RAC interconnect using UDP - default ports?

Is there a default port used by each cluster member to listen for connections over UDP? We use IPTABLES firewalls on our hosts, and I need to ensure the cluster heartbeat traffic gets through the firewall properly.
Thanks in advance.
Jeff

user2528460 wrote:
I understood the UPD ports that are going to be used on the interconnect (clearly without a firewall). Is there a set of default ports?I did a quick count (using <i>lsof</i> to list UDP ports opened on the Interconnect interface) that showed over 185 UDP ports in use.. E.g.
[root ~]# lsof -n -i | grep UDP | grep "10.0.1.1"
oracle     5577  oracle   10u  IPv4   130938       UDP 10.0.1.1:22747
oracle     5577  oracle   15u  IPv4   130941       UDP 10.0.1.1:64265
oracle     5579  oracle   10u  IPv4   130948       UDP 10.0.1.1:39566
oracle     5579  oracle   15u  IPv4   130951       UDP 10.0.1.1:55454
oracle     5579  oracle   21u  IPv4   130970       UDP 10.0.1.1:27897
oracle     5581  oracle   10u  IPv4   130973       UDP 10.0.1.1:14118
oracle     5581  oracle   15u  IPv4   130976       UDP 10.0.1.1:13774
oracle     5583  oracle   10u  IPv4   130983       UDP 10.0.1.1:33277
oracle     5583  oracle   15u  IPv4   130986       UDP 10.0.1.1:6886
..snipped..I would not be concerned about what ports are in use. The important decisions are do you use bonding for the Interconnect, do you use jumbo or super-jumbo frames (MTU sizes), and so on. The actual ports being used has no real bearing as firewalling is not applicable.

Similar Messages

  • How to use non default port 1521 while 11.2.0.1 grid upgrade to 11.2.0.2

    Hi Team ,
    We are planning 11.2.0.1 Grid infra rolling upgrade to 11.2.0.2 with out any downtime.
    But while up gradation due to default scan port 1521 , 11.2.0.1 databases are not able to connect (remote connections)
    We are using 1900 port for existing 11.2.0.1 grid infra scan.
    While up gradation it is taking default port of 1521 insted of existing port 1900.
    Please provide the solution to use non default port while 11.2.0.2 up gradation.
    After upgrade the status as below.
    grdoratst104:/apps/grid/grdhome:+ASM4> srvctl config scan_listener
    SCAN Listener LISTENER_SCAN1 exists. Port: TCP:1521
    SCAN Listener LISTENER_SCAN2 exists. Port: TCP:1521
    SCAN Listener LISTENER_SCAN3 exists. Port: TCP:1521
    Here I was getting TNS:no Listener errors from the client connections.
    I have modifyed the scan port then it is working fine.
    grdoratst104:/apps/grid/grdhome:+ASM4> srvctl modify scan_listener -p TCP:1800
    grdoratst104:/apps/grid/grdhome:+ASM4> srvctl config scan_listener
    SCAN Listener LISTENER_SCAN1 exists. Port: TCP:1800
    SCAN Listener LISTENER_SCAN2 exists. Port: TCP:1800
    SCAN Listener LISTENER_SCAN3 exists. Port: TCP:1800
    grdoratst104:/apps/grid/grdhome:+ASM4>
    Here the problem is we need to do the grid infra upgrade with out downtime,but due this default port issue clients are not able to connect to the database.
    Thanks
    Bala
    Edited by: user12032334 on May 31, 2011 11:46 AM

    Why are you using a non default port? It does not improve security. It makes network management more complex. And causes the type of issues that you are facing now.
    So before changing defaults, make sure that your reasons are technically sound. And using port 1900 when 1521 is available, is not technically sound by any means.
    As for addressing the problem you have created for yourself by mucking around with port numbers. Use a NAT firewall (on each RAC node) to rewrite packets headers received on port 1900 and send these to the server's port 1521 instead (on the VIP or static IP as required).
    This can be fairly easily done using iptables if your o/s is Linux. You need to:
    a) create a pre-routing NAT rule
    b) create a post-routing NAT rule
    c) create a forwarding filter rule for port 1900/tcp
    d) create an input filter rule to accept traffic on 1900/tcp

  • How to establish user equvalance between 2 rac nodes on non default ports??

