TFTP broken in PI 1.x because of iptables

Hi All
I recently upgraded our PI 1.2.1 to 1.3. It all worked fine but I had no more TFTP working. It didn't really work in the previous version, but now it didn't work at all. I could neither put nor get a file.
So today I checked out some system setting and finally found the reason within iptables.
Please note, this requires root access to the PI 1.3
Here:
ade # tftp -v -c put /localdisk/defaultRepo/cpi1.domain.com_neu.csr cpi1.domain.com_neu.csr
(to) x.x.x.x
Connected to x.x.x.x (x.x.x.x), port 69
putting /localdisk/defaultRepo/cpi1.domain.com_neu.csr to x.x.x.x:cpi1.domain.com_neu.csr [netascii]
Transfer timed out.
So this is the error message when doing it on the root shell. This error always appeared.
Now disabling iptables and doing it again:
ade # /etc/init.d/iptables stop
Flushing firewall rules: [  OK  ]
Setting chains to policy ACCEPT: filter [  OK  ]
Unloading iptables modules: [  OK  ]
ade #
ade #
ade # tftp -v -c put /localdisk/defaultRepo/cpi1.domain.com_neu.csr cpi1.domain.com_neu.csr
(to) x.x.x.x
Connected to x.x.x.x (x.x.x.x), port 69
putting /localdisk/defaultRepo/cpi1.domain.com_neu.csr to x.x.x.x:cpi1.domain.com_neu.csr [netascii]
Sent 1062 bytes in 0.0 seconds [394426 bit/s]
And bang, it worked on the first try!
And reenabling iptables:
ade # /etc/init.d/iptables start                                                   
Applying iptables firewall rules: [  OK  ]
Anybody else also having those problems?
I'm sadly an absolute iptables beginner and don't really know how to troubleshoot this more (even though I expect it to be working from start).
Thanks,
Patrick

Also doesn't help.
But I found now a working solution. It indeed seems to be a wrong configured iptables. The issue is with the dynamic high-ports of TFTP which aren't allowed by default on iptables.
Here I found the hint that works: http://nartax.com/2012/04/iptables-rule-for-tftp/
So I logged in as root, edited the config file
vi /etc/sysconfig/iptables-config
And changed
IPTABLES_MODULES=""
to
IPTABLES_MODULES="ip_conntrack_tftp"      
After saving it with :wq I restarted iptables and also restarted ncs (this is needed as some iptables rules are loaded when ncs starts and are lost when iptables is restarted!).
I'm checking if I can open a TAC case for this, so it might get fixed in some future version.
Patrick
[edit]
Can't open a TAC, my permission level is not enought
Message was edited by: Patrick Oberli
Added comment about TAC

Similar Messages

  • My ipod touch power button is broken and it is disabled because I forgot my password

    My ipod touch power button is broken, and it is disabled because I forgot my password....any ideas??

    Use this program to place the iPod in recovery mode and then restore via iTunes.
    RecBoot: Easy Way to Put iPhone into Recovery Mode

  • Broken screen now locked out because of passcode, help unlocking?

    Okay so after a hopeless battle of my phone working and not and then working and so on I finally bought a new iPhone but because I never took my passcode off and because it does resond to touch I can't back up my phone to put all my stuff the new phone, I am beyond frustrated.. Help?

    Locked Out, Forgot Lock or Restrictions Passcode, or Need to Restore Your Device: Several Alternative Solutions
    A
    1. iOS- Forgotten passcode or device disabled after entering wrong passcode
    2. iPhone, iPad, iPod touch: Wrong passcode results in red disabled screen
    3. Restoring iPod touch after forgotten passcode
    4. What to Do If You've Forgotten Your iPhone's Passcode
    5. iOS- Understanding passcodes
    6. iTunes 10 for Mac- Update and restore software on iPod, iPhone, or iPad
    7. iOS - Unable to update or restore
    Forgotten Restrictions Passcode Help
                iPad,iPod,iPod Touch Recovery Mode
    You will need to restore your device as New to remove a Restrictions passcode. Go through the normal process to restore your device, but when you see the options to restore as New or from a backup, be sure to choose New.
    You can restore from a backup if you have one from BEFORE you set the restrictions passcode.
    Also, see iTunes- Restoring iOS software.
    If your iPod Touch, iPhone, or iPad is Broken
    Apple does not fix iDevices. Instead, they exchange yours for a refurbished or new replacement depending upon the age of your device and refurbished inventories. On rare occasions when there are no longer refurbished units for your older model, they may replace it with the next newer model.
    ATTN: Beginning July 2013 Apple Stores are now equipped to do screen repairs/replacements in-house on iPhone 5 and 5C. In some cases while you wait. According to Apple this is the beginning of equipping Apple Stores with the resources needed to do most repairs for iPhones, iPads, and iPod Touches that would not require major replacements. Later in the year the services may be extended as Apple Stores become equipped and staffed with the proper repair expertise. So, if you need a screen repaired or a broken screen replaced or have your stuck Home button fixed, call your local Apple Store to see if they are now doing these in-house.
    You may take your device to an Apple retailer for help or you may call Customer Service and arrange to send your device to Apple:
    Apple Store Customer Service at 1-800-676-2775 or visit online Help for more information.
    To contact product and tech support: Contacting Apple for support and service - this includes international calling numbers.
    You will find respective repair costs in the appropriate link:
    iPod Service Support and Costs
    iPhone Service Support and Costs
    iPad Service Support and Costs
    There are third-party firms that do repairs on iDevices, and there are places where you can order parts to DIY if you feel up to the task:
    1. iResq or Google for others.
    2. Buy and replace screen yourself: iFixit

  • The song "Morning Has Broken" could not be used because the original file could not be found. Would you like to locate it?

    how to bring back my song? i purchased it directly from itunes

    http://support.apple.com/kb/ht2519
    You may need to right click it and delete first.

  • Pacman freezes (because of iptables?).

    It just freezes and nothing happens. Doesn't matter if I do -Sy or just -S it freezes without any output. I can just ^C to kill it though. I recently created a firewall using iptables (the one on wiki) and I'm not sure if I've used pacman since.
    [edit]
    hmm. I got some strange output now. I've usually killed it after a minute or so but now, however, I let it run and there seems to be something wring with my repos. Shouldn't it try the next one on the list?
    Output so far:
    184230/home/riwa/# pacman -Sy cdrdao
    ^[x:: Synchronizing package databases...
    connect: Connection timed out
    error: cannot connect to ftp.ds.hj.se
    failed downloading /current/os/i686/current.db.tar.gz from archlinux.antesis.org : HTTP/1.1 404 Not Found
    connect: No route to host
    error: cannot connect to ftp.rez-gif.supelec.fr
    error: could not cwd to /pub/archlinux/current/os/i686/: 550 Failed to change di rectory.
    current [################] 100% 66K 3.0K/s 00:00:22
    connect: Connection timed out
    error: cannot connect to ftp.ds.hj.se
    failed downloading /extra/os/i686/extra.db.tar.gz from archlinux.antesis.org: HT TP/1.1 404 Not Found
    connect: No route to host
    error: cannot connect to ftp.rez-gif.supelec.fr
    error: could not cwd to /pub/archlinux/extra/os/i686/: 550 Failed to change dire ctory.
    extra [################] 100% 248K 30.1K/s 00:00:08
    unstable [################] 100% 4K 3.4K/s 00:00:01
    [/edit]

    riwa wrote:Nope. No improvement. Still frozen. However, I got the program that I tried (where I said I got ouput). Could it be that my swedish repositories aren't up and running anymore?
    There are two hosts it can't connect to: the swedish and the french one. But the third repo in your serverlists is working - they might be down, having some DNS problems or something yes. I'm not sure if it's iptables because you can connect to the third server it tried (you see the  #'s after the reponame), but you might check if the third repo in the list is HTTP - in that case, the firewall might permit HTTP but disallow FTP (and if it uses "drop" instead of "block" or whatever it was called, it won't get any response from the server or firewall or anything - and freeze while waiting).

  • HT1212 kids locked iphone and cant figure out password and im not able to reset phone... top button broken and itunes wont even connect to phone because its locked..... what do i do???

    How to reset iphone thats locked and top button broken that itunes wont reset because i cant unlock phone??

    you make an appointment at the genius bar of your local Apple Store and pay them to get your phone serviced. Then you can restore the replacement phone from your backup.

  • Broken screen on Nokia express 5800

    I have a 5800 Nokia Express Music phone that I purchased when i was outside the US a few months back. I am using it in the US now. The screen developed a small crack and when I call Nokia customer service, I am told that they will not replace / repair the unit although it is under warranty. what are my options to get the unit replaced /repaired with no charges since the instrument is under warranty?
    Thanks,

    I've had the same problem with my fiance's phone, she only had the phone for 4 days and the screen cracked. Got hold of O2 and they said just send it back and we'll give you a replacement, however now we've found out that that information they gave us is incorrect, and that it is going to have to be assessed by an engineer and then repaired, at a cost they are unwilling to tell me.
    I asked what criteria the 'engineers' would use to ascertain whether the phone is faulty or broken because of our own fault and they could'nt give me a sraight answer beyond the basis of if there has been damage caused by excessive pressure to the screen, which sounds like, if the screen has broken. This is troubling because I obviously wouldnt send it back unless the screen was broken. The phone has absolutley no damage to it, no scratches to the screen casing or likewise, it broken under conditions which can really be classified as 'less that normal use' as we were really very careful with it. The crack simply developed on its own. Having previously owned a Samsung Pixon which had a larger touchscreen pannel and I've given some quite bad drops to it it has survived fine! Why then is there this problem with the 5800?
    If anyone else has had this problem please post on here! the more recognition this gets the better!

  • ASP Command still broken?

    I'm just getting around to trying out CS4, and I noticed right away that the ASP Command implementation is still broken. I'm stunned, because it was first broken in CS3 and remained broken in CS4 beta despite numerous pleas and requests to fix it.
    Please, Adobe, will you ever fix it?

    I'm just getting around to trying out CS4, and I noticed right away that the ASP Command implementation is still broken. I'm stunned, because it was first broken in CS3 and remained broken in CS4 beta despite numerous pleas and requests to fix it.
    Please, Adobe, will you ever fix it?

  • Is there any hope of apple adding a 're-link with media folder'-type function to iTunes?

