[prev in list] [next in list] [prev in thread] [next in thread] 

List:       novell
Subject:    NOVELL Digest - 18 Aug 2002 to 19 Aug 2002 (#2002-352)
From:       Automatic digest processor <LISTSERV () LSV ! SYR ! EDU>
Date:       2002-08-20 4:00:17
[Download RAW message or body]

There are 17 messages totalling 819 lines in this issue.

Topics of the day:

  1. NW6SP2 problem
  2. TCP/IP communicaion problems... (3)
  3. NT Domains are there but aren't...
  4. JRBImport - I am so screwed! (An idiot too...)
  5. Migration Wizard trustee rights restore abends
  6. Iprint problems (2)
  7. my experiences :)
  8. FTP NWFTPD v5.02r passive connections (3)
  9. Compaq ML370 G2 - 4gb Ram?
 10. Jrbimprt - difficulty using "Login Disabled" directive (2)
 11. Novastor Backup Software

The NOVELL list is hosted by L-Soft international's LISTSERV(TM) software
at Syracuse University.  To unsubscribe, send a SIGNOFF NOVELL command
to LISTSERV@LSV.SYR.EDU.  If you have questions about the list, write
to NOVELL-REQUEST@LSV.SYR.EDU.

----------------------------------------------------------------------

Date:    Mon, 19 Aug 2002 08:37:34 +0100
From:    Gordon Ross <G.Ross@CCW.GOV.UK>
Subject: Re: NW6SP2 problem

Have you got a sufficent number for the "Files=" entry in config.sys ?
Latest service packs require a larger number for this. (I use 100)

GTG

>>> JRD@CC.USU.EDU 19/08/2002 02:27:46 >>>
>I found a problem with NW6SP2
>
>I got errors on one of the Loadstages when it loaded CLIB.nlm
>
>The solution was that it did not copy CLIB to sys\system but it copied
the
>
>new one to c:\nwserver\
>
>So I loaded it from the c drive and it worked.
>
>Then when I ran loadstage 5
>nwusage.nlm
>it gave an error on httpstk.nlm
>
>However after loading autoexec.ncf  httpstk.nlm loads fine.
>I can't figure out what the cause or solution is but it works
>after autoexec.ncf
----------
        Clib*.nlm live in c:\nwserver. They aren't in sys:system with
NW 6. Thus we suspect your server was one upgraded from NW 5.1 and
loose ends persist. If so there may be a bit of file comparing and
cleanup required.
        Joe D.

------------------------------

Date:    Mon, 19 Aug 2002 10:16:07 +0100
From:    Ian Kennedy <ian.kennedy@DTU.OX.AC.UK>
Subject: Re: TCP/IP communicaion problems...

John Hanna wrote:
> Here are some things you may want to check.
>
> 1) Make sure the duplex and speed are hard set to the same on the servers
> and the switch ports. I recommend half duplex at least until you find your
> problem out.

Yes, we checked this. The duplex in our site was half duplex. In the new
site it was full and we changed the servers to match that. Now that
we've moved them back we changed it to half duplex again.

> 2) make sure you have the gateway set on your servers. I have seen marginal
> problems with traffic leaving the subnet on servers without the gateway set.

Hmm... I used to have these specified in the autoexec.ncf. However,
years ago I switched to useing INetCFG and they seem to have disapeared.
Also, I can't find any place to enter them. Is there a method of
manipulating a file to allow the option to be pressent in INetCFG
(kinda like you can alter card drivers by editing the LDI file).

> 3) Check to see if you have someone else competing for your IP address.
> This sounds possible since, traffic goes fine and then quits for a few
> minutes it could mean the arp table is changing, most windows boxes will arp
> to see if the address is already in use, if it is, it will disable the
> interface, but not until it has cause problems for about the period of time
> you state.

Yes, we thought about this one. It had the look of someone walking on
our address. However, now that the machines are back in our department
and all is back to the way it was we're sure that these adresses are
are unique.

> HTH

Thanks
Ian

<my message trimmed for space>

------------------------------

Date:    Mon, 19 Aug 2002 10:07:05 +0100
From:    Tim Heywood <tch@IQX.CO.UK>
Subject: Re: TCP/IP communicaion problems...

> 2) make sure you have the gateway set on your servers. I have seen
marginal
> problems with traffic leaving the subnet on servers without the
gateway set.

