 10:15:32 gateway launchd: com.apple.servermgrd: exited abnormally: Broken pipe
    Aug 10 10:15:32 gateway launchd: com.apple.servermgrd: 9 more failures without living at least 60 seconds will cause job removal
    Aug 10 10:16:37 gateway sshd[756]: fatal: Timeout before authentication for 10.1.123.1
    Aug 10 10:18:04 gateway bootpd[711]: DHCP REQUEST [en1]: 1,0:14:a5:73:ba:4c
    Aug 10 10:18:04 gateway bootpd[711]: ACK sent <no hostname> 10.1.123.3 pktsize 300
    Aug 10 10:21:04 gateway launchd: com.apple.servermgrd: exited abnormally: Broken pipe
    Aug 10 10:21:04 gateway launchd: com.apple.servermgrd: 9 more failures without living at least 60 seconds will cause job removal
    Aug 10 10:28:03 gateway launchd: com.apple.servermgrd: exited abnormally: Broken pipe
    Aug 10 10:28:03 gateway launchd: com.apple.servermgrd: 9 more failures without living at least 60 seconds will cause job removal
    Aug 10 10:30:28 gateway bootpd[765]: interface en0: ip <external ip> mask 255.255.25.0
    Aug 10 10:30:28 gateway bootpd[765]: interface en1: ip <internal ip1> mask 255.255.224.0
    Aug 10 10:30:28 gateway bootpd[765]: interface en1: ip <internal ip2> mask 255.255.224.0
    Aug 10 10:30:28 gateway bootpd[765]: server name <my server's hostname>
    Aug 10 10:34:13 gateway servermgrd: [762] error in getAndLockContext: flock(servermgr_dhcp) FATAL time out
    Aug 10 10:34:13 gateway servermgrd: [762] process will force-quit to avoid deadlock
    Aug 10 10:34:13 gateway launchd: com.apple.servermgrd: exited with exit code: 1
    Aug 10 10:34:13 gateway launchd: com.apple.servermgrd: 9 more failures without living at least 60 seconds will cause job removal
    Aug 10 10:36:05 gateway ARDAgent [219]: ValidDHEXAdmin unexpected error -14136
    Aug 10 10:36:05 gateway ARDAgent [219]: entry not found for admin
    Aug 10 10:36:05 gateway ARDAgent [219]: entry not found for admin
    Aug 10 10:36:05 gateway ARDAgent [219]: entry not found for admin
    Aug 10 10:36:05 gateway ARDAgent [219]: entry not found for admin
    Aug 10 10:36:05 gateway ARDAgent [219]: entry not found for admin
    Aug 10 10:36:05 gateway ARDAgent [219]: entry not found for admin
    Aug 10 10:36:09 gateway /Applications/Server/Server Admin.app/Contents/MacOS/Server Admin: [273] ServerManager session failed in connect(gateway.local,127.0.0.1,311): 54
    Aug 10 10:36:09 gateway /Applications/Server/Server Admin.app/Contents/MacOS/Server Admin: [273] ServerManager session failed in connect(gateway.local,127.0.0.1,311): 54
    Aug 10 10:36:09 gateway /Applications/Server/Server Admin.app/Contents/MacOS/Server Admin: [273] ServerManager session failed in connect(gateway.local,127.0.0.1,311): 54
    Aug 10 10:36:09 gateway /Applications/Server/Server Admin.app/Contents/MacOS/Server Admin: [273] ServerManager session failed in connect(gateway.local,127.0.0.1,311): 54
    Aug 10 10:36:09 gateway /Applications/Server/Server Admin.app/Contents/MacOS/Server Admin: [273] ServerManager session failed in connect(gateway.local,127.0.0.1,311): 54
    Aug 10 10:36:09 gateway /Applications/Server/Server Admin.app/Contents/MacOS/Server Admin: [273] ServerManager session failed in connect(gateway.local,127.0.0.1,311): 54
    Aug 10 10:36:09 gateway /Applications/Server/Server Admin.app/Contents/MacOS/Server Admin: [273] ServerManager session failed in connect(gateway.local,127.0.0.1,311): 54
    Aug 10 10:36:09 gateway /Applications/Server/Server Admin.app/Contents/MacOS/Server Admin: [273] ServerManager session failed in connect(gateway.local,127.0.0.1,311): 54
    Aug 10 10:36:09 gateway /Applications/Server/Server Admin.app/Contents/MacOS/Server Admin: [273] ServerManager session failed in connect(gateway.local,127.0.0.1,311): 54
    xserve dual g5 2.3 ghz   Mac OS X (10.4.2)   2 GB RAM, 80 GB HD

