Solved

Query on clustering and IP addresses

Posted on 2009-04-09
7
341 Views
Last Modified: 2012-05-06
Hi Forum,

I have installed a Windows 2008 2-node cluster for SMTP purposes.

Node1: 192.168.1.1
Node2: 192.168.1.2
Cluster1: 192.168.1.3

Cluster1 is the clustered address/hostname. All three are registered in DNS.

Applications on our network will be configured to use an SMTP server of: Cluster1 (or 192.168.1.3 if we need to specify an IP).

We have some ports of the network that are not accessible due a firewall being placed between that subnet and the rest. So, for example, Server1 in a restricted subnet needs to send SMTP mail. We'll need to open port 25, but to what destination, 192.168.1.1 and 192.168.1.2, or those AND 192.168.1.3, or just 192.168.1.3 only?

Thanks in advance.
0
Comment
Question by:kam_uk
  • 4
  • 2
7 Comments
 
LVL 6

Expert Comment

by:page1985
ID: 24110142
You should be able to open the firewall to point to the cluster address only being as the nodes in the cluster will listen on the cluster IP for all clustered traffic.
0
 
LVL 7

Expert Comment

by:dolomiti
ID: 24110193
hi,
I believe you need another name/address: the application one

node1, points to node1
node2, points to node3
cluster is just to manage it from you
Application1   192.168.1.4

Now you have to use cluster: build a resource group as Fileserver, SMTP, SQL server,...
and depending of type, give networkname,ipadress,resourcedisk,...
and inform users, firewall, dns, ecc about Application1 and/or  192.168.1.4

Then will be a problem of MSCS to run Applicatio01 on node1 or 2.

bye
vic
0
 
LVL 6

Expert Comment

by:page1985
ID: 24110219
This is true.  I was assuming you had already clustered the application and the IP was the application's cluster IP.
0
DevOps Toolchain Recommendations

Read this Gartner Research Note and discover how your IT organization can automate and optimize DevOps processes using a toolchain architecture.

 
LVL 3

Author Comment

by:kam_uk
ID: 24114388
Sorry guys - I should have mentioned, this is Windows 2008 NLB clustering I am using, not the hardware type clustering where you have resource groups, networkname etc
0
 
LVL 6

Accepted Solution

by:
page1985 earned 500 total points
ID: 24142180
The cluster address should still receive the traffic because if you send traffic to the node addresses one of two (or both) things will happen:
1) Only the node will receive the traffic
2) Neither node will receive the traffic because it's a Unicast cluster and the node addresses are management only.
0
 
LVL 3

Author Comment

by:kam_uk
ID: 24171187
Yep it's set up as a Unicast cluster.

So the only IP I need to open up on my firewall is the cluster address? Just to confirm :)
0
 
LVL 6

Expert Comment

by:page1985
ID: 24246918
Correct.  Only open the cluster address.
0

Featured Post

U.S. Department of Agriculture and Acronis Access

With the new era of mobile computing, smartphones and tablets, wireless communications and cloud services, the USDA sought to take advantage of a mobilized workforce and the blurring lines between personal and corporate computing resources.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

BIND is the most widely used Name Server. A Name Server is the one that translates a site name to it's IP address. There is a new bug in BIND (https://kb.isc.org/article/AA-01272), affecting all versions of BIND 9 from BIND 9.1.0 (inclusive) thro…
Resolve DNS query failed errors for Exchange
This tutorial will show how to push an installation of Backup Exec to an additional server in both 2012 and 2014 versions of the software. Click on the Backup Exec button in the upper left corner. From here, select Installation and Licensing, then I…
This tutorial will walk an individual through the steps necessary to enable the VMware\Hyper-V licensed feature of Backup Exec 2012. In addition, how to add a VMware server and configure a backup job. The first step is to acquire the necessary licen…

864 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

25 Experts available now in Live!

Get 1:1 Help Now