Hmm... I used to have these specified in the autoexec.ncf. However,
years ago I switched to useing INetCFG and they seem to have
disapeared.
Also, I can't find any place to enter them. Is there a method of
manipulating a file to allow the option to be pressent in INetCFG
(kinda like you can alter card drivers by editing the LDI file).


In INETCFG select Protocols, TCP/IP, LAN Static Routing.  There you can
set up routes to hosts, networks and the default route.  The default
route is to all intents and purposes the gateway.

The gateway as per the autoexec.ncf method says if I don't know about
the destination, send it to...  and that's exactly what the default
route does.

Tim

*************************
Tim Heywood
Scotland
(God's Country)
Novell Support Connection Sysop
*************************

------------------------------

Date:    Mon, 19 Aug 2002 11:33:28 +0100
From:    Ian Kennedy <ian.kennedy@DTU.OX.AC.UK>
Subject: Re: TCP/IP communicaion problems...

Tim Heywood wrote:
>>2) make sure you have the gateway set on your servers. I have seen
>
> marginal
>
>>problems with traffic leaving the subnet on servers without the
>
> gateway set.
>
> Hmm... I used to have these specified in the autoexec.ncf. However,
> years ago I switched to useing INetCFG and they seem to have
> disapeared.
> Also, I can't find any place to enter them. Is there a method of
> manipulating a file to allow the option to be pressent in INetCFG
> (kinda like you can alter card drivers by editing the LDI file).
>
>
> In INETCFG select Protocols, TCP/IP, LAN Static Routing.  There you can
> set up routes to hosts, networks and the default route.  The default
> route is to all intents and purposes the gateway.
>
> The gateway as per the autoexec.ncf method says if I don't know about
> the destination, send it to...  and that's exactly what the default
> route does.
>
> Tim

Yup, that seems to have done the trick.
Thanks to John and Tim for the fix.
TTFN
Ian

------------------------------

Date:    Mon, 19 Aug 2002 09:14:56 -0400
From:    Wallace Marks <Wallace.Marks@NATIONALVISION.COM>
Subject: Re: NT Domains are there but aren't...


You mentioned ZenWorks.  Are you using Dynamic Local User?  If yes, that
could be your problem.  ZenWorks' DLU directly conflicts with NT Domain
access.  See the following TIDs for more info:

http://support.novell.com/cgi-bin/search/searchtid.cgi?/10060858.htm
http://support.novell.com/cgi-bin/search/searchtid.cgi?/10071725.htm
http://support.novell.com/cgi-bin/search/searchtid.cgi?/10017584.htm
...plus many others.  Search the Knowledgebase for "DLU and domain" for
more info.

In a nutshell, DLU is an authentication mechanism intended for use in a
domain-less environment.  When domains are present, you should disable
DLU and let the domain do the authentication instead.  If you have both
domains AND DLU, users will be able to browse domain controllers but not
member servers.  The TIDs all say that if domains are present, you
should disable DLU.  What irritates me is the assumption that domains
are an "all-or-nothing" approach.  In our organization, the vast
majority of users don't even touch a domain.  We need both domains AND
DLU.

That said, here are some workarounds:

1) Use a separate policy to disable DLU for select users.  Of course
this locks those users down to workstations that are domain-enabled.

2) Disable DLU on the client.  According to online documentation, the
4.83 SP1 client has an option to disable DLU from the client side.
Where this feature is hidden though, I have no idea.  I also don't know
if this resolves the DLU <-> Domain conflict.

3) Make all NT servers domain controllers.  One of the TIDs mentioned
that DLU users would be able to browse domain controllers but not member
servers.  That led us to ask "what if we do away with member servers?"
We did some experimenting and found this to be a good working solution.
There may be some drawbacks to this approach, but we haven't encountered
any.

Hope this helps...

>>> Rich Molettiere rmoletti@OPS.ORG> 08/17/02 12:26PM >>

Windows2000 with 4.83 SP1, MS Client active and the workstation is a
member of the local domain NORTH. We access NT4-based apps in the SASI
domain housed at our district office.