    Is there any hope of apple adding a 're-link with media folder'-type function to iTunes?
    I have 1000s of broken links after installing the latest version of iTunes and updating some files in my media folder. The location of my itunes library has not changed, and all the files are there (I know because I've just waited several hours for the files to be updated by my ultra-slow computer) - by my logic, there should be some menu option that simply re-synchronises with the media folder, just like itunes would do with an ipod - it can't be that hard can it? The only way I can restore a link is by clicking every song (I have over 28,000) and locating the file in the folder that iTunes claims to use as its media folder - the new version 10 option of then using this location to restore all broken links doesn't work because it only looks in the specific album file, and after a couple of times this dialog box no longer even comes up, so I couldn't ask it to do this even if I wanted to. At the moment the only option I can see is to completely wipe iTunes and re-load all my music from scratch - using my tired and over-worked computer this will realistically take around 15 hours that I don't have, and my computer will melt in the process. I wish I'd never tried to 'tidy up' my iTunes library...
    PLEASE Apple, how hard can it be to have a function that searches for and restores broken links by itself????? I've told you where the music is - just flipping look for it yourself instead of getting me to do it!

    You don't have to re-rip, re-import or re-download all your content. You can clear the iTunes library, either by selecting all in the libary and pressing the Delete key, saying "no" when it asks if you want to remove the files themselves, and then use the Add To Library command, selecting the iTunes Media folder (or iTunes Music folder, as applicable to your situation), and that will add back all your content. It shouldn't take more than a few minutes; if it does, something may be amiss with your hard drive or the library file is corrupted (in which case just delete the library file and re-do the Add To Library command).
    Regards.

  • SSD Upgraded MacBook Pro 2011 freezes, hangs, until SSD is no longer recognized

    Hello.
    Enough with the small talk. I have MacBook Pro 13" Late 2011 with Lion that I upgraded with a 128GB Vertex 4 SSD about 8 months ago. I moved the original HDD into the optical bay and slipped the Vertex 4 into its place. Everything was all good and well until about a month ago when my computer started freezing and hanging (I'm not exactly sure what the difference is or if they're interchangeable words). To be more descriptive, I would have some applications open and it would randomly freeze, leaving me with a rainbow wheel I could control. The computer would then be essentially unresponsive other than the ability to click between apps, but if I did it a couple times everything would become completely unresponsive and I would be left with the spinning pinwheel. At first I thought the computer would right itself, but it stayed like that for 30 minutes one time, with the fan ending up blowing as hard as it could and the temperature of the computer becoming quite warm. The only thing I would be able to do at that point was to hold the power button to force restart the computer. Then the whole process would happen again, once more than 10 times a day. It didn't seem like the hanging was due to intensive use of the computer; sometimes I would literally just have one window open browsing the interwebs and it would give up on me, and other times it wouldn't happen until I had a billion tabs open streaming tv shows on every single one.
    At its very worst, I had to hard reset the computer yet again, but when it booted up the SSD was no longer recognized. It was as if I unplugged and removed it so there was nothing in the primary bay and I just turned the computer on. So it booted to the that thing with the options: recover from time machine backup, reinstall Lion, get help online, or disk utility. However, the SSD does not appear in the disk utility, I can't reinstall Lion to it (because it's not an option), and I can't use the SSD as a startup disk (also because it's not an option). I was completely sure it was a faulty SSD so I sent it to OCZ, who then crushed my hopes and told me there was nothing wrong with the drive.
    My hunch after several hours of digging throgh other forums is that something is wrong with my logic board, but I'm obviously posting this because I don't have any confidence in my hunch and would rather have some feedback before I go splurging on a diagnosis or - oh no! - another logic board.
    Thanks in advance, maybe.

    As I mentioned I sent it back to them, and they replied with this:
    "I would like to inform you that the RMA drive you sent back to us is no trouble found. Hence we will ship the same unit back to you. 
    Below is all the actions were performed on your drive.
    •        Writes every block on the drive many times.
    •        Verifies all data written.
    •        Reads every block on the drive many times.
    •        Tracks performance during this test, and makes sure it is within expected ranges.
    •        Tracks SMART data throughout this process to ensure proper functionality and recording of info."
    Then in a later email:
    "We thoroughly tested the drive on several machines. The drive has passed all testing with no faults found. The drive is functioning correctly as received. "
    I am actually praying that its my SSD or a broken SATA cable (no chance) because those are relatively cheap.
    Any ideas?