    Hi Friends,
    Please shed some light on how to establish user equvalance between 2 rac nodes on non default ports such as ssh on 22...
    i want to establish user equvalance on other ports..
    Thanks
    RB

    R12DBA wrote:
    Hi Friends,
    Please shed some light on how to establish user equvalance between 2 rac nodes on non default ports such as ssh on 22...
    i want to establish user equvalance on other ports..
    Thanks
    RBHi RB ,
    22 is default port for ssh. For configuring
    http://yasarmoran.wordpress.com/2010/06/12/configuring-ssh-on-oracle-rac-nodes/
    For non default port , first of all you need to configure ssh on new port . For that refer :
    http://www.itworld.com/nls_unixssh0500506

  • IdM doesn't support non-default port on mysql 4.1 as repository??

    Hi
    IdM doesn't support non-default port on mysql 4.1 as repository??
    IdM version is 6.0.
    I setup mysql 4.1 using non-default port 3307.
    (default port is 3306)
    During setup wizard,
    the URL [jdbc:mysql://localhost:3307/waveset] doesn't work.
    I am getting following error.
    com.waveset.util.InternalError:
         ==> com.waveset.util.ConfigurationError:
         ==> com.mysql.jdbc.CommunicationsException: Communications link failure due to underlying exception:
    Of cource,
    the URL [jdbc:mysql://localhost/waveset] works well
    when I setup mysql using default port.

    Hi,
    it does work with non standard ports but whatever port you specify it will always try to connect to the default port before actually changing the repo setting.
    Therefore use the switches -n -o $WSHOME/WEB-INF/ServerRepository.xml to write the new configuration without performing the broken checks.
    Regards,
    Patrick

  • SSRS 2012 MP (Native) - Bug with non-default port on SSRS DB, Does not discover

    We have test changing SSRS DB instance to default port 1433 and discovery is immediate in SSRS MP. When using non-default port, discovery fails, SSRS instance role is never identified.
    Our SSRS is separated into app and db tires across two servers. Have tried creating sql network aliases, but this does not work either.
    In our environment, we use non-default port for our SQL DB instances. how do we get SSRS to discover.
    Thanks in advance,
    Rois Cordova

    The Monitoring Pack for Microsoft SQL Server 2012 Reporting Services automatically discovers instances of SSRS 2012 by reading registry.
    When the Monitoring Pack for Microsoft SQL Server 2012 Reporting Services is imported for the first time, it creates three new Run As profiles:
    • Microsoft SQL Server 2012 Reporting Services Discovery Run As Profile
    • Microsoft SQL Server 2012 Reporting Services Monitoring Run As Profile
    • Microsoft SQL Server 2012 Reporting Services SCOM SDK Discovery Run As Profile
    By default, all discoveries, monitors and rules defined in the SQL Server 2012 Reporting Services management pack use accounts defined in the “Default Action Account”
    Run As profile. If the default action account for a given system does not have the necessary permissions to discover or monitor the instance of SQL Server 2012 Reporting Services, then those systems can be bound to more specific credentials in the
    “Microsoft SQL Server 2012 Reporting Services …” Run As profiles, which do have access.
    It s recommend that you should check the default action account permission.
    Roger

  • CHANGING DEFAULT PORT

    I purchase the app Splashtop Remote Desktop . It says to use  2 default port #'s to get sound on my IPad. How do I go about doing this. I have Windows XP.

    I don't believe that it's possible.  Do you have a mechanism to contact the app publisher?
    Also, please do not use the super-sized bolded font.  It's extremely annoying.

  • DISPATCHER  : avoid change of  a default PORT 1521

    I have configured DB 10.1.0.3 with SHARED SERVER .
    If I connnected to the database (SERVER=SHARED), dispatcher would use
    non-default PORT as
    "D001" established:5 refused:0 current:4 max:972 state:ready
    DISPATCHER <machine: ............., pid: 19839>
    (ADDRESS=(PROTOCOL=tcp)(HOST=..............)(PORT=35972))
    I use my database behind the firewall in DMZ , so I want to use a default PORT 1521 with my dispatcher D0001.
    There was an option "PORT" in a initialization parameter DISPATCHERS in previous DB versions. I cannot use this option in the database release 10.1.0.3.
    Help me?