Browsing My Network Places sometimes displays only the NORTH domain;
others all the NT domains in the district.
A ZEN app object that points to the NT-based app will sometimes work or
will fail with "access denied." However, on the failure, "sometimes" you
can browse to the app and launch it OR doing a START:RUN and then
\\sasi332\ (the domain server on which the NT app resides) will open the
sasi332 desktop and you can then browse by opening the folders.
Eventually, you can launch the app.

The problem is the inconsistency - the district support folks are
talking about some sort of conflict with Windows95 desktops (we still
have a few) and/or IP protocal preferences on the desktop or ???

Does this make sense to anyone because it doesn't to me.


[Attachment #3 (text/html)]

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META http-equiv=Content-Type content="text/html; charset=iso-8859-1">
<META content="MSHTML 6.00.2716.2200" name=GENERATOR></HEAD>
<BODY style="MARGIN-TOP: 2px; FONT: 10pt Comic Sans MS; MARGIN-LEFT: 2px">
<DIV>You mentioned ZenWorks.&nbsp; Are you using Dynamic Local User?&nbsp; If
yes, that could be your problem.&nbsp; ZenWorks' DLU directly conflicts with NT
Domain access.&nbsp; See the following TIDs for more info:</DIV>
<DIV>&nbsp;</DIV>
<DIV><A
href="http://support.novell.com/cgi-bin/search/searchtid.cgi?/10060858.htm">http://support.novell.com/cgi-bin/search/searchtid.cgi?/10060858.htm</A></DIV>
 <DIV><A
href="http://support.novell.com/cgi-bin/search/searchtid.cgi?/10071725.htm">http://support.novell.com/cgi-bin/search/searchtid.cgi?/10071725.htm</A></DIV>
 <DIV><A
href="http://support.novell.com/cgi-bin/search/searchtid.cgi?/10017584.htm">http://support.novell.com/cgi-bin/search/searchtid.cgi?/10017584.htm</A></DIV>
 <DIV>...plus many others.&nbsp; Search the Knowledgebase for "DLU and domain"
for more info.</DIV>
<DIV>&nbsp;</DIV>
<DIV>In a nutshell, DLU is an authentication mechanism intended for use in a
domain-less environment.&nbsp; When domains are present, you should disable DLU
and let the domain do the authentication instead.&nbsp; If you have both domains
AND DLU, users will be able to browse domain controllers but not member
servers.&nbsp; The TIDs all say that if domains are present, you should disable
DLU.&nbsp; What irritates me&nbsp;is the assumption that domains are an
"all-or-nothing" approach.&nbsp; In our organization, the vast majority of users
don't even touch a domain.&nbsp; We need both domains AND DLU.</DIV>
<DIV>&nbsp;</DIV>
<DIV>That said, here are some workarounds:</DIV>
<DIV>&nbsp;</DIV>
<DIV>1) Use a separate policy to disable DLU for select users.&nbsp; Of course
this locks those users down to workstations that are domain-enabled.</DIV>
<DIV>&nbsp;</DIV>
<DIV>2)&nbsp;Disable DLU on the client.&nbsp; According to&nbsp;online
documentation, the 4.83 SP1 client has an option to disable DLU from the client
side.&nbsp; Where this feature is hidden though, I have no idea.&nbsp; I also
don't know if this&nbsp;resolves the DLU &lt;-&gt; Domain conflict.&nbsp; </DIV>
<DIV>&nbsp;</DIV>
<DIV>3) Make all NT servers domain controllers.&nbsp;&nbsp;One of the&nbsp;TIDs
mentioned that DLU&nbsp;users would be able to browse domain controllers but not
member servers.&nbsp; That led us to ask "what if we do away with&nbsp;member
servers?"&nbsp; We&nbsp;did some experimenting and found this to be a good
working solution.&nbsp; There may be some drawbacks to this approach, but we
haven't encountered any.</DIV>
<DIV><BR>Hope this helps...</DIV>
<DIV>&nbsp;</DIV>
<DIV>&gt;&gt;&gt; Rich Molettiere <A
href="mailto:rmoletti@OPS.ORG> 08/17/02 12:26PM >>">rmoletti@OPS.ORG&gt;
08/17/02 12:26PM &gt;&gt;</A> <BR></DIV>
<DIV>Windows2000 with 4.83 SP1, MS Client active and the workstation is a member
of the local domain NORTH. We access NT4-based apps in the SASI domain housed at
our district office. <BR><BR>Browsing My Network Places sometimes displays only
the NORTH domain; others all the NT domains in the district. <BR>A ZEN app
object that points to the NT-based app will sometimes work or will fail with
"access denied." However, on the failure, "sometimes" you can browse to the app
and launch it OR doing a START:RUN and then \\sasi332\ (the domain server on
which the NT app resides) will open the sasi332 desktop and you can then browse
by opening the folders. Eventually, you can launch the app. <BR><BR>The problem
is the inconsistency - the district support folks are talking about some sort of
conflict with Windows95 desktops (we still have a few) and/or IP protocal
preferences on the desktop or ??? <BR><BR>Does this make sense to anyone because
it doesn't to me. <BR></DIV></BODY></HTML>


