Astaro User Bulletin Board
Go Back   Astaro User Bulletin Board > Astaro Gateway Products > Network Security: Firewall, NAT, QoS, IPS and more

Welcome to the Astaro User Bulletin Board.
If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 06-23-2009, 08:20 PM
Junior Member
 
Join Date: Sep 2006
Posts: 27
Default HP ILO not working from the world

I upgraded to a new ASG120 box with V7.4 and thought I set up all my nats and filters okay but maybe Im missing something.

I cannot get HP's Integrated Lights Out remote console to work properly. The ILO address is its own address on the webserver. I also have a specific additional public IP on the Astaro for ILO. I NAT from one externally to the other internally. Right now I have ANY port open for this NAT in order to troubleshoot it, with auto packet filter selected.

I get to the ILO login screen fine and can authenticate fine, but when in the ILO control panel every time I try to fire up the Remote Console, the Java just hangs and the emulation screen never renders.

Ive successfully tested from inside the network and ILO remote console fires up fine. So something is not being passed properly when out to the world. Not sure why since I have it on ANY at the moment. And, if I get to the ILO login web page using ANY and login ok, you'd think the remote console java wold run too.

Any ideas?
Reply With Quote
  #2 (permalink)  
Old 06-23-2009, 08:37 PM
Moderator
 
Join Date: Jul 2001
Location: southern California
Posts: 4,928
Default

That's funny; I'm having the same problem, but only with my DL165 servers; the DL365's with ILO2 work fine. I assumed it was a problem with the servers...

I'd recommend starting by checking the packetfilter and IPS logs.

Barry
__________________
http://DealBert.net
Home & business end-user since v1.x
  • ASL 6.3x, HP DL145 Dual Opteron, 1GB RAM, 6 gigE NICs, 50-IP Platinum License
  • ASL 7.3x, Dell PE1550 Dual PIII 1GHz, 1GB RAM, 2 NICs, 50-IP Platinum License
  • ASL 7.501, 17-watt fanless mini-ITX system: MSI IM-945GSE-A Atom n270, 2GB RAM, Morex T3310 case. 2 Intel GigE, 3 VLANs. 80G 5200rpm 2.5" HD
    Netgear GS108T gigE VLAN switch & Linksys WRT54G WAP
    Total network infrastructure: 27 watts. 100-IP Home User. FiOS 10mb/2mb
Reply With Quote
  #3 (permalink)  
Old 06-23-2009, 09:46 PM
Wizard
 
Join Date: Oct 2005
Posts: 2,359
Default

This is interesting; whilst I wouldn't expose ILO to the public internet, it should work nonetheless... in addition to the IPS and Packetfilter logs, check the IM/P2P logs as well (if you have those features enabled)... sometimes the IM/P2P filter falsely detects traffic and blocks it. Failing that, I'd probably start a case with Astaro.
__________________
Convergent Information Security Solutions, LLC
Astaro Preferred Solution Partner
Reply With Quote
  #4 (permalink)  
Old 06-23-2009, 11:54 PM
Moderator
 
Join Date: Jul 2001
Location: southern California
Posts: 4,928
Default

I've been trying it over a VPN... still not working, and nothing in either PF nor IPS log.
tcpdump shows traffic flowing both ways.

I'm not sure this is an Astaro problem; it could be that the ILO doesn't have the gateway right or something.

FWIW, I've also previously found cabling problems where the NIC worked fine but the ILO didn't, when sharing the port. Changing the cable fixed the problem, but has not helped remote access.

Barry
__________________
http://DealBert.net
Home & business end-user since v1.x
  • ASL 6.3x, HP DL145 Dual Opteron, 1GB RAM, 6 gigE NICs, 50-IP Platinum License
  • ASL 7.3x, Dell PE1550 Dual PIII 1GHz, 1GB RAM, 2 NICs, 50-IP Platinum License
  • ASL 7.501, 17-watt fanless mini-ITX system: MSI IM-945GSE-A Atom n270, 2GB RAM, Morex T3310 case. 2 Intel GigE, 3 VLANs. 80G 5200rpm 2.5" HD
    Netgear GS108T gigE VLAN switch & Linksys WRT54G WAP
    Total network infrastructure: 27 watts. 100-IP Home User. FiOS 10mb/2mb
Reply With Quote
  #5 (permalink)  
Old 06-24-2009, 12:18 AM
BAlfson's Avatar
Moderator
 
Join Date: Mar 2007
Location: Oklahoma City
Posts: 4,954
Default

Barry, can you VPN/RDP to your local desktop and do it from there?
__________________
ACE V7 - Astaro Preferred Partner since V3
Addicted to my iPhone!
Reply With Quote
  #6 (permalink)  
Old 06-24-2009, 02:03 AM
Moderator
 
Join Date: Jul 2001
Location: southern California
Posts: 4,928
Default

Hi Bob,
The servers are at a co-lo, so there's no local desktop, but iirc, they did work locally on my laptop when I was setting up the co-lo.

Since the ILO needs JS I can't use lynx to connect locally either.

Barry
__________________
http://DealBert.net
Home & business end-user since v1.x
  • ASL 6.3x, HP DL145 Dual Opteron, 1GB RAM, 6 gigE NICs, 50-IP Platinum License
  • ASL 7.3x, Dell PE1550 Dual PIII 1GHz, 1GB RAM, 2 NICs, 50-IP Platinum License
  • ASL 7.501, 17-watt fanless mini-ITX system: MSI IM-945GSE-A Atom n270, 2GB RAM, Morex T3310 case. 2 Intel GigE, 3 VLANs. 80G 5200rpm 2.5" HD
    Netgear GS108T gigE VLAN switch & Linksys WRT54G WAP
    Total network infrastructure: 27 watts. 100-IP Home User. FiOS 10mb/2mb
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 02:02 PM.

 

Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.


These pages are specifically maintained for the discussion of firewall issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases. issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases.