Os X Server 10.4.9+4 eth ports+firewall active: 1 port is totally locked

Ciao to all.
I need a strong help!
I have an XServe where I run few application: AFP, Web, 4Dimension, PureFTP and few other services.
I decided to use 2 of the 4 ethernet ports for a direct connection with 2 G5 used for graphics jobs (192.168.3.1 and 192.168.4.1).
The other 2 eth ports are used:
1) for the web services (the principal in list on "Network" panel) (192.168.0.25)
2) for internal use (AFP , Print etc etc) for the iBooks of the sales department (192.168.0.2)
As described above, the two G5 are directly connected to the card and the other 2 eth ports, on a switch with the rest of tha lan.
I used the Gateway Setup Assistant in order to prepare the routing of the 2 ports directly connected .
I choose the first port ( 192.168.0.25) as main port for internet routing and I choose the 2 G5's port (192.168.3.1 and 192.168.4.1) as lan that needs to be routed..
I did NOT choose the eth port I use for internally purposes (192.168.0.2)......
Generally, the Assistant made a good job; I mean from the 2 G5 I can see ALL the services published on the server AND they are correclty routed on Internet.
The problem is on the port internally dedicated.
When the firewall starts, all the ports of the 192.168.0.2 are filtered!
No way to see one open port.........
I don't have lot of knowledge about firewalling; someone can suggest me a way to make this eth port "free" again?
GRAZIE
Rob (Italy)

I don't understand your settings. Either your ISP is misleading you, or they are doing something very unusual.
>The other eth port was used for internal connection but I had to use the same subnet because , always for ISP settings, to surf on internet, I'm allowed to use ONLY a specific range 192.168.0.2to192.168.0.25.
There is no valid network that run from 192.168.0.2 through 192.168.0.25. The closest you can get is a /27 network which uses the subnet mask 255.255.255.224, but that gives you the IP address range 192.168.0.1 through 192.168.1.32.
It's possible that's what you've got, but I've never seen an ISP hand out a /27 in the 192.168.0 network. Usually they hand out a small number of real-world IP addresses and you use a router to share that address amongst clients on your own private network, but then you wouldn't be limited to such a small subnet.
Can you report all the numbers in the Network Preferences, including subnet mask and router address.
If all your client systems in the same 192.168.0.x network there's no need to use a second NIC in the server - they can all talk to the server on the 192.168.0.25 address.

Similar Messages

  • The DNS server has encountered a critical error from the Active Directory. Check that the Active Directory is functioning properly. The extended error debug information (which may be empty) is "". The event data contains the error.

    got event ID 4015 and source DNS-Server-Service. please suggest how to fix this issue
    The DNS server has encountered a critical error from the Active Directory. Check that the Active Directory is functioning properly. The extended error debug information (which may be empty) is "". The event data contains the error.
    Raj

    Hi
     first run "ipconfig /flushdns" and then "ipconfig /registerdns" finally restart dns service and check the situation,also you can check dns logs computer management ->Event viewer->Custom Views->Server roles->DNS.

  • Trying to install WSUS role on Windows Server 2012 R2 using dedicated SQL Instance with static port on remote SQL Server 2012 SP1 CU7 on Windows Server 2012 R2.

    I am trying to install WSUS role on Windows Server 2012 R2 using dedicated SQL Instance with static port on remote SQL Server 2012 SP1 CU7 on Windows Server 2012 R2.
    It verifies the connection and then throws the error:
    The request to add or remove features on the specified server failed. The operation cannot be completed, because the server you specified requires a restart.
    WSUS Server : Windows Server 2012 R2
    Remote SQL Server: 2012 SP1 CU7 hosted on Windows Server 2012 R2
    Please let me know if anyone has experienced this issue.