[Attachment #4 (.)]
Date:    Mon, 19 Aug 2002 09:52:48 -0400
From:    John Hanna <John@COASTAL.EDU>
Subject: Re: JRBImport - I am so screwed! (An idiot too...)

First hand experience for me.. John Responded to me even while on a long
weekend trip to the states.  Sent me a copy of the jrbimprt utility until I
received the CD. Was having trouble with processing the business credit
card, so I couldn't download immediately, but John was very accommodating.

>-----Original Message-----
>From: Novell LAN Interest Group [mailto:NOVELL@LSV.SYR.EDU]On Behalf Of
>Baird, John
>Sent: Sunday, August 18, 2002 10:43 PM
>To: NOVELL@LSV.SYR.EDU
>Subject: Re: JRBImport - I am so screwed! (An idiot too...)
>
>
>> False alarm, never mind, sorry for the bandwidth waste. I just found the
>> correct zip file.
>>
>> Ghod, I never thought I'd be that close to heart failure...
>
>You will get a response from me within 24 hours regardless of the day
>of the week, most days of the year. That doesn't mean I dont
>take holidays, just that I check for emails regardless ..
>
>John
>

------------------------------

Date:    Mon, 19 Aug 2002 10:01:23 -0500
From:    Gerry VanLoh <vanloh@OLE.AUGIE.EDU>
Subject: Migration Wizard trustee rights restore abends

We're in the middle of migrating a Netware 6 sp1 server to new hardware,
same NW6 SP1, etc.  Did an across the wire migration with the wizard and
it went reasonably well until the last phase.  It looks like the schema
and volume objects are ok and work normally but the trustee rights
restoration cannot complete on one of the 4 volumes without abending the
server.  3 of the 4 volumes seem to have gone ok but the 4th one is a
user volume with about 3000 user folders on it.  I've restarted the
restoration of trustee rights to that volume several times but the
server abends with:

Server TUCKER halted Monday, August 19, 2002   8:09:07 am
Abend 2 on P00: Server-5.60b-4348: Kernel detected an attempted context
switch when it was not allowed.

This is a single processor server but has dual capabilities (Compaq
DL380) and support had been loaded for that but has been removed.

The migration wizard error log shows nothing other than there was an
error caused by a Netware API losing connection - because the server has
abended at that point - nearly immediately in the process.

Anyone run into these types of problems or have ideas?  I've run
dsrepair full and also volume and trustee checks which show normal and
eDir seems to be all running fine in the tree.

I can supply full abend log.  Looking for directions at this point. ;-)

Thanks
Gerry  vanloh@augie.edu
Augustana College
Sioux Falls, SD

------------------------------

Date:    Mon, 19 Aug 2002 08:22:08 -0400
From:    Steve Klemetti <sklemetti@SOFTHOME.NET>
Subject: Re: Iprint problems

Joe Doupnik wrote:

> >We've been having problems with Iprint.
> >
> >It works but then it crashes when certain print jobs from certain
> >applications are sent,
> >but not every print job from that application.
> >
> >Spool32.exe crashes on mscvrtl.dll
> >
> >we are using Lexmark Optra S printers.
> ----------
>         First check should be to see if it is related to iPrint by
> printing to another place (even to a file). Second check is for proper
> printer drivers, and Lexmark is the supplier of them. They would go
> onto the server for delivery to clients upon demand. If these two
> pass muster then we worry about iPrint.

Printing to Queues serviced by the NDPS printers that service Iprint work
fine in
all applications.  But using applications such as Adobe Acrobat and
printing
through Iprint crashes the workstation.

