NTP Server behind CSS / Responses from outside don't get through

I have a CSS and behind it an NTP-Server (simulated for this posting by the ntpdate-command:
First, when I use ntpdate -q 128.130.2.7 (with the -q parameter a source-port >1024 is used) all wents fine, I get a response and the flow trace-ip shows:
JAN 20 10:12:15 1/1 1187 FLOWMGR-4: UDP in 192.168.7.73:35700->128.130.2.7:123
JAN 20 10:12:15 1/1 1188 FLOWMGR-4: UDP out 128.131.2.73:4724->128.130.2.7:123
JAN 20 10:12:15 1/1 1189 FLOWMGR-4: UDP in 128.130.2.7:123->128.131.2.73:4724
JAN 20 10:12:15 1/1 1190 FLOWMGR-4: UDP out 128.130.2.7:123->192.168.7.73:35700
But when I now use ntpdate 128.130.2.7 without the -q option, i.e. well known Source Port 123 is used, no response come through and the trace-ip shows:
JAN 20 10:13:20 1/1 1194 FLOWMGR-4: UDP in 192.168.7.73:123->128.130.2.7:123
JAN 20 10:13:20 1/1 1195 FLOWMGR-4: UDP out 128.131.2.73:123->128.130.2.7:123
JAN 20 10:13:20 1/1 1196 FLOWMGR-4: UDP in 128.130.2.7:123->128.131.2.73:123
JAN 20 10:13:21 1/1 1197 FLOWMGR-4: UDP in 128.130.2.7:123->128.131.2.73:123
JAN 20 10:13:22 1/1 1198 FLOWMGR-4: UDP in 128.130.2.7:123->128.131.2.73:123
JAN 20 10:13:23 1/1 1199 FLOWMGR-4: UDP in 128.130.2.7:123->128.131.2.73:123
i.e. 128.130.2.7 sends the response to the vip-address and the css receives it, but does not send it to the requesting server.
The relevant configuration parts are (currently ACL is disabled!):
!************************** CIRCUIT **************************
circuit VLAN602
ip address 128.131.2.101 255.255.255.0
ip virtual-router 102 priority 254 preempt
ip redundant-vip 102 128.131.2.72 shared
ip redundant-vip 102 128.131.2.73 shared
ip redundant-vip 102 128.131.2.3 shared
ip critical-service 102 gw-128.131.2
!*************************** GROUP ***************************
group ogawa2
add service ogawa2i
vip address 128.131.2.73
active
!************************** SERVICE **************************
service ogawa2i
ip address 192.168.7.73
active
It looks like, that the response does not comes through, if the source-port of the requesting server uses a port <1024.
Any ideas ??

There are some ports for which we do not maitain flow information but 123 should not be one of them.
What software version are you using ?
A workaround could be to create the following content rules :
owner TEST
content NTP
vip address 128.131.2.73
protocol udp
port 123
add service ogawa2i
active
Let me know if this works.
Gilles.

Similar Messages

  • Email sent from iPad don't get saved

    Sent emails from iPad don't get saved  I

    POP by definition doesn't "share" folders. Sent messages from one machine are invisible to another. Messages deleted on one machine are gone, period. IMAP, used by MobileMe and Gmail, may be better for your needs. I don't use Yahoo mail, but I'd be surprised if this weren't "working as intended" (by them, if not by you.)

  • Do I need a domain name in order to connect to my Mini Server 10.8.2 from outside my network?

    I am working on setting up my mac mini server. Aside from in home file sharing I want ot be able to connect to some files remotely and even upload files, say pictures from my camera, to my server from outside my network. I am only looking to have maybe 2 users that have access. Should I get a domain name from a place like GoDaddy? in order to set up server to use domain in initial setup? I have 2 Drobos connected with my music, videos and pictures and I wat to access them from an Android, Windows and iPod device when away from home. Any how-tos out there or good step by step guides?
    Thanks for any information.
    -Peace
    -Dave

    A normal address like www.domain.com is intended to work with static IP addresses, DynDNS is a service specifically intended for dynamic addresses and it will therefore automatically update the address e.g. name.dyndns.org to match the dynamic IP address each time it changes.
    Some home broadband routers have built-in support to act as a DynDNS client but if yours does not then you can run the DynDNS software on your Mac server. This will then tell the DynDNS servers what your current dynamic IP address is so they can map it to your host name.
    The result will be that your users can use a name like yourname.dyndns.org to access your server and not have to worry about the fact your IP address may change.
    You would still need to run a VPN server to allow your remote users to connect to your network but OS X Server can do this. You could also run a website but depending on your needs that might be better done by using a web hosting service.