  • No one from Verizon has addressed my previous post, so I'll ask again:

    WHAT IN THE HECK happened during the 5/22/14 update that messed up Android phones on Verizon? Is it possible to UN-update??? I have a Motorola Droid Razr M. ( I have a friend who has a Samsung Galaxy Note, and she is having similar problems as me).  I LOVED my phone until this May 22, 2014 update....now I HATE it.  And don't tell me there is something wrong with my phone.....these issues started IMMEDIATELY after re-starting my phone after installing the update.  I have gone through all the typical troubleshooting steps already. Here is a list of my issues, in no particular order:
    1.  Device vibration upon incoming call/text is so faint now it is undetectable when the phone is in my pocket or purse.   It worked just fine before. 
    2.  LED light to signal incoming call or text, missed call, or low battery no longer working....I only get an LED light with incoming call and it is a very pale, faint white light that is hard to see in the daylight. No light for missed call, incoming text, or battery.
    3.  Calls drop constantly when I cradle the phone between my chin and shoulder.  Never had this problem before, and I ALWAYS cradle the phone.  I believe this problem exists because of issue #4....
    4.  Prior to update, during a call, if I had the phone up to my ear, the buttons would go to black screen so there was no accidental bumping of buttons, until I pulled the phone away from my ear.  After update, buttons stay visible during call, thus possibly leading to the issue above.
    5. No longer able to switch between calls using call waiting feature. First call is always dropped when I go to switch.
    6. Volume on calls significantly reduced....even with volume all the way up.  Very hard to hear the caller talking now unless they raise their voice!
    7. It is now taking a good 5-8 seconds for a call to begin from the time I click on my contact to the time the number actually dials.  I don't understand the sudden delay!
    8.  All my icons for apps/widgets changed.  Not liking new format.    
    9. Not liking new format on white text message screen....very hard to see in daylight. Not liking inability to delete multiple messages at once.
    10.  Not liking format of contacts list, with no letter tabs on sides to go directly to the letter I want, I have to scroll through whole list now.
    11.  Update messed with my Weather Underground App (dark grey on the radar map now, making it hard to see precipitation), and Facebook (cannot operate several functions within Facebook that were easily accessible just prior to the phone update). New format on Google Play Music has changed and is no longer user-friendly!!
    12.  Update installed several apps that I do not want nor need on my phone but yet I cannot un-install.  Perhaps leading to issue #13....
    13.  BATTERY LIFE SIGNIFICANTLY REDUCED SINCE UPDATE.....AM CHARGING PHONE TWICE A DAY NOW BUT NOT USING IT ANY MORE THAN BEFORE!!
    14.  Can no longer download music from MP3 download site to Google Play Music. Downloads go to Astro File manager and cannot be moved to Google Play Music widget.
    I clean cache/history and run Antivirus software at least once weekly.  I manage running tasks/apps.  I do not download apps,  no do I download music from questionable sources.  And yet I have at least 14 problems/issues since the update!  And I have been reading online that MANY Android owners are having many of the same issues & complaints since the 5/22/14 update. SOMETHING IS VERY WRONG HERE!!  THESE UPDATES.....WHY IS IT NECESSARY TO "FIX" SOMETHING THAT ISN'T EVEN BROKEN????  Because....NOW it IS broken....
    Verizon.......do something about this, please??????

    Neenert88 I sympathize with you.  I just added a line to my account because of major issues with the Droid Razor M which they could not fix.    I can't view email 99% of the time. I can open the app but that's as far as it goes.  I live by email some days so it's causing big issues for me at times.  No answer from Verizon when I had the problem with the Razor either, just that they are aware there are bugs and give it few weeks to see if they make any patches.  I don't have several weeks to sit and wait to see if someone decides to make a decision to fix the issues.
    I'm paying for a service that I cannot use, and there seems to be no care from anyone to resolve a thing.  It's ok that they receive their payments but when there is a problem, everyone seems to disappear.  Forget about insurance, $100.00 later, on top of what you paid already, you get a crappy refurbished phone that someone else already returned because of issues.
    I have an appointment tomorrow with Verizon.  If they can't fix the problem and guarantee it tomorrow, they can take the phone back for a full refund, of EVERYTHING, or reduce my bill for no access until they do, or I'll take my business someplace else and NOT purchase a product with the Droid OS.   Such a shame.  I guess they don't believe in performing testing on applications or OS before it's rolled out to the public. 

  • Error in creating Java Users during Solution Manager installation

    Hi gurus,
    First time trying to install SAP.
    Red Hat Linux 4
    Oracle
    jdk 1.4.2_11
    While installing the Solution Manager, it errored when it was creating Java Users, SAPJSF, J2EE_ADMIN and J2EE_GUEST.
    The error description read "jco$exception: rfc_error_system_failure: invalid request".
    I want to create these users manually and continue with the rest of process.
    I searched lots of entries, notes, etc., but somehow, my "old" pair of eyes (and brains, too) failed to come up with something I could understand.
    So, gurus, please help, help, help!!
    There are no GUI version of anything installed, no Virtual Admin, no nothing like that. I have to rely on good old unix (Linux) command to do (add users) this.
    Can you please, please post the instructions (step-by-step)? Please have a pity on me since this is my very first time dealing with SAP.
    Thanks and regards.