    Forgot to mention -
    if you SSH into the server before it starts having problems, you can continue to work on it once it does. The last time I did this I found that the system really wasn't doing much - it had 93% of the CPU free, 1.64 GB of RAM free (of 2 GB total), and only had about 30 network connections.
    Also, according to the firewall log, people are trying to get into my proxy server, but they are being blocked, so I don't think it's anyone relaying spam or anything though the system.

  • BIND 9.2.4 Slow on Solaris 10 01/06

    Hi There,
    Have an issue with 2 x Solaris 10 (Sparc) external DNS servers that we put in. The servers are very quick to resolve local zone files and any cached queries. When i'm requesting a new internet DNS record that is not in the cache, it can take 5-6 seconds for the query to come back.
    I've been doing some reading and other people have had similar issues with IPV4/IPV6 queries. When looking at my bind debug logs i can see that requests go out for AAAA records. The servers are not running IPV6 themselves.
    Is there any way to disable IPV6 in Bind 9.2.4 or has anyone come across this problem before and its something completely different?
    Thanks

    We only have one search domain that is used internally, the external dns servers host about 25 zones on them that they are authoritive for. The 2 external servers are also used by the 2 internal servers to handle internet resolution. Its only slow when requesting FQDN's from the internet that are not int he cache. If i clear the bind cache and look up say www.microsoft.com it takes 5-6 seconds to resolve. Next time its instant.
    Here is most of the named.conf (cut out some of the hosted zones to limit the length);
    acl bogusnets { 0.0.0.0/8; 2.0.0.0/8; 224.0.0.0/3; };
    acl local { 172.19.220.0/32; 172.22.280.0/32; };
    acl local { 127.0.0.1/8; };
    options {
         directory "/var/zones";
         allow-recursion { local; };
         allow-transfer { 172.19.82.17; 172.19.220.4; 172.19.280.5; };
         blackhole { bogusnets; };
    logging {
         category default { default_log; };
         category queries { query_log; };
         category network { network_log; };
         channel default_log {
              file "/var/logs/default.log" versions 7 size 10m;
              print-category     yes;
              print-severity     yes;
              print-time     yes;
         channel query_log {
              file "/var/logs/query.log" versions 7 size 10m;
              print-category     yes;
              print-severity     yes;
              print-time     yes;
         channel network_log {
              file "/var/logs/network.log" versions 7 size 10m;
              print-category     yes;
              print-severity     yes;
              print-time     yes;
         category lame-servers { null; };
    zone "." {
         type hint;
         file "named.cache";
    zone "0.0.127.IN-ADDR.ARPA" {
         type master;
         file "master/db.reverse.127.0.0";
    # Reverse lookups for 172.20
    zone "20.172.IN-ADDR.ARPA" {
         type master;
         file "master/db.reverse.172.20";
    # Reverse lookups for 172.19
    zone "191.150.IN-ADDR.ARPA" {
         type master;
         file "master/db.reverse.172.19";
    # Reverse lookups for 172.20
    zone "205.155.IN-ADDR.ARPA" {
         type master;
         file "master/db.reverse.172.20";
    zone "example.com" {
         type master;
         file "master/db.example.com";     
    zone "abc.int" {
         type stub;
         file "slave/db.abc.int";
         allow-query { internal; local; };
         masters { 172.20.7.120; 172.20.7.121; };
    zone "testing.com" {
         type stub;
         file "slave/db.testing.com";
         allow-query { internal; local; };
         masters { 172.20.8.161; 172.20.7.119; };
    Message was edited by:
    jgooding

Maybe you are looking for