    I'm afraid you can't do that, at least with that version.
    See http://download-uk.oracle.com/docs/cd/A97329_03/core.902/a92171/concepts.htm#1016370
    Here an extract :
    The metadata repository is always configured to use port 1521 and has a service name of the form iasdb.host.domain (for the first infrastructure on a host) and iasdbx.host.domain for any subsequent infrastructures on that host). You should never change these values.

  • Risk & Security vulnerability for using default ports

    Dear All,
    As far as I know, Oracle does not recommend to use default ports for
    security purposes. Searching out of Oracle community found that some people
    think that it does not matter any more. However, it can have some vulnerability
    and, I think, security risk & auditors would not like to see that.
    I have found that in 2012 ORacle Tns listener port 1521 had a vulnerability
    issue with oracle database 11gR1 and 11gR2, but how about Oracle 12?.
    Also, I was searching something similiar for Oracle OAM, SOA, OIM, OAAM, but still cannot
    find anything.
    Thanks
    Georgina Acuna-Rivera

    Do you happen to have such a storage peripheral attached to your M3000?
    If yes, then it is probably reachable through the M3000's IP address. You will need to log a support ticket with HP and get guidance how to get into the array's FCAL controller and investigate the issue.
    If you do not have an HP array attached to your M3000, then log a support case with Oracle and arrange for a field service engineer to visit the site to manipulate the password for its `admin` account (since that special account is likely needs service-employee-only access).
    Either way, you need to get accurate technical support and this forum is NOT official tech-support.

  • Can javamail use windows default outgoing smtp mail server and port?

    how can i use windows default outgoing smtp service and port from javamail? is it possible to retrieve this info or just instruct javamail to use default?
    thanks

    Windows doesn't have a default SMTP server. However if you have something like Outlook or Outlook Express or Eudora or Netscape Mail or whatever set up on your Windows box, you will have already told it what SMTP server it should connect to.
    That information would be in the Windows registry, or in the config file of whatever e-mail client you already have set up. However it's probably easier to just have your application ask for the SMTP server's name again rather than trying to find where some other application stashed it.

  • Change default port used for FlexUnit reports

    Good day,
    I have recently set up a CruiseControl server that runs two concurrent builds. Most of these builds contain FlexUnit tests. I am well aware that the default port for FlexUnit task is 1024 and I know that only one listener can access the port at one time. I tried passing a different port number but the flexunit task hangs. So, I was wondering if anyone has tried changing the default port to something other than 1024.

    Hi Michael,
    I created a bug for tracking, as you requested (https://bugs.adobe.com/jira/browse/FXU-153).

  • How to use the default database service name on creating procedure for data

    how to use the default database service name on creating procedure for datagaurd client failover ??? all oracle doc says create a new service as below and enable at DB startup. but our client is using/wanted database default service to connect from application on the datagaurd environment (rac to non rac setup).please help.
    Db name is = prod.
    exec DBMS_SERVICE.CREATE_SERVICE (service_name => 'prod',network_name =>'prod',failover_method => 'BASIC',failover_type => 'SELECT',failover_retries => 180,failover_delay => 1);
    says already the service available.
    CREATE OR REPLACE TRIGGER manage_dgservice after startup on database DECLARE role
    VARCHAR(30);BEGIN SELECT DATABASE_ROLE INTO role FROM V$DATABASE;
    IF role = 'NO' THEN DBMS_SERVICE.START_SERVICE('prod');
    END IF;
    END;
    says trigger created, but during a swithover still the service is listeneing on listener.
    tns entry.
    prod =
    (DESCRIPTION =
    (ADDRESS_LIST =
    (LOAD_BALANCE = YES)
    (ADDRESS = (PROTOCOL = TCP)(HOST = prod1)(PORT = 1521))
    (ADDRESS = (PROTOCOL = TCP)(HOST = prod2)(PORT = 1521)) ---> primary db entry
    (ADDRESS_LIST =
    (ADDRESS = (PROTOCOL = TCP)(HOST = proddr)(PORT = 1521)) --> DR DB entry
    (CONNECT_DATA =
    (SERVICE_NAME = prod)
    thanks in advance.
    Edited by: 854393 on Dec 29, 2012 11:52 AM