    Creating users manually is not the intension of the SAP Installation tool. There are other solutions available
    A good starting point is to check if SELinux is enabled or disabled. I've seen lots of broken installations on Red Hat because SELinux does not allow the installer to create users. Check if in /etc/selinux/config  the setting
    SELINUX=disabled
    is set.
    I see, that you are using JDK 1.4.2_11. Is this the Sun JDK? In case you are on x86_64 you have to use the IBM JDK instead. You can download it from <a href="https://www14.software.ibm.com/webapp/iwm/web/reg/download.do?source=lxdk&S_PKG=amd64142sr7&S_TACT=105AGX05&S_CMP=JDK&lang=en_US&cp=UTF-">here</a> .
    Also a new SAPINST may help. The current Installation Master CD can you download here:
    http.//service.sap.com/swdc
    -> Download
    -> Installations and Upgrades
    -> Entry by Application Group
    -> SAP Technology Components
    -> SAP SOLUTION MANAGER
    -> SAP SOLUTION MANAGER 3.2/4.0
    -> Installation and Upgrade
    -> LINUX
    -> ORACLE
    51032006       SAP Solution M. 4.0 SR1 Inst. Master **
    Best Regards,
    Hannes Kuehnemund

  • 10.6.2 update causes all non-Apple applications to crash.

    update Final Cut Studio 3 and Aperture fail to open as well (pro apps)
    Hi: Hoping for some expert help here.
    Updated from 10.6.1 to 10.6.2 today, using the combo update. The Software Update version refused to install.
    After a reboot, I was *unable to open any non-Apple branded application*. Firefox, Adobe CS3 or CS4, Roxio, MS Office, you name it. All Apple branded apps, iLife, iWork, Mail, Safari, all performed well.
    I created a new admin account, hoping that those problems would not occur - but they did.
    I have since done a Time Machine backup and am ready to do a clean install to rid myself of this mess.
    Before I do, I'm wondering if there's an easy fix out there.
    I did do a repair permissions before and after the install. I have removed Application Support files from the Library (both in the root and my profile).
    Am now angry and frustrated, but this isn't the first time Apple has let me down with a poor update package.
    Any suggestions/help would be appreciated.
    Thanks.
    Message was edited by: Prof. Van Nostrum

    donv (The Ghost) wrote:
    I am still happily at 10.6 because .6.1 broke things for some and offered me nothing I needed. Looks like .6.2 combo will be the same. I have no incentive to install it.
    Keep in mind:
    1. There is no evidence that the Snow Leopard updates have broken anything for most users -- because of the focus of forums like this one on problems, they are not reliable indicators of typical results.
    2. Among the reports of Snow Leopard update problems, many if not most are caused by unidentified pre-exsting conditions, not the updates themselves. These things should be fixed whether or not you update the OS because they usually get worse over time & eventually can't be ignored.
    3. For almost all users there are very strong incentives to install the updates. Among them:
    • Eliminating bugs that have been identified in the original release of the OS, typically ones that occur under relatively rare conditions. Just because one has not affected you yet does not mean it won't in the future.
    • Adding small & sometimes not-so-small improvements in the reliability, efficiency, & optimization of applications & application services. Every OS release is subject to deadlines; there are always some things that could be improved given more time to work on them. Software updates give the engineers the time they need to add these tweaks to the system.
    • Eliminating potential security exploits that have been identified in earlier releases of the OS. The OS is pretty secure to begin with; however, it is not so secure that users should become complacent about this -- especially since many of the flaws are well documented, meaning those with malicious intent can easily learn how to exploit them. This has been a historic problem with Windows: so many users of that OS are so lax about applying security updates that Windows malware that could not exploit the updated OS still regularly spread across the Internet & affect tens of millions of users. This includes Mac users because the malware often turns the vulnerable computers into "zombies" used to create botnets to do things like generate spam or launch denial of service attacks.
    There is little indication that this kind of malware currently targets Macs -- Windows computers are still the low hanging fruit most malefactors target -- but continued complacency among Mac users about this issue plus the increasing market share of Macs do not bode well for the future.
    Simply put, all OS's should be considered ongoing works in need of improvement. Apple does not make public all the fixes or improvements any OS update provides, so unless you try them you won't know how significant they will be for you. Caution is good -- always have a backup/reversion strategy should something go wrong -- but the old adage "if it ain't broke don't fix it" does not apply -- the OS is always broken so it is really a matter of how broken it is, not if it is or isn't.

  • Failover cluster failed due to mysterious IP conflict ?