  • Remote Desktop in Server 2012 is inaccessible from outside of LAN

    We have a server 2012 machine it was setup and accessible via Remote Desktop for months.  A few days ago we wiped it and did a fresh install of Server 2012.  Now we can not remote to the server from outside of the LAN, even though it is setup exactly
    as it was before. 
    Here is a checklist of things I have checked while trying to figure out the break:
    Router/firewall is forwarding port 3389 to the correct internal static IP of the server.  Port forward test tools online confirm the port is open.
    Windows firewall is set to allow all connections for Remote Desktop on 3389.  Also tried turning off firewall completely, does not fix the issue.
    Allow remote connections is enabled in System Properties, and users have been added to the list of allowed user
    Additional info:  The server is also a standalone Active Directory and Domain Controller.
    Remote desktop connections work fine while in the office on the LAN.  When remoting to the external IP, it doesn't work, even though it did only days before we re-did the server.
    Thanks!

    What should I check in AD?  I am by no means an expert with AD.
    Yes, I am using the same client OS.
    I am talking about RDP over the internet, like from home to the office.  We have a static IP assigned to the router from ISP.  A static internal IP assigned to the server on the LAN.  And the router port forwards 3389 to the assigned IP. 
    It was working fine before we reinstalled Server 2012.  These are the steps I took when reinstalling:
    1. format drive and install OS
    2. rename the server
    3. install SQL server
    4. Install TFS and SharePoint
    5. Add Active Directory role and promote to Domain Controller
    6. Add domain users
    7. Enable remote access on the server and add users to remote access list

  • Email sent from iPad don't get sent

    Some email messages sent from my iPad 2 just disappear. Don't get sent.

    POP by definition doesn't "share" folders. Sent messages from one machine are invisible to another. Messages deleted on one machine are gone, period. IMAP, used by MobileMe and Gmail, may be better for your needs. I don't use Yahoo mail, but I'd be surprised if this weren't "working as intended" (by them, if not by you.)

  • How to obtain response from asyn bpel process invoked through java

    I need to get the response from Asynchronous bpel process which im invoking through java using DeliveryPost method whose return type is void.

    I was able to write java code for the above process
    the code is here
    NormalizedMessage nm = new NormalizedMessage( );
    String uniqueBpelId = com.collaxa.cube.util.GUIDGenerator.generateGUID();
    java.util.Map msgProps = new HashMap();
    // NormalizedMessage res = deliveryService.request("OraFormsService", "initiate", nm);
    //deliveryService.post(null,null,null,null);
    msgProps.put("conversationId",uniqueBpelId);
    nm.setProperty("conversationId",uniqueBpelId);//to set the property for this message
    nm.addPart("payload",xml1);//to add to the payload of this message
    deliveryService.post("OraFormsService", "initiate", nm);
    // System.out.println("con1 "+IDeliveryConstants.STATE_HANDLED);
    StringBuffer buf = new StringBuffer();
    WhereCondition cond;
    cond = new WhereCondition(buf.append(SQLDefs.IM_state).append( " = " ).append(IDeliveryConstants.STATE_UNRESOLVED ).toString() );
    //cond = WhereConditionHelper.whereInstancesOpen();
    IInvokeMetaData imd[] = locator.listInvokeMessages(cond);
    String ids[] = new String[imd.length];
    // print out the partial process information
    // for processes in manual recovery status on invoke
    for (int i = 0; i < imd.length; i++)
    System.out.println("ConversationId=" +
    imd.getConversationId());
    System.out.println("ProcessId=" +
    imd[i].getProcessId());
    System.out.println("State=" + imd[i].getState());
    ids[i] = imd[i].getConversationId();
    Thanks for the Help

  • Remote Server Admin not working from outside of network for 1 server

    Our company recently changed ISPs and I had to change our two 10.4 server's IP addresses. We have a mail server (intel xserve) and a file/web server (quicksilver g4). Both servers have two network cards in them. The problem is two-fold:
    1- I can successfully manage the Xserve machine locally on our network and from my home. However, I can only manage the Quicksilver g4 server locally. Any kind of external access is not even acknowledged.
    2- I'm not sure if I missed any steps when changing IP addresses for these server-based computers. Also, I'm not sure if I correctly set our dns names to the correct IP address.
    For some background, this is the exact IP update process I used for each server:
    Quicksilver G4 (file/web server) - Installed network card #2 and configured it with the new Public IP in the "System Preferences/Network" panel. In Server Admin I set our website to use the new public IP address. (network card #2 has no firewall device in between it and the internet.)
    Then, I configured the default network card #1 to a static, yet private IP address that's behind our DLink firewall device with the rest of our network.
    Intel Xserve (e-mail server) - Network card #1 was the only one setup before our network change. It had a static, public IP address. When we changed ISPs, I configured network card #2 to the new static, public IP address supplied to us by the new ISP in the "System Preferences/Network" panel. This new IP address is where all email traffic currently gets pointed to. (All mail is successfully sent and delivered.) Until our former ISP gets shutdown, I still have network card #1 configured to the older static public IP address. After the old ISP is shut off, I plan on changing network card #1 to a static, private address.
    Any assistance would be greatly appreciated.
      Mac OS X (10.4.8)  