    Hello;
    So in the example below replace "ernie" with the alias you want the client to use.
    I can show you how I do it :
    First an entry need to be added to the client tnsnames.ora that uses a SERVICE_NAME instead of a SID.
    ernie =
    (DESCRIPTION =
        (ADDRESS_LIST =
           (ADDRESS = (PROTOCOL = TCP)(HOST = Primary.host)(PORT = 1521))
           (ADDRESS = (PROTOCOL = TCP)(HOST = Standby.host)(PORT = 1521))
           (CONNECT_DATA =
           (SERVICE_NAME = ernie)
    )Next the service 'ernie' needs to be created manually on the primary database.
    BEGIN
       DBMS_SERVICE.CREATE_SERVICE('ernie','ernie');
    END;
    /After creating the service needs to be manually started.
    BEGIN
       DBMS_SERVICE.START_SERVICE('ernie');
    END;
    /Several of the default parameters can now be set for 'ernie'.
    BEGIN
       DBMS_SERVICE.MODIFY_SERVICE
       ('ernie',
       FAILOVER_METHOD => 'BASIC',
       FAILOVER_TYPE => 'SELECT',
       FAILOVER_RETRIES => 200,
       FAILOVER_DELAY => 1);
    END;
    /Finally a database STARTUP trigger should be created to ensures that this service is only offered if the database is primary.
    CREATE TRIGGER CHECK_ERNIE_START AFTER STARTUP ON DATABASE
    DECLARE
    V_ROLE VARCHAR(30);
    BEGIN
    SELECT DATABASE_ROLE INTO V_ROLE FROM V$DATABASE;
    IF V_ROLE = 'PRIMARY' THEN
    DBMS_SERVICE.START_SERVICE('ernie');
    ELSE
    DBMS_SERVICE.STOP_SERVICE('ernie');
    END IF;
    END;
    /lsnrctl status - should show the new service.
    When I do this the Database will still register with the listener. I don't give that to the clients. That one will still be available but nobody knows about it. Meanwhile "ernie" moves with the database role.
    So in my example the default just hangs out in the background.
    Best Regards
    mseberg
    Edited by: mseberg on Dec 29, 2012 3:51 PM

  • LACP using 2x 10G ports not showing 20G?

    I currently have etherchannel configured to 2x 10g ports.
    Cat_6509#sh run int ten8/1
    Building configuration...
    Current configuration : 156 bytes
    interface TenGigabitEthernet8/1
     switchport
     switchport mode trunk
     channel-group 42 mode desirable
    end
    Cat_6509#sh run int ten9/1
    Building configuration...
    Current configuration : 156 bytes
    interface TenGigabitEthernet9/1
     switchport
     switchport mode trunk
     channel-group 42 mode desirable
    end
    Cat_6509#
    Cat_6509#sh int t8/1
    TenGigabitEthernet8/1 is up, line protocol is up (connected)
      Hardware is C6k 10000Mb 802.3, address is fc99.4736.a2f0 (bia fc99.4736.a2f0)
      Description: 10 Gig GEC to MADDC (Spanned VLANS)
      MTU 1500 bytes, BW 10000000 Kbit, DLY 10 usec, 
         reliability 255/255, txload 5/255, rxload 1/255
      Encapsulation ARPA, loopback not set
      Keepalive set (10 sec)
      Full-duplex, 10Gb/s
    Cat_6509#sh int t9/1
    TenGigabitEthernet9/1 is up, line protocol is up (connected)
      Hardware is C6k 10000Mb 802.3, address is fc99.4736.a238 (bia fc99.4736.a238)
      Description: 10 Gig GEC to MADDC (Spanned VLANS)
      MTU 1500 bytes, BW 10000000 Kbit, DLY 10 usec, 
         reliability 255/255, txload 8/255, rxload 1/255
      Encapsulation ARPA, loopback not set
      Keepalive set (10 sec)
      Full-duplex, 10Gb/s
    Cat_6509#sh int po42
    Port-channel42 is up, line protocol is up (connected)
      Hardware is EtherChannel, address is fc99.4736.a2f0 (bia fc99.4736.a2f0)
      Description: 10 Gig GEC to MADDC (Spanned VLANS)
      MTU 1500 bytes, BW 20000000 Kbit, DLY 10 usec, 
         reliability 255/255, txload 7/255, rxload 1/255
      Encapsulation ARPA, loopback not set
      Keepalive set (10 sec)
      Full-duplex, 10Gb/s               <<<<<<<<<<<<<<<<<<<<<<< Should this be 20GB if the ports are bundled?
    Cat_6509#show etherchannel 42 summary 
    Flags:  D - down        P - bundled in port-channel
            I - stand-alone s - suspended
            H - Hot-standby (LACP only)
            R - Layer3      S - Layer2
            U - in use      N - not in use, no aggregation
            f - failed to allocate aggregator
            M - not in use, no aggregation due to minimum links not met
            m - not in use, port not aggregated due to minimum links not met
            u - unsuitable for bundling
            d - default port
            w - waiting to be aggregated
    Number of channel-groups in use: 28
    Number of aggregators:           28
    Group  Port-channel  Protocol    Ports
    ------+-------------+-----------+-----------------------------------------------
    42     Po42(SU)        PAgP      Te8/1(P)       Te9/1(P)       
    Last applied Hash Distribution Algorithm: Fixed
    Cat_6509#
    Thanks
    ST