    I'm having a mysterious problem with my Failover cluster,
    Cluster name: PrintCluster01.domain.com
    Members: PrintServer01.domain.com andPrintServer02.domain.com
    in the Failover Cluster Management – Cluster Event I received the Critical error message 1135 and 1177:
    Log Name: System
    Source: Microsoft-Windows-FailoverClustering
    Date: 15/06/2011 9:07:49 PM
    Event ID: 1177
    Task Category: None
    Level: Critical
    Keywords:
    User: SYSTEM
    Computer: PrintServer01.domain.com
    Description:
    The Cluster service is shutting down because quorum was lost. This could be due to the loss of network connectivity between some or all nodes in the cluster, or a failover of the witness disk.
    Run the Validate a Configuration wizard to check your network configuration. If the condition persists, check for hardware or software errors related to the network adapter. Also check for failures in any other network components to which the node is
    connected such as hubs, switches, or bridges.
    Log Name: System
    Source: Microsoft-Windows-FailoverClustering
    Date: 15/06/2011 9:07:28 PM
    Event ID: 1135
    Task Category: None
    Level: Critical
    Keywords:
    User: SYSTEM
    Computer: PrintServer01.domain.com
    Description:
    Cluster node 'PrintServer02' was removed from the active failover cluster membership. The Cluster service on this node may have stopped. This could also be due to the node having lost communication with other active nodes in the failover cluster. Run
    the Validate a Configuration wizard to check your network configuration. If the condition persists, check for hardware or software errors related to the network adapters on this node. Also check for failures in any other network components to which the node
    is connected such as hubs, switches, or bridges.
    After further investigation, I found some interesting error here, from the very first critical error message logged in the Event viewer on PrintServer02:
    Log Name: System
    Source: Tcpip
    Date: 15/06/2011 9:07:29 PM
    Event ID: 4199
    Task Category: None
    Level: Error
    Keywords: Classic
    User: N/A
    Computer: PrintServer02-VM.domain.com
    Description:
    The system detected an address conflict for IP address 192.168.127.142 with the system having network hardware address 00-50-56-AE-29-23. Network operations on this system may be disrupted as a result.
    192.168.127.142 --> secondary IP of PrintServer01
    how could that be possible it conflict by one of the PrintServer01 node ? the detailed is as below:
    **From PrintServer01**
    Ethernet adapter Local Area Connection* 8:
    Connection-specific DNS Suffix . :
    Description . . . . . . . . . . . : Microsoft Failover Cluster Virtual Adapter
    Physical Address. . . . . . . . . : 02-50-56-AE-29-23
    DHCP Enabled. . . . . . . . . . . : No
    Autoconfiguration Enabled . . . . : Yes
    IPv4 Address. . . . . . . . . . . : 169.254.1.183(Preferred)
    Subnet Mask . . . . . . . . . . . : 255.255.0.0
    Default Gateway . . . . . . . . . :
    NetBIOS over Tcpip. . . . . . . . : Enabled
    I have double check in all of the cluster members that all IP addresses is now unique.
    however I'm sure that I the IP is static not by DHCP as from the IPCONFIG results below:
    From **PrintServer01** (the Active Node)
    Windows IP Configuration
    Host Name . . . . . . . . . . . . : PrintServer01
    Primary Dns Suffix . . . . . . . : domain.com
    Node Type . . . . . . . . . . . . : Hybrid
    IP Routing Enabled. . . . . . . . : No
    WINS Proxy Enabled. . . . . . . . : No
    DNS Suffix Search List. . . . . . : domain.com
    domain.com.au
    Ethernet adapter Local Area Connection* 8:
    Connection-specific DNS Suffix . :
    Description . . . . . . . . . . . : Microsoft Failover Cluster Virtual Adapter
    Physical Address. . . . . . . . . : 02-50-56-AE-29-23
    DHCP Enabled. . . . . . . . . . . : No
    Autoconfiguration Enabled . . . . : Yes
    IPv4 Address. . . . . . . . . . . : 169.254.1.183(Preferred)
    Subnet Mask . . . . . . . . . . . : 255.255.0.0
    Default Gateway . . . . . . . . . :
    NetBIOS over Tcpip. . . . . . . . : Enabled
    Ethernet adapter Cluster Public Network:
    Connection-specific DNS Suffix . :
    Description . . . . . . . . . . . : Intel® PRO/1000 MT Network Connection
    Physical Address. . . . . . . . . : 00-50-56-AE-29-23
    DHCP Enabled. . . . . . . . . . . : No
    Autoconfiguration Enabled . . . . : Yes
    IPv4 Address. . . . . . . . . . . : 192.168.127.155(Preferred)
    Subnet Mask . . . . . . . . . . . : 255.255.255.0
    IPv4 Address. . . . . . . . . . . : 192.168.127.88(Preferred)
    Subnet Mask . . . . . . . . . . . : 255.255.255.0
    IPv4 Address. . . . . . . . . . . : 192.168.127.142(Preferred)
    Subnet Mask . . . . . . . . . . . : 255.255.255.0
    IPv4 Address. . . . . . . . . . . : 192.168.127.143(Preferred)
    Subnet Mask . . . . . . . . . . . : 255.255.255.0
    IPv4 Address. . . . . . . . . . . : 192.168.127.144(Preferred)
    Subnet Mask . . . . . . . . . . . : 255.255.255.0
    Default Gateway . . . . . . . . . : 192.168.127.254
    DNS Servers . . . . . . . . . . . : 192.168.127.10
    192.168.127.11
    Primary WINS Server . . . . . . . : 192.168.127.10
    Secondary WINS Server . . . . . . : 192.168.127.11
    NetBIOS over Tcpip. . . . . . . . : Enabled
    Ethernet adapter Cluster Private Network:
    Connection-specific DNS Suffix . :
    Description . . . . . . . . . . . : Intel® PRO/1000 MT Network Connection #2
    Physical Address. . . . . . . . . : 00-50-56-AE-43-EC
    DHCP Enabled. . . . . . . . . . . : No
    Autoconfiguration Enabled . . . . : Yes
    IPv4 Address. . . . . . . . . . . : 10.184.2.2(Preferred)
    Subnet Mask . . . . . . . . . . . : 255.255.255.0
    Default Gateway . . . . . . . . . :
    NetBIOS over Tcpip. . . . . . . . : Disabled
    From **PrintServer02**
    Windows IP Configuration
    Host Name . . . . . . . . . . . . : PrintServer02
    Primary Dns Suffix . . . . . . . : domain.com
    Node Type . . . . . . . . . . . . : Hybrid
    IP Routing Enabled. . . . . . . . : No
    WINS Proxy Enabled. . . . . . . . : No
    DNS Suffix Search List. . . . . . : domain.com
    domain.com.au
    Ethernet adapter Local Area Connection* 8:
    Connection-specific DNS Suffix . :
    Description . . . . . . . . . . . : Microsoft Failover Cluster Virtual Adapter
    Physical Address. . . . . . . . . : 02-50-56-AE-5F-E5
    DHCP Enabled. . . . . . . . . . . : No
    Autoconfiguration Enabled . . . . : Yes
    IPv4 Address. . . . . . . . . . . : 169.254.2.86(Preferred)
    Subnet Mask . . . . . . . . . . . : 255.255.0.0
    Default Gateway . . . . . . . . . :
    NetBIOS over Tcpip. . . . . . . . : Enabled
    Ethernet adapter Cluster Public Network:
    Connection-specific DNS Suffix . :
    Description . . . . . . . . . . . : Intel® PRO/1000 MT Network Connection
    Physical Address. . . . . . . . . : 00-50-56-AE-79-FA
    DHCP Enabled. . . . . . . . . . . : No
    Autoconfiguration Enabled . . . . : Yes
    IPv4 Address. . . . . . . . . . . : 192.168.127.172(Preferred)
    Subnet Mask . . . . . . . . . . . : 255.255.255.0
    IPv4 Address. . . . . . . . . . . : 192.168.127.119(Preferred)
    Subnet Mask . . . . . . . . . . . : 255.255.255.0
    Default Gateway . . . . . . . . . : 192.168.127.254
    DNS Servers . . . . . . . . . . . : 192.168.127.10
    192.168.127.11
    Primary WINS Server . . . . . . . : 192.168.127.11
    Secondary WINS Server . . . . . . : 192.168.127.10
    NetBIOS over Tcpip. . . . . . . . : Enabled
    Ethernet adapter Cluster Private Network:
    Connection-specific DNS Suffix . :
    Description . . . . . . . . . . . : Intel® PRO/1000 MT Network Connection #2
    Physical Address. . . . . . . . . : 00-50-56-AE-77-8D
    DHCP Enabled. . . . . . . . . . . : No
    Autoconfiguration Enabled . . . . : Yes
    IPv4 Address. . . . . . . . . . . : 10.184.2.3(Preferred)
    Subnet Mask . . . . . . . . . . . : 255.255.255.0
    Default Gateway . . . . . . . . . :
    NetBIOS over Tcpip. . . . . . . . : Disabled
    Any help would be greatly appreciated.
    Thanks,
    AWT
    /* Server Support Specialist */

