重庆思庄Oracle、、PostgreSQL、Redhat认证学习论坛

 找回密码
 注册

QQ登录

只需一步,快速开始

搜索
查看: 3964|回复: 0
打印 上一主题 下一主题

11g rac 下设置itables

[复制链接]
跳转到指定楼层
楼主
发表于 2013-10-7 16:48:24 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
Running iptables on a RAC
Hi there, it's been quite time ago since my last and only post on this site :-)
I should definitely make a blog and mantain it, if I never find the time.

Anyway, one frustrating things about Oracle RAC is that Oracle does not provide any support to implement a firewall on the nodes of a RAC cluster.
In some MOS document (notably RAC instabilities due to firewall (netfilter/iptables) enabled on the cluster interconnect [ID 554781.1]) it's simply stated that you should not run any cluster at all between the nodes.
Typical error on wrong firewall rules dropping interconnect traffic include the "IPC Send timeout detected" error in the db alert log, and can cause node eviction.

And what about iptables ?

You can put this rules on your INPUT chain to permit multicast traffic and trust all traffic from the interconnect interface(s) and the loopback:

iptables -A INPUT -m pkttype --pkt-type multicast -j ACCEPT
iptables -A INPUT -i lo -j ACCEPT
iptables -A INPUT -i eth1 -j ACCEPT


Here I'm assuming you're running the RAC interconnect on eth1.
分享到:  QQ好友和群QQ好友和群 QQ空间QQ空间 腾讯微博腾讯微博 腾讯朋友腾讯朋友
收藏收藏 支持支持 反对反对
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 注册

本版积分规则

QQ|手机版|小黑屋|重庆思庄Oracle、Redhat认证学习论坛 ( 渝ICP备12004239号-4 )

GMT+8, 2025-4-21 09:56 , Processed in 0.091977 second(s), 20 queries .

重庆思庄学习中心论坛-重庆思庄科技有限公司论坛

© 2001-2020

快速回复 返回顶部 返回列表