    Hi WannaB
    Oops you are right the configuration is in PagP. However I have another port channel from the 7706 to Fabric Interconnect which is configured as LACP that is still operating on 10G.
    ethernet# show int po30
    port-channel30 is up
    admin state is up
      Hardware: Port-Channel, address: 8480.2da5.c36c (bia 8480.2da5.c36c)
      Description: UCS Fabric Interconnect A
      MTU 1500 bytes, BW 10000000 Kbit, DLY 10 usec
      reliability 255/255, txload 1/255, rxload 1/255
      Encapsulation ARPA, medium is broadcast
      Port mode is trunk
      full-duplex, 10 Gb/s
    ethernet# show port-channel summary 
    Flags:  D - Down        P - Up in port-channel (members)
            I - Individual  H - Hot-standby (LACP only)
            s - Suspended   r - Module-removed
            S - Switched    R - Routed
            U - Up (port-channel)
            M - Not in use. Min-links not met
    Group Port-       Type     Protocol  Member Ports
          Channel
    1     Po1(SD)     Eth      NONE      --
    2     Po2(SD)     Eth      NONE      --
    3     Po3(SU)     Eth      LACP      Eth1/2(P)    Eth2/2(P)    
    30    Po30(SU)    Eth      LACP      Eth1/5(P)    Eth2/5(D)
    ethernet# sh run int eth1/5
    !Command: show running-config interface Ethernet1/5
    !Time: Thu Dec 11 02:43:46 2014
    version 6.2(8a)
    interface Ethernet1/5
      description UCS Fabric Interconnect A
      switchport
      switchport mode trunk
      channel-group 30 mode active
      no shutdown
    ethernet# sh run int eth2/5
    !Command: show running-config interface Ethernet2/5
    !Time: Thu Dec 11 02:43:48 2014
    version 6.2(8a)
    interface Ethernet2/5
      description UCS Fabric Interconnect A
      switchport
      switchport mode trunk
      channel-group 30 mode active
      no shutdown
    ethernet#

  • RAC Interconnect Transfer rate vs NIC's Bandwidth

    Hi Guru,
    I need some clarification for RAC interconnect terminology between "private interconnect transfer rate" and "NIC bandwidth".
    We have 11gR2 RAC with multiple databases.
    So we need to find out what the current resource status is.
    We have two physical NICs each node. And 8G is for public and 2G is for private (interconnect).
    Technically, we have 4G for Private network bandwidth.
    If I look at the "Private Interconnect Transfer rate" though OEM or IPTraf (linux tool), it is showing 20 ~30 MB/Sec.
    There is no any issue at all at this moment.
    Please correct me if I am wrong.
    The transfer rate will be fine till 500M or 1G/Sec. Because the current NIC's capacity is 4G. Does it make sense ?
    I'm sure there are multiple things to consider,but I'm kind of stumped on the whole transfer rate vs bandwidth. Is there any way to calculate what a typical transfer would be....
    OR How do I say our interconnect are good enough ....based on the transfer rate ?
    Another question is ....
    In our case, how do I set up the warning threshold and Critical threshold for "Private Interconnect Transer rate" in OEM ?
    Any comments will be appreciated.
    Please advise.