    I
    am facing the same scenario as the original poster. This is on Server 2008 R2 SP1.
     WIndow event log entries follow the same pattern. The MAC address listed in connection with the duplicate IP belonged to the passive node.
    Interestingly, the Cluster.log begins to explode with activity a few milliseconds before the first Windows event is logged.
    2012/07/11-15:20:59.517 INFO  [CHANNEL fe80::8145:f2b9:898e:784e%37:~3343~] graceful close, status (of previous failure, may not indicate problem) ERROR_IO_PENDING(997)
    2012/07/11-15:20:59.517 WARN  [PULLER SQLTESTSQLB] ReadObject failed with GracefulClose(1226)' because of 'channel to remote endpoint fe80::8145:f2b9:898e:784e%37:~3343~
    is closed'
    2012/07/11-15:20:59.517 ERR   [NODE] Node 1: Connection to Node 2 is broken. Reason GracefulClose(1226)' because of 'channel to remote endpoint fe80::8145:f2b9:898e:784e%37:~3343~
    is closed'
    2012/07/11-15:20:59.517 WARN  [RGP] Node 1: only local suspects are missing (2). moving to the next stage (shortcut compensation time 05.000)
    2012/07/11-15:20:59.548 WARN  [NETFTAPI] Failed to query parameters for fe80::5efe:169.254.1.79 (status 80070490)
    2012/07/11-15:20:59.548 WARN  [NETFTAPI] Failed to query parameters for fe80::5efe:169.254.1.79 (status 80070490)
    2012/07/11-15:20:59.579 INFO  [CHANNEL 192.168.3.22:~3343~] graceful close, status (of previous failure, may not indicate problem) ERROR_SUCCESS(0)
    2012/07/11-15:20:59.579 WARN  cxl::ConnectWorker::operator (): GracefulClose(1226)' because of 'channel to remote endpoint 192.168.3.22:~3343~ is closed'
    2012/07/11-15:20:59.829 INFO  [GEM] Node 1: EnterRepairStage1: Gem agent for node 1
    2012/07/11-15:21:00.141 INFO  [GEM] Node 1: EnterRepairStage2: Gem agent for node 1
    2012/07/11-15:21:00.499 WARN  [RCM] Moving orphaned group Available Storage from downed node SQLTESTSQLB to node SQLTESTSQLA.
    2012/07/11-15:21:00.499 WARN  [RES] IP Address <Cluster IP Address>: WorkerThread: NetInterface ef150d1a-f4a1-4f4f-a5c7-6e7cb2bfacab changed to state 3.
    2012/07/11-15:21:00.499 WARN  [RCM] Moving orphaned group MSSTEST from downed node SQLTESTSQLB to node SQLTESTSQLA.
    2012/07/11-15:21:00.546 WARN  [RES] IP Address <SQL IP Address 1 (DEVSQL)>: Failed to delete IP interface 2003B882, status 87.
    2012/07/11-15:21:00.562 WARN  [RES] Physical Disk <Cluster Disk 2>: PR reserve failed, status 170
    2012/07/11-15:21:00.577 WARN  [RES] Physical Disk <Cluster Disk 1>: PR reserve failed, status 170
    2012/07/11-15:21:00.593 WARN  [RES] Physical Disk <Cluster Disk 3>: PR reserve failed, status 170
    2012/07/11-15:21:02.215 WARN  [NETFTAPI] Failed to query parameters for 192.168.3.32 (status 80070490)
    2012/07/11-15:21:02.215 WARN  [NETFTAPI] Failed to query parameters for 192.168.3.32 (status 80070490)
    2012/07/11-15:21:05.864 DBG   [NETFTAPI] received NsiParameterNotification  for fe80::5cd:8cc2:186:f5cb (IpDadStatePreferred )
    2012/07/11-15:21:06.565 ERR   [RES] Physical Disk <Cluster Disk 2>: Failed to preempt reservation, status 170
    2012/07/11-15:21:06.581 ERR   [RES] Physical Disk <Cluster Disk 2>: OnlineThread: Unable to arbitrate for the disk. Error: 170.
    2012/07/11-15:21:06.581 ERR   [RES] Physical Disk <Cluster Disk 2>: OnlineThread: Error 170 bringing resource online.
    2012/07/11-15:21:06.581 ERR   [RHS] Online for resource Cluster Disk 2 failed.
    2012/07/11-15:21:06.581 WARN  [RCM] HandleMonitorReply: ONLINERESOURCE for 'Cluster Disk 2', gen(0) result 5018.
    2012/07/11-15:21:06.581 ERR   [RCM] rcm::RcmResource::HandleFailure: (Cluster Disk 2)
    2012/07/11-15:21:06.581 WARN  [RES] Physical Disk <Cluster Disk 2>: Terminate: Failed to open device \Device\Harddisk5\Partition1, Error 2
    2012/07/11-15:21:06.581 ERR   [RES] Physical Disk <Cluster Disk 1>: Failed to preempt reservation, status 170
    2012/07/11-15:21:06.581 ERR   [RES] Physical Disk <Cluster Disk 1>: OnlineThread: Unable to arbitrate for the disk. Error: 170.
    2012/07/11-15:21:06.581 ERR   [RES] Physical Disk <Cluster Disk 1>: OnlineThread: Error 170 bringing resource online.
    Full cluster log here:
    https://skydrive.live.com/redir?resid=A694FDEBF02727CD!133&authkey=!ADQMxHShdeDvXVc