    We were trying to install WSUS role on Windows Server 2012 R2 using dedicated SQL Instance with static port on remote SQL Server 2012 SP1 CU7 on Windows Server 2012 R2.
    It verifies the connection and then throws the error:
    The request to add or remove features on the specified server failed. The operation cannot be completed, because the server you specified requires a restart.
    Same error even after rebooting the server multiple times.
    WSUS Server : Windows Server Standard2012 R2
    Remote SQL Server: Windows Server 2012 SP1 CU7 hosted on Windows Server 2012 R2
    Event ID 7000:
    The Windows Internal Database service failed to start due to the following error:
    The service did not start due to a logon failure.
    Event ID 7041
    The MSSQL$MICROSOFT##WID service was unable to log on as NT SERVICE\MSSQL$MICROSOFT##WID with the currently configured password due to the following error:
    Logon failure: the user has not been granted the requested logon type at this computer.
    Service: MSSQL$MICROSOFT##WID
    Domain and account: NT SERVICE\MSSQL$MICROSOFT##WID
    This service account does not have the required user right "Log on as a service."
    User Action
    Assign "Log on as a service" to the service account on this computer. You can use Local Security Settings (Secpol.msc) to do this. If this computer is a node in a cluster, check that this user
    right is assigned to the Cluster service account on all nodes in the cluster.
    If you have already assigned this user right to the service account, and the user right appears to be removed, check with your domain administrator to find out if a Group Policy object associated
    with this node might be removing the right.
    I found following article:
    "MSSQL$MICROSOFT##WID service was unable to log on as NT SERVICE\MSSQL$MICROSOFT##WID" error when you install WID in Windows Server 2012
    http://support.microsoft.com/kb/2832204/en-us
    To work around the issue, use one of the following methods:
    Assign the Log on as a service user right to NT SERVICE\ALL SERVICES in the GPO that defines the user right.
    Exclude the computer from the GPO that defines the user right.
    We moved the SCCM server to OU where no policies were getting applied and then applied the new GPO to that OU. Restarted the server and we were able to install WSUS role.
    Regards
    PR

  • After change port for TCPIP PORT for default SQL Server instance (MSSQLSERVER), sql service and sql agent service did not started again

    Hi 
    -when i install default instance MSSQLSERVER i added a domain account as a service account,
    - when i change port for TCPIP PORT , and after sql service and sql agent service did not started again.
    it thrown error 
    The SQL Server (MSSQLSERVER) service failed to start due to the following error: 
    The service did not start due to a logon failure.
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
        <EventID Qualifiers="49152">7000</EventID>
        <Version>0</Version>
        <Level>2</Level>
        <Task>0</Task>
        <Opcode>0</Opcode>
    but when i add domain\sqservice account in administrators group these services started,
    1) here  why this change behavior  happened
    2i changed the port 1500
    adil

    HI
    the sql instance service is running with domain/sqlservice account , 
    - i stopped the sql service service
    - when i start it not started again and i found below error message
    Domain and account: MOJPORTAL\spsqlservice
    This service account does not have the required user right "Log on as a service."
    User Action
    Assign "Log on as a service" to the service account on this computer. You can use Local Security Settings (Secpol.msc) to do this.
     If this computer is a node in a cluster, check that this user right is assigned to the Cluster service account on all nodes in the cluster.
    If you have already assigned this user right to the service account, and the user right appears to be removed, 
    check with your domain administrator to find out if a Group Policy object associated with this node might be removing the right.
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
        <EventID Qualifiers="49152">7041</EventID>
        <Version>0</Version>
        <Level>2</Level>
        <Task>0</Task>
        <Opcode>0</Opcode>
        <Keywords>0x8080000000000000</Keywords>
        <TimeCreated SystemTime="2015-04-24T17:12:58.326973300Z" />
        <EventRecordID>2177</EventRecordID>
        <Correlation />
        <Execution ProcessID="520" ThreadID="4044" />
        <Channel>System</Channel>
        <Computer>PORTALSQL1.mojportal.com</Computer>
        <Security />
      </System>
      <EventData>
        <Data Name="param1">MSSQL$xSQL</Data>
        <Data Name="param2">xxxL\spsqlservice</Data>
      </EventData>
    </Event>
    adil

  • Can OS X Server 10.6 reverse proxy be setup to route port traffic 5003 (FileMaker Server) to 2 seperate servers (FM 11 and FM 12)?

    Can OS X Server 10.6 reverse proxy be setup to route port traffic 5003 (FileMaker Server) to 2 seperate servers (FM 11 and FM 12)?

    In your scenario, how is the 'OS X 10.6 Server' supposed to identify which FM machine to proxy the connection to?
    The FM client uses a proprietary protocol, so it's not something simple like HTTP.  Off hand I don't know of any way the server can accept arbitrary connections on port 5003 and know which FM server to relay it to.
    Two options come to mind. One is to nix the OS 10.6 Server altogether - I don't understand this machine's purpose in your network - the second is to setup different ports on the OS X 10.6 Server machine and map each port to a different FM server, e.g. 5003 -> FM11, 5004 -> FM12, then you configure the remote client to connect to a different port number based on the server they want to connect to. I haven't used FM client in a long time to know if this is supported on the client side, but I'm guessing it is.
    Either way, using a proprietary protocol, there's no way for the proxy machine to be able to filter the traffic on any given ports.

  • TS4000 I have a dialog box in Mac OS calendar that says "moving calendars to server account. It has totally locked up the Calendar app. I have forced quit, restarted the Mac as well as Calendar but I can't use Calendar at all. How can I restore Calendar?