------------------------------

Date:    Mon, 19 Aug 2002 11:47:48 -0700
From:    Joe Doupnik <JRD@CC.USU.EDU>
Subject: Re: Iprint problems

>> >We've been having problems with Iprint.
>> >
>> >It works but then it crashes when certain print jobs from certain
>> >applications are sent,
>> >but not every print job from that application.
>> >
>> >Spool32.exe crashes on mscvrtl.dll
>> >
>> >we are using Lexmark Optra S printers.
>> ----------
>>         First check should be to see if it is related to iPrint by
>> printing to another place (even to a file). Second check is for proper
>> printer drivers, and Lexmark is the supplier of them. They would go
>> onto the server for delivery to clients upon demand. If these two
>> pass muster then we worry about iPrint.
>
>Printing to Queues serviced by the NDPS printers that service Iprint work
>fine in
>all applications.  But using applications such as Adobe Acrobat and
>printing
>through Iprint crashes the workstation.
-----------
        Again, I think the problem is too muddled to point fingers anywhere.
Please try some decisive experiments. And check that Windows has the IPP
software from NW 6 and that one can print normal documents through that
particular pathway. Acrobat is an especially awkward program, so try
printing to a file first, just to see what happens.
        Joe D.

------------------------------

Date:    Mon, 19 Aug 2002 20:08:40 +0200
From:    Erik Thiele <erikyyy@ERIKYYY.DE>
Subject: my experiences :)

Hi!

I recently posted to this list and asked for possibilities to let
netware 4.11 SFT III automatically reboot at 3 o'clock in the night,
and how to make it start without entering "activate server".

shutting down is now done with cron. (down,remove dos,exit) thanks to
whoever posted me the answer on this list!

booting works without "activate server", because i managed to remove
SFT III. i read in a TID about the issue. again thanks to whoever
posted me that idea on this list!

backing up the server works very great now. every midnight it shuts
down, boots from network, does a bit by bit harddisk image backup and
restarts netware.

but there ist a problem with the license now. there was the SFT III
license installed and i am running without SFT III now. the server now
still has the 50 connection limit, but it has serial number
00000001. and the "VERSION" command shows no installed licenses. our
KHK server process (KHKSRV4A.NLM, KHK Classic Line 97) denies work,
due to invalid PIN. the PIN only works with the correct serial
number. we have a PIN for our SFT III license disc and a PIN for our
normal license (no SFT III). but the problem is the server now has
serial number 00000001 for which we have no PIN.

so i loaded INSTALL.NLM and tried to install the normal non-SFT III
license disc. it said there already was another license installed. i
tried the SFT III license disc, and it just popped away the window,
without showing some useful message. then i removed the license which
downgraded the server to a 2 connection license. instantly the people
came to me and wanted to kill me, because all of them have been
knocked out the server! so i tried to install any license, but the
INSTALL.NLM told me it cannot install the license due to a "Server
Connection Error". Rebooting the server didn't help. Lucky me i had
the backups of midnight before and rebuilt another server which is
working now. the rest of the day was wasted for manually taking back
the work that was done today.

OK. tomorrow i'll do a fresh installation of Netware 4.11 without SFT
III. then i'll copy the files and manually adjust the trustees :-((
I'll install the license disc and return KHK to work. if KHK won't
work I'll start to get real angry against all that proprietary
software which you cannot debug, cannot read the source and cannot fix
the damn problems!!

cu
erik

--
Name:  Erik Thiele                                        \\\\
Email: erikyyy@erikyyy.de                                 o `QQ'_
WWW:   http://www.erikyyy.de/                              /   __8
                                                           '  `

------------------------------

Date:    Mon, 19 Aug 2002 13:42:15 -0500
From:    Skip Hefel <skiphefel@ADVANCED-DATA.COM>
Subject: FTP NWFTPD v5.02r passive connections

I'm running NW5.1 server SP4, eDir 8527c running FTP v5.02r services. After
migrating over from the old NW5.0 unix based ftp service, On my new FTP
server, I have one client out of 40+ clients that is receiving "timeout,
unable to connect successfully ", and "server closed connection"

1. They have mentioned that it seems that maybe my FTP server's service is
attempting a Reverse DNS lookup or attempting to PING the IP of the client.
Therefore  getting the timeout of server closed connection.