    Interconnect performance sways more to latency than bandwidth IMO. In simplistic terms, memory is shared across the Interconnect. What is important for accessing memory? The size of the pipe? Or the speed of the pipe?
    A very fast small pipe will typically perform significantly better than a large and slower pipe.
    Even the size of the pipe is not that straight forward. Standard IP MTU size is 1500. You can run jumbo and super-jumbo frame MTU sizes on the Interconnect - where for example a MTU size of 65K is significantly larger than a 1500 byte MTU. Which means significantly more data can be transferred over the Interconnect at a much reduced overhead.
    Personally, I would not consider Ethernet (GigE included) for the Interconnect. Infiniband is faster, more scalable, and offers an actual growth path to 128Gb/s and higher.
    Oracle also uses Infiniband (QDR/40Gb) for their Exadata Database Machine product's Interconnect. Infiniband also enables one to run Oracle Interconnect over RDS instead of UDP. I've seen Oracle reports to the OFED committee saying that using RDS in comparison with UDP, reduced CPU utilisation by 50% and decreased latency by 50%.
    I also do not see the logic of having a faster public network and a slower Interconnect.
    IMO there are 2 very fundamental components in RAC that determines what is the speed and performance achievable with that RAC - the speed, performance and scalability of the I/O fabric layer and for the Interconnect layer.
    And Exadata btw uses Infiniband for both these critical layers. Not fibre. Not GigE.

  • Default ports groups for iptv and iptv control server

    is there a default group for iptv and default ports for different types of communication

    I was able to take a look at the system here at work:
    Under "Preferences" in the Content Manager, the first category of configurable parameters are for Multicast Addresses.
    If you keep the default (Global)it uses 224.2.X.Y, and allows you to set the TTL's to set the multicast diameter.
    The Administratively Scoped multicast addresses are 239.255.0.0 - 239.255.255.255. You can also set a TTL.
    Global SSM addresses are 232.0.0.0-232.255.255.255
    Admin Scoped SSM addresses are 239.232.0.0-239.232.255.255
    Near the end of that section, you can choose which address range will be the default, and I believe "Global" (224.2.X.Y) is the "default" default.
    The only ports listed are for Multicast Announcement (9874) and RTSP (8554) both are UDP.
    Good Luck
    Scott

  • How to change the default port of webdispatcher

    Hello Everyone,
    We wish to  know to how to change the default port of SAP webpatcher port from 81$$ to 80.
    Appreciate your response.
    Thanks,
    Vadi

    Hello Vadi
    you have to change the PORT value in your profile parameter from 81$$ to 80
    icm/server_port_0 = PROT=HTTP,PORT=81$$ to
    icm/server_port_0 = PROT=HTTP,PORT=80
    Also, in SMICM, then change http service port and activate it and above parameter will require SAP restart
    $$ is used generally to accomodate multiple port services running in SMICM and so as to avoid the parameter setting according to instance number of any system.
    thanks
    Bhudev

Maybe you are looking for

  • Sync iphone to ipad

    How do I sync my mac book and ipad to the information in my phone?  My mac book is 7yrs old and my ipad is the first generation 2010

  • Association Wizard; DB Constraints, Composition, & Cascades

    A couple of clarifications please: 1. When would I want (ie 'be better off) with a composite association (fk) that is NOT in the database and only at he bc4j level. 2. If I do want the fk in the database, how can I specify (page 3 of 3 of the wizard)

  • EXECUTE IMMEDIATE stmt

    I am using oracle 10G XE. When I have the following, it works fine.. ======================================== FOR report_c IN report_cur LOOP FOR i in 1 .. 62 loop INSERT INTO trip_stop (sc_v, r_id, b_id, code_id, terminal, seq_num, bs_id, flag, note

  • Hardware Requirements for J2EE application

    Hi, I need to know the best way to estimate the required hardware resources for a J2EE web application. For example if i have 200 users running the system, how much CPUs/RAMs .. etc resources do i need? Thank you

  • Can't download JDev 11.1.2 - corrupted

    Hi OTN, Tried to download JDeveloper 11.1.2 (Windows) from oracle.com twice - from different machines, using Firefox 4 on Windows 7. Both time I got corrupted source file error and download was canceled at about 30%. Internet Explorer 8 stopped at 34