    I have a dialog box in Mac OS calendar that says "moving calendars to server account. It has totally locked up the Calendar app. I have forced quit, restarted the Mac as well as Calendar but I can't use Calendar at all. How can I restore Calendar?

    No one have any idea as to what's going on with my issue?
    A lot of people do, if you take a look at the More Like This widget on the right side of this page.
    Try signing out and back in to iCloud in System Preferences.

  • Server 2012 R2 Essentials Role: How to change the port numbers?

    Hi All,
    I've installed Server 2012 R2 on a Hyper-V guest, and then installed the Essentials Role on it. I've setup the role, and can access the dashboard. However the client I have has only one static IP - and Exchange/IIS running on the Hyper-V host. So the normal
    ports for Access Anywhere won't work. I'd like to have the Access Anywhere respond on a different port - say 9999 for example. Then I can configure port forwarding on the router to pass it through, and have it working correctly as an SBS replacement. I messed
    around with the bindings in IIS, but that didn't really solve the problem. I thought that would be it - but I suppose it's possible the service isn't meant to run on another port?
    Has anyone had any luck in changing Access Anywhere to respond on a different port?
    Thanks!

    Hi,
    Based on your description, I understand that you want to change the default port of Anywhere Access. Please
    refer to following thread and check if can help you.
    WSE
    2012. Cant use port 443 for Anywhere Access
    If anything I misunderstand or any update, please don’t hesitate to let me know.
    Hope this helps.
    Best regards,
    Justin Gu

  • Server Admin refuses to connect, servermgrd runs but no ports are open

    Server Admin refuses to connect to server when run locally or remotely. Upon investigating, servermgrd seems to run but when I run network utilities and port scan the server, neither port 311 or 687 are open. All other services appear to be running fine. No firewall is running. Server Monitor also has the same problems but WorkGroup Manager seems to work fine.
    About 3 weeks ago, I had the problem and after trying many things, I did a clean install but the problem has reappeared after a few days/weeks.
    At some point, servermgrd was crashing with a message about NSURL.... (lost and forgot the exact message).
    -Tried to remove all the files in /private/var/servermgrd/
    This solved the crashes but it now runs without opening the ports. After starting, it doesn't run away and consume any CPU.
    Could not locate in system.log, console.log and servermgr.log any error messages indicatind something is wrong with servermgrd.
    The log does show that server names are coherent.
    Apr 18 23:06:31 server-1 servermgrd: servermgr_dns: hostname and DNS entries for this server are synchronized
    - Tried rebooting.
    - Tried running servermgrd with various flags, including alternate port but nothing happen. In fact the alternate ports do noot seem to get open. Even passing faulty options, it runs without complaining !
    - Tried to reinstall the admin tools
    - Tried to remove keychain paswords entries
    - Tried Disk Utilities repair permissions.
    Searching the posts, found somebody talkingabout servermgr_ctl
    I'm starting to suspect some hardware failure (RAM).
    Any suggestion how to test the ram.
    Running out of idea.
    Desperate for solution.
    Background
    OS X Server 10.4.9
    Server Admin version Version 10.4.7 (157.8)
    Xserve Dual G4 with 2 GB ram.   Mac OS X (10.4.9)  

    Ok, I ran memtest 4.2 and discovered the ram was failing, In replacing the dimm, they started working again so it may have been a mis-seated dimm module or some oxidation on the contact. My file system was already corrupt despite it being a fresh install. Then I checked and notice that the file com.apple.servermgrd.plist in Library preferences was gone. Either I stuppidly deleted it trying to fix the problem or it was hosed by the memory/file system corruption. Anyway, I copied it from another server and Both Server Admin and Server Monitor are now working.
    SOLVED.
    PS: in view of this event, once I'm satisfied the memory issues is solved, I'll do again a clean install. Who know what else was corrupted.

  • Cisco UCS C220-M3 Server doesn't boot after adding Intel I350 Quad Port NIC

    Hello,
    We have purchased 2 Cisco UCS C220-M3 rack mounted servers (Single Processor) that have a dual port I350 LOM. We also purchased two Intel I350 Quad Port NICs to expand the available ports on each server from 2 to 6.
    The problem we are facing is that the server will not complete the boot process unless we disable either the LOM or the Quad Port NIC. We have tried numerous settings in the BIOS area but we haven't managed to have them both working.
    The I350 Quad Port NICs are from Intel and not from Cisco and we are running the latest FW/BIOS on the Servers as of March 10 2015.
    We have followed the steps described in the installation guide to install them.
    Could you provide some light in this situation please, what are our options?
    P.S. Although the LOMs are I350, the MAC Address Vendor is Cisco, is it possible that Cisco servers accept only Cisco Branded Expansion Cards?
    Thank you,
    George

