[suse-sles-e] Problem with network and FW

From: Stefan Jakobs (stefan.jakobs_at_rus.uni-stuttgart.de)
Date: Wed Jun 07 2006 - 18:22:27 CEST


From: Stefan Jakobs <stefan.jakobs@rus.uni-stuttgart.de>
Date: Wed, 7 Jun 2006 18:22:27 +0200
Message-Id: <200606071822.27747.stefan.jakobs@rus.uni-stuttgart.de>
Subject: [suse-sles-e] Problem with network and FW

Hello list,

I'm using SLES9 with bonding on two interfaces. The Server was in production
and worked fine, till I rebooted yesterday.
After the reboot the server hangs and all what I see is the output from the
firewall on the terminal. Something like that:

Jun 7 00:01:05 testserv kernel: SFW2-INext-ACC-TCP IN=bond0
OUT=MAC=00:07:e9:24:1d:1c:00:07:84:a2:1a:ca:08:00 SRC=XXX.XXX.XXX.XXX
DST=XXX.XXX.XXX.XXX LEN=48 TOS=0x00 PREC=0x00 TTL=116 ID=14712 DF PROTO=TCP
SPT=4245 DPT=25 WINDOW=65535 RES=0x00 SYN URGP=0 OPT (020405B401010402)

If I start the server without Firewall (init,setup, final off), then the
server will start proper, but the network isn't working. A "rcnetwork restart"
repairs that.

If I start the server with firewall on, but no networkcable plugged in, then
it will start also.

Here is the boot.msg logfile:

#################################################################
##<snip>
<notice>run boot scripts (boot.sched boot.localnet boot.isapnp boot.cycle)
Setting scheduling timeslices unused
Setting up hostname 'testserv'done
Setting up loopback interface lo
    lo IP address: 127.0.0.1/8
done
<notice>exit status of (boot.sched boot.localnet boot.isapnp boot.cycle) is (6
0 0 6)
<notice>run boot scripts (boot.klog boot.ipconfig)
Enabling syn flood protectiondone
Disabling IP forwardingdone
done
Creating /var/log/boot.msg
done<notice>killproc: kill(2428,29)
System Boot Control: The system has been set up
Skipped features: boot.sched boot.cycle
System Boot Control: Running /etc/init.d/boot.local
done<notice>exit status of (boot.klog boot.ipconfig) is (0 0)
<notice>killproc: kill(2428,3)

INIT: Entering runlevel: 3

<notice>start services (random
Boot logging started on /dev/ttyS1(/dev/console) at Wed Jun 7 17:54:21 2006

Master Resource Control: previous runlevel: N, switching to runlevel: 3
Initializing random number generatordone
 coldplug SuSEfirewall2_init)
coldplug scanning input: *done
         scanning pci: *W*W****.*WW*W****done
         scanning usb: done
         . . . . . . . . . . . . . . . . . . . . . . . .done
Starting Firewall Initialization (phase 1 of 3) done
<notice>exit status of (random coldplug SuSEfirewall2_init) is (0 0 0)
<notice>start services (network)
Setting up network interfaces:
    lo
    lo IP address: 127.0.0.1/8

 Warning: interface eth1 is not (yet?) active.
 Warning: interface eth0 is not (yet?) active.
 Warning: interface bond0 is not (yet?) active.
 Warning: No interface active (yet?)done eth0 device: Intel
Corporation 82546EB
Gigabit Ethernet Controller (Copper) (rev 01)
    eth0 No configuration found for eth0
unused eth1 device: Intel Corporation 82546EB Gigabit Ethernet
Controller (Coppe
r) (rev 01)
    eth1 No configuration found for eth1
unused

    bond0
    bond0 enslaving interfaces: eth0 eth1
    bond0 IP address: 192.168.1.56/24 as bonding master

Warning: interface eth-id-00:07:e9:24:1d:1d is not (yet?) active.doneSetting
up service
 network . . . . . . . . . . . . . . . .done
<notice>exit status of (network) is (0)
#####################################################################
## end

What I have done before the reboot:
- Kernel update (this wasn't the fault, I installed the old one already, but
nothing changed)
- cron update
- ocfs2 update
- cpio update
- Adding a rcScript, that runs "ifconfig bond0 add 192.168.11.23" at startup

I guess there is a problem with the bonding interface and the SuSEfirewall2,
but I have no idea how I can fix that.

Has somebody an advice, what I've done wrong?

Thanks for help.
Stefan

---------------------------------------------------------------------
To unsubscribe, e-mail: suse-sles-e-unsubscribe@suse.com
For additional commands, e-mail: suse-sles-e-help@suse.com



This archive was generated by hypermail 2.1.7 : Wed Jun 07 2006 - 18:22:39 CEST