  • My hp external display is not found

    Have been using HP w19b as an external monitor for almost a year.  I have a 2009 (late) 27" imac and am running 10.8.2.  My external monitor went to sleep and never woke up on Nov 11, 2012.  I don't think there were any new updates on this date.  Had been on 10.8.2 for a while???  When I go to preferences, it is as though it is not even connected.  I unplugged and re-plugged all connections.  The monitor is not broken, just goes to sleep because it is getting no signal from imac.  What in the world.  Please help.  I need the screen real estate!!!! The connection is the mini display port? to AVG adapter...

    thanks for the reply...unfortunately, I just did all of the above.  I checked all connections, no external monitor appears in system preferences - displays, did a restart in safe mode, did a SMC reset and a pram reset.  Still no monitor.  So I unhooked mine, and tried my son's monitor - an hp 2009m.  I restarted my imac and the screen on the monitor said scanning for signal, no signal found, going to sleep. 
    Is it possible that the adapter thing to my vga cable has gone bad.  Is there a way to see if the port itself is functioning?
    I was on the verge of buying a bigger external monitor, but don't want to now since I am scared it won't work.
    Is anyone else having this problem???

Maybe you are looking for

  • Why do I have to keep downloading FOXFIRE. This is the 4th time.

    I don't know what you need as to more details. But every once in awhile, I completely lose the normal loading of FOXFIRE. I end up without my toolbar and when I enter my email, or any other link - FACEBOOK, or whatever, I have a full screen of that l

  • Time stamp / serial number

    Trying to create a serial number that is stamped with a dealer ID code, and the current date/time when the form is initially opened. var dealer_id = String(Dealer_ID.rawValue); var today = new Date(); var serializedNumber = Dealer_ID + today.getTime(

  • Original file name preserved in metadata but not being found in searches (Mac)

    I have a large collection of images (a mix of raw, tif, and jpg files) that I would like to rename. Because some are referred to in other documents by their original names, and because I can't track down every single version that might exist in other

  • Issue using JS to change the value of an output text component dynamically

    I am developing an application and I need to change the output text component value at run time when the mouse moves over a field. I am using javascript and then using UIComponent.setproperty to change the value. I am not able to do this and am getti

  • Also.... Credit card number needed?

    Why is the credit card number and expiration needed to create the account on the iTunes store? I've read a lot of the previous questions and answers to topics similar to this, and many of the answers tell the person who asked the question to check th