    Hi Shawn,
    At least I'm not the only one having the same problem!
    You are trying to use the cards with the LOMs enabled?
    Which screen are you referring to in the first paragraph of your message?
    Mine sits in BIOS POST for about 10 minutes and then resets itself....
    We are also waiting for an answer from Cisco, so any findings/news will be posted here.
    Thanks,
    George

  • Server 2012 CDP PKI Setup on Subordinate CA - Active Directory Certificate Services could not create an encryption certificate

    Hi,
    When I check pkiview.msc on my 2012 Subordinate CA I get the error shown in the first picture below. I'm also getting errors similar to below in the event log:
    "Active Directory Certificate Services could not create an encryption certificate.  Requested by contoso\admin1.  The revocation function was unable to check revocation because the revocation server was offline. 0x80092013 (-2146885613 CRYPT_E_REVOCATION_OFFLINE)."
    I'm assisting in setting up a 2 tier PKI infrastructure using Windows 2012. The root CA looks good, but we're getting errors on the subordinate. The server was working, but we discovered that the server would only issue certificates with a maximum of a 1
    year expiry date - obviously no good, so we decided to run through the following commands on the root CA (as recommended byhttp://www.techieshelp.com/subordinate-ca-increase-certificate-validity/)
    certutil -setreg ca\ValidityPeriodunits "Years"
    certutil -setreg ca\ValidityPeriod "5"
    restarted AD certificate services on the root and subordinate CA.Then did the following on the subordinate CA:
    1.On the Subordinate CA create a new CA request by right clicking the server in ADCS and select New Request.
    2.Supplied the original request file from the subordinate CA (I couldn't find a way of generating a new request file)
    3.Issued the certificate using the Root CA.
    4.On the Subordinate CA ADCS installed new CA cert.
    However, I keep on getting CDP or AIA errors on my subordinate CA.Also I'm missing a CDP field value when I look at the certificate listed in the personal and trusted certification authority store on my subordinate CA.
    In addition, when I look at my CDP locations in Certificate Authority, I see a lot of CDPs, but I'm not sure if I need them all - I suspect I could just get away with LDAP, the C:\windows path and a single http:// path.
    I've tried renewing the existing certificate and CRL on my subordinate CA, but that didn't work either.
    Please advise.
    Thanks

    Ok, the process to renew the subordinate CA is incorrect. Once the registry setting to change the validity period was made on the root CA, the root CA ADCS service needs to be restarted. That is the only time those keys are read. Then:
    1) On the subordinate CA, open the CA tool, right click the CA and select Renew CA Certificate. You can use the same key, no need to create a new one. It will create a NEW certificate request file
    2) Copy that to the Root CA and submit like you would have done during the initial install
    3) Approve the request and export the issued certificate
    4) On the subordinate CA, in the CA tool, right click the CA and choose Install CA Certificate.
    You can not reuse request files.
    Mark B. Cooper, President and Founder of PKI Solutions Inc., former Microsoft Senior Engineer and subject matter expert for Microsoft Active Directory Certificate Services (ADCS). Known as “The PKI Guy” at Microsoft for 10 years.

  • Is it possible to bypass Domain Controller Promotion (dcpromo) Hard Drive Check? My Server has an embedded drive instead of a SATA port. (emmc)

    I have a small computer with just an embedded drive instead of a sata port. It seemed perfect for a small domain controller, since it has 32G's which is more than enough space, and with a gigabit Ethernet, and 1.6Ghz dual core cpu, seemed more than enough
    for what I needed.
    Windows 2012, or Windows Server Technical Preview, both install fine on it, but when I run dcpromo to create the domain It fails on selecting the location for files. The error is that the path is not a hard drive. The machine only has USB ports so I can't
    add a SATA drive just to store these logs/configs, even if I wanted to.  
    The actual computer I was trying to use: http://www.ecs.com.tw/LIVA/
    Thanks for any help.

    On the Windows Server Technical Preview, 
    Install-ADDSForest -SkipPreChecks -DomainName DOMAIN.CONTOSO.COM -DomainMode Win2008 -ForestMode Win2008R2 –DatabasePath "C:\Windows\NTDS" –SYSVOLPath "C:\Windows\NTDS" –LogPath "C:\Windows\NTDS\Logs"
    gives me the error "No NTFS 5 drives exit." (note exit, not exist)
    I'll reinstalling windows 2012 and see if I get a different message there.
    This was just a standard install, so the drive is definitely NTFS.