    What should I check in AD?  I am by no means an expert with AD.
    Yes, I am using the same client OS.
    I am talking about RDP over the internet, like from home to the office.  We have a static IP assigned to the router from ISP.  A static internal IP assigned to the server on the LAN.  And the router port forwards 3389 to the assigned IP. 
    It was working fine before we reinstalled Server 2012.  These are the steps I took when reinstalling:
    1. format drive and install OS
    2. rename the server
    3. install SQL server
    4. Install TFS and SharePoint
    5. Add Active Directory role and promote to Domain Controller
    6. Add domain users
    7. Enable remote access on the server and add users to remote access list

  • Set up LAMP server, but not viewable from outside.

    I set up a LAMP server, followed the guide http://wiki.archlinux.org/index.php/LAMP there.  I can view it from localhost or the IP address or the web address http://plaufcan.homeunix.org.  But it is not viewable outside of my local network.  What else do I have to do?

    If your router is showing an external IP address of 192.x.x.x, I am guessing that you are on a DSL line, and that you more than likely used the windows setup software to configure your internet connection.
    Basically, when you run the software, many of the modems go into a very dumb router configuration.  Your router is picking up a natted ip address from the modem, and using that to update dyndns. 
    # nslookup plaufcan.homeunix.org
    Non-authoritative answer:
    Name: plaufcan.homeunix.org
    Address: 192.168.2.101
    I'll bet you dollars to donuts that you can open your browser and go to http://192.168.2.1 (or alternatively http://192.168.2.254) and you'll get access to the modem.  You'll have to find the page that allows it to be set to a bridge.   After that, you'll have to set the router up to do any authentication that your ISP requires.   
    One of the large ISP's in Canada use modems like this for their DSL,  and it causes no end of problem when SOHO users add another router.  NATted NAT connections do not always play nice.

  • Using KAL to monitor app server behind CSS

    We have had issues in the past where the app server has crashed and the CSS would keep sending connections to the front end webserver.
    I am trying to find a way to monitor/keepalive based on the availability of an app server. The webserver is acting as a database app server front end.
    I would like to be able to use the CSS to send a fixed set of (form style or XML) input to the ASP webserver so that it will return an expected output (from the app server) that can be hashed. The GET hash comparison will tell the CSS that the app server is correctly responding to the input.
    Any one have any experience with things like this?
    Carl

    Thanks Steve,
    I created a script that I think will do what I want, but I am not really clear on a couple of points.
    I could not find anything to expand on the syntax for the socket send command. I noticed that some scripts that were posted used what seems like a directive to use the GET method but did not include any input.
    socket send ${SOCKET} "GET ${webpage} http1.0\n\n"
    It seems there may be some undocumented arguments to the socket commands. How do I find them?
    I need to send an XML query as if it came from a form so the webserver will return the webpage I expect it to. The script I have so far is;
    ! Filename: ap-kal-dbstat
    ! Parameters: None - must be coded in script
    ! Description:
    ! This script will attempt to connect to a web server
    ! front end to a database host and
    ! "GET" an html page with dynamic content. The "sendstring"
    ! is some XML query which should return an expected output.
    ! The script checks the contents of the page for the returnstring.
    ! If found, the script passes.
    ! Failure Upon:
    ! 1. The correct arguments are not supplied.
    ! 2. The CSS is unable to connect to the host.
    ! 3. The string is not found in the return page.
    no echo
    if ${ARGS}[#] "LT" "5"
    echo "Usage: ap-kal-dbstat \'Hostname Port Page Sendstring Returnstring\'"
    echo "Example: ap-kal-dbstat \'10.1.1.1 80 webpage.asp XML=string form-element\'"
    exit script 1
    endbranch
    set host "${ARGS}[1]"
    set port "${ARGS}[2]"
    set page "${ARGS}[3]"
    set sendstring "${ARGS}[4]"
    set returnstring "${ARGS}[5]"
    set EXIT_MSG "Host ${host} not responding on TCP port ${port}."
    socket connect host ${host} port ${port} tcp session
    set EXIT_MSG "Socket string: String sent."
    socket send ${SOCKET} "GET ${webpage} ${sendstring}"
    set EXIT_MSG "Socket->Waitfor returnstring not found or timed out waiting."
    socket waitfor ${SOCKET} "${returnstring}" 500
    set EXIT_MSG "Socket: disconnected"
    socket disconnect ${SOCKET}
    echo "String ${returnstring} was found."
    no set EXIT_MSG
    exit script 0
    Does this look like it will achieve my objective?
    Carl

  • How do I import multiple responses from outside Forms Central into a form at one time?