2. One of the Client's employees at his home computer was able to connect
and down load files. He then implemented a high security level on his home
firewall and thus got the same problem.

3. I Have another server in our Superior, Wi. running the same NWFTPD
version, (on a NCS( novell cluster services) 1.01) Both FIREWALLS exactly
the same setup.
 Crazy thing is it works there, but not here.

The only thing I could see was the NAT Implicit Filtering was enabled on the
server in Superior, so I will enable it here to check it out.

In the NW5.1 Documentation, in the FTP service, it mentions setting the
Passive mode data transfer and also allowing for configuring a range of
passive data ports when the client is behind a firewall.
The TWO settings are:
        Parameter                       Setting
1. PASSIVE_PORT_MIN               1
2. PASSIVE_PORT_MAX             65534

Anyone deal with this before?

------------------------------

Date:    Mon, 19 Aug 2002 13:44:42 -0700
From:    Joe Doupnik <JRD@CC.USU.EDU>
Subject: Re: FTP NWFTPD v5.02r passive connections

>In the NW5.1 Documentation, in the FTP service, it mentions setting the
>Passive mode data transfer and also allowing for configuring a range of
>passive data ports when the client is behind a firewall.
>The TWO settings are:
>        Parameter                       Setting
>1. PASSIVE_PORT_MIN               1
>2. PASSIVE_PORT_MAX             65534
>
>Anyone deal with this before?
-----------
        Never use port numbers below 1023 for by guess and by golly work.
Those are allocated for systems daemons, well known ports.
        There are a couple of Italian ISPs whose broken ftp clients keep
asking for connections to their port 0, and my ftp server says rejected.
        To see what happens, it is best to observe the wire of the client
and perhaps the server. There are plenty of free packet snoop programs,
such as ethereal (www.ethereal.org) as one example.
        Joe D.

------------------------------

Date:    Mon, 19 Aug 2002 15:32:58 -0500
From:    Joe Serrone <jserrone@UHS.EDU>
Subject: Compaq ML370 G2 - 4gb Ram?

Has anyone had any issues or problems with a Compaq ML370 G2 server
using 4gb of RAM with Netware 5.1 SP3 or SP4...We are experiencing
reboots and lockups when using 4gb of RAM in this server but the box
seems to stabilize if we only use 2gb of RAM...

Just wondering if anyone else has experienced these issues.

Joe Serrone
Systems Manager
University of Health Sciences
1750 Independence Avenue
Kansas City, MO  64106-1453
Phone: 816.283.2472
Fax: 816.283.0692
E-mail: jserrone@uhs.edu

------------------------------

Date:    Mon, 19 Aug 2002 17:27:23 -0500
From:    Matthew Jeppsen <mjeppsen@TIGER.NWSC.K12.AR.US>
Subject: Jrbimprt - difficulty using "Login Disabled" directive

Attempting to use jrbimprt to disable multiple user accounts. When I run
the import, the log file looks good. However, checking in NWADMIN show
that the accounts are still enabled.
I am using u (Update) mode, and the last field in my control file is
named "Login disabled". See below for details on the control file.
The last column in the data file contains a "Y".

Log:
--snip relevant portion of log---
abshierashton: Attribute "Login Disabled" has been set
--snip---

Data file:
--snip--
Ashton
Abshier,Ashton,Abshier,abshierashton,password,abshierashton@tiger.nwsc.k
12.ar.us,Y
--snip--

I'm probably doing something wrong, so any suggestions will be much
appreciated.

Matt Jeppsen
Technology Coordinator
Prairie Grove School District

The following is the contents of my import control file:
--snip--
Import control

        Separator=,

        Name context=school.prairie_grove

        Delete attribute = #delete

;       Delete home directory=n

;       Delete on name mismatch=n

;       Delete on rights mismatch=n

        Delete property = #delete

        Template=2008

        Home directory volume=PG-STOR_SYS.Prairie_grove

        Home directory path=students\2008

        Create home directory=Y

        Home directory restriction=102400

;       Import mode=r

        Import mode=u

;       Import mode=c

Fields

        Full name

        Given name

        Last name

        Login name

        Password

        Internet email address

        Login Disabled
--snip--

------------------------------

Date:    Mon, 19 Aug 2002 19:07:40 -0400
From:    HB <hbueno@OPTONLINE.NET>
Subject: Re: FTP NWFTPD v5.02r passive connections

I did.  In our case, the problem was our Checkpoint Firewall-1.  The
firewall has some sort of feature that checks for carriage returns and
line feeds during FTP.  I disabled checking and now FTP works through
the firewall using passive FTP.