  • The update server is not responding or internet or firewall setting are incorrect

    can anyone help me with this issue? i am trying to update elements 11, i have a new Nikon D7100 and can't download NEF (raw) files on to elements.

    What operating system are you using?
    On a windows system, this is often the cause:
    http://helpx.adobe.com/creative-suite/kb/error-update-server-repsonding-cs4.html

  • Can't reach global catalog server.....that I am actively pinging....

    Hello.
    Background
    I have a Window server 2008 r2 installation that I fell in on. I removed all roles and features. Renamed, and gave a new ip address
    I ran DCpromo and installed AD and DNS. this server was to be the first in a new domain.
    After successfully creating the domain, I added my workstation (laptop) to the domain successfully and logged on with a created domain administrator account.
    I installed the remote administrator pack for windows 7 onto my workstation 
    Problem
    I ran AD Users and Computers (from my workstation) and proceeded to create a user... only to be told:
    "Windows cannot verify that the user name is unique because the following error occurred while contacting the global catalog: The server is not operational."
    Troubleshooting steps taken so far:
    I have ensured that my workstation and server times match (to the second)
    I have ensure they are in the same time zone, date, etc.
    I am actively pinging the domain controller from my workstation WHILE I attempt to create the user, so network connectivity is ruled out. they are in the same subdomain, there is no router in between. it is workstation > switch > switch > switch
    > server
    I checked sites and services, to find only 1 server listed for the sole domain, and it IS checked as the global catalog server
    My workstation when added to the domain registered in DNS appropriately. As is the domain controller itself.
    DCDIAG /fix reports no errors, everything passes
    metadata.cleanup cannot be used because there are not other domains or sites, or servers listed beside the one I created.
    Please help....Thank you.

    Please use dcdiag /v and repadmin /showreps
    to check the DCs health status and AD replication.
    Please also refer to the recommendations mentioned here: http://social.technet.microsoft.com/wiki/contents/articles/18513.active-directory-replication-issues-basic-troubleshooting-steps-single-ad-domain-in-a-single-ad-forest.aspx
    This posting is provided "AS IS" with no warranties or guarantees , and confers no rights.
    Get Active Directory User Last Logon
    Create an Active Directory test domain similar to the production one
    Management of test accounts in an Active Directory production domain - Part I
    Management of test accounts in an Active Directory production domain - Part II
    Management of test accounts in an Active Directory production domain - Part III
    Reset Active Directory user password

  • ATG Server Port # and Client Port #?

    Can you confirm that the server port # for ATG is 9010 and is there a Client Port #?
    TY!
    RC

    I have been tasked with finding the following information ahead of a server cutover due to company merger:
    Application Name |     Server Name | IP Address     | Server Port # | Client Port #
    ATG

  • Server aol imap cannot be contacted on the default ports...emails not sending

    my emails are not sending it says
    cannot send message using the server aol
    the server AOL IMAP cannot be contacted on the default ports

    Hello Sophie,
    Thank you for all the information you provided about what is going on with your email on your MacBook Pro.  I recommend following the steps in the article below to continue isolating and troubleshooting the issue you are experiencing with Mail:
    OS X Mail: Troubleshooting sending and receiving email messages
    http://support.apple.com/kb/ts3276
    Thank you for using Apple Support Communities.
    Best,
    Sheila M.

Maybe you are looking for

  • So what is the Option 3: Unlimited FUP limit at th...

    Hi guys, I have been away from the forums for a bit and I have yet to catch up on the latest posts I have seen a post stating that the 'Heavy User' quote has been increased from 100GB to 300GB, is this only for Infinity? Here is a link to the post I

  • Same old...number of rows in a resultset...but a different question

    Hi, I'm writing a code to generate report from the database. Everything is working absolutely fine. Now the problem is that when I try to check whether any row has been returned, I'm not able to do it correctly. What is happening is that the column h

  • Trading Partner Config

    Hello everyone, I am looking for Trading Partner configuration Steps for intercompany clearing. I will appriciate if some one can share the important steps. Thanks in Advance Krishna

  • Sharepoint2013 - Organizational browser not showing anything

    Hi there. Sharepoint 2013 installed. Tried the Organizational Browser web part, but it does not shows anything neither in Silverlight view or in HTML view. What exactly should this "feature" show? It's the same in IE on WIN8 and WIN7 client (both wit

  • Missing letters in foreign font

    I am making credits and lower thirds in Turkish, using the papyrus font. Most of it worked, but I'm missing a few letters. ( ş and ğ) When I type them, my title defaults to American Typewriter font. If this is an issue with Papyrus, how do I tell if