    I created a survey in Word, used Adobe to make into a fillable pdf, emailed it to the prospective respondents, and I have received many emailed responses.  I have uploaded my original form to Adobe Forms and now I would like to upload those responses into Forms Central to make use of its reporting capabilities.  How can I import all of my repsonses into Forms Central?  

    Hi,
    I don't mean to hijack this thread, but Randy had mentioned a bug in Chrome regarding copy/paste. I've been searching for hours for a solution, but nothing on Google Chrome and c/p for the fillable area of a pdf document. Google forums have not yielded anything about fillable forms, so I'm hoping an Adobe forum would be more knowledgable.
    I have a fillable form online where the fillable area cannot be pasted into or copied out of while using Google Chrome. Note that the text already on the document can be c/p'ed. You can see it here: http://www.centralcallegal.org/eictaxcampaign/Coverform.pdf   This is a form for our self-help computer kiosks which use Google Chrome. The form is designed so users can copy and paste their own info into the cover sheet so there won't be any typos.
    Without looking at alternative methods of using the form (i.e. saved on desktop), is there a way to fix this copy/paste issue? It is definitely a Google Chrome issue, as c/p works fine in IE and Mozilla. Thank you.

  • I have no problem connecting my i-phone programs to my tv through apple tv. but one program from an application from appstore don't go through apple tv. It says an error occured while loading the content.This is just for one program. All other works good.

    My apple TV works fine with my I-Phone 4s. But one program from one of the application I downloaded from the app store dont work. When I load that a message comes "an error occured while loading this program" This is  only for one program all other most of the time works good. Any one knows why ?

    Hi there Mundaplackel!
    I have an article here for you that can help you troubleshoot the functionality of that app that you have purchased from the app store, and should be able to give you some steps that will help you resolve the issue:
    iOS: Troubleshooting applications purchased from the App Store
    http://support.apple.com/kb/TS1702
    Thanks for using the Apple Support Communities!
    Cheers,
    Braden

  • For an unknown reason any pics I try to send to email addr from iphone don't get delivered. help?

    For an unknown reason, my iphone no longer sends pics to my email address. Is this a safari issue?. Help?

        Hello sund914,  Let's keep your contacts in house!  Do you use various social media applications like Facebook, Twitter or Google ?  When going to Menu>Setttings>Accounts what are the different accounts currently setup to sync contacts? I would be more than happy to continue to troubleshoot if still needed.
    Thank you,
    YaleK_VZW
    Follow us on Twitter @VZWsupport

  • An email from BPEL doesn't get through

    Hi guys.
    I am testing an email notification service from BPEL, and from the WL EM Console, the result is "Completed"; however, I never get the email in my account, and when I check the log, I find the following notification message:
    WSIFBinding=> [default/MyEmailTest3!1.0*94b9c13b-083c-42e4-999b-1c3a1af5a213.NotificationService_1]:sendNotificationToUser Performing outbound request/response interaction..
    Any ideas on what can be wrong or where to find a log that may help me to trace the error (if any).
    I'm working on weblogic 10.3.2
    Thanks, and have a great weekend!
    Ignacio.

    Welcome to the Apple Community.
    If you still know the ID and password, you can change your email address.
    Start here, change your country if necessary and go to manage your account.

  • I am trying to load my contacts from outlook but not getting through

    I am unable to load my list of contact from outlook unto my iphone 5s

    What method of syncing contacts are you trying?  Are you using iTunes to sync Contacts?  Are you using iCloud Control Panel to link Outlook to iCloud, and then syncing Contacts from iCloud to your iPhone?

  • Slow Response from the server

    It seems that after 1 - 1:30 hrs after the server start the response from app server
    (weblogic 5.1 here) is very very slow. This remains as it is until we stop and
    restart the server..But again after the same period of time the problem continues
    and the server tends to respond slowly.Where could be the problem? If you can
    let us know the underlying problem, it would be great.

    "Amit" <[email protected]> wrote in message news:<3e7054c6$[email protected]>...
    It seems that after 1 - 1:30 hrs after the server start the response from app server
    (weblogic 5.1 here) is very very slow. This remains as it is until we stop and
    restart the server..But again after the same period of time the problem continues
    and the server tends to respond slowly.Where could be the problem? If you can
    let us know the underlying problem, it would be great.OK, check in the admin console for Garbage Collection. You will see
    the heap usage reach 100% and the drop off suddenly. If this is the
    case, consider increasing your heap, if that isnt an option.. Try
    checking your code to make sure everything that is called is
    destroyed.
    That may help... If not it could be JDBC,other connectivity, or code.
    But try that 1st and let me know.
    Steve

Maybe you are looking for