 From my experience, the Novell FTP server is capable of both passive
and active FTP automatically.  For passive mode FTP, it allows you to
define the ports the server tells the client to use.  I would recommend
a narrow range above 1023.  I think I set ours up to use 34000-34100.
 From the same subnet as our FTP server, I can do both active and
passive FTP.  Across the firewall, I can only do passive.

On clustering servers, I think the terms passive and active are used as
well, but in that case that's specifically for clustering features, not
FTP methods.

Hugo


Skip Hefel wrote:
> I'm running NW5.1 server SP4, eDir 8527c running FTP v5.02r services. After
> migrating over from the old NW5.0 unix based ftp service, On my new FTP
> server, I have one client out of 40+ clients that is receiving "timeout,
> unable to connect successfully ", and "server closed connection"
>
> 1. They have mentioned that it seems that maybe my FTP server's service is
> attempting a Reverse DNS lookup or attempting to PING the IP of the client.
> Therefore  getting the timeout of server closed connection.
>
> 2. One of the Client's employees at his home computer was able to connect
> and down load files. He then implemented a high security level on his home
> firewall and thus got the same problem.
>
> 3. I Have another server in our Superior, Wi. running the same NWFTPD
> version, (on a NCS( novell cluster services) 1.01) Both FIREWALLS exactly
> the same setup.
>  Crazy thing is it works there, but not here.
>
> The only thing I could see was the NAT Implicit Filtering was enabled on the
> server in Superior, so I will enable it here to check it out.
>
> In the NW5.1 Documentation, in the FTP service, it mentions setting the
> Passive mode data transfer and also allowing for configuring a range of
> passive data ports when the client is behind a firewall.
> The TWO settings are:
>         Parameter                       Setting
> 1. PASSIVE_PORT_MIN               1
> 2. PASSIVE_PORT_MAX             65534
>
> Anyone deal with this before?
>

------------------------------

Date:    Mon, 19 Aug 2002 19:20:08 -0500
From:    Lowry Wilson <lwilso@NETDOOR.COM>
Subject: Novastor Backup Software

This is a multi-part message in MIME format.


Is anyone using the Novastor (Novanet) backup software?  I am looking for a solution \
that is cross-platform compatible and will allow backup to a tape or NAS.  This seems \
to be a viable option.  

LP


[Attachment #7 (text/html)]

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META http-equiv=Content-Type content="text/html; charset=iso-8859-1">
<META content="MSHTML 5.50.4522.1800" name=GENERATOR>
<STYLE></STYLE>
</HEAD>
<BODY bgColor=#ffffff>
<DIV><FONT face=Arial size=2>Is anyone using the Novastor (Novanet) backup 
software?&nbsp; I am looking for a solution that is cross-platform compatible 
and will allow backup to a tape or NAS.&nbsp; This seems to be a viable 
option.&nbsp; </FONT></DIV>
<DIV><FONT face=Arial size=2></FONT>&nbsp;</DIV>
<DIV><FONT face=Arial size=2>LP</FONT></DIV></BODY></HTML>

------------------------------

Date:    Tue, 20 Aug 2002 15:45:21 +1200
From:    "Baird, John" <Baird2@TUI.LINCOLN.AC.NZ>
Subject: Re: Jrbimprt - difficulty using "Login Disabled" directive

> Attempting to use jrbimprt to disable multiple user accounts. When I run the
> import, the log file looks good. However, checking in NWADMIN show that the
> accounts are still enabled. I am using u (Update) mode, and the last field
> in my control file is named "Login disabled". See below for details on the
> control file. The last column in the data file contains a "Y".

Please send problem reports direct to me.

As attributes from a template are by default set after the attributes
in the "Fields" list, I suspect that the template has a "Login
Disabled" attribute set to "N".

John

------------------------------

End of NOVELL Digest - 18 Aug 2002 to 19 Aug 2002 (#2002-352)
*************************************************************


[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic