Closed Bug 497422 Opened 15 years ago Closed 15 years ago

a few firewall changes for try-win32-slave05

Categories

(mozilla.org Graveyard :: Server Operations, task)

x86
Windows Server 2003
task
Not set
major

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: bhearsum, Assigned: dmoore)

References

Details

As part of the OPSI rollout in bug 495948 we need to get the try slaves talking to the staging-opsi/production-opsi VMs. Can you please allow the following ports (both ways) between try-win32-slave05 and staging-opsi.build.mozilla.org? Before we go to the trouble of changing it for everything I want to make sure I've got everything covered.

Here they are:
ports 137-139 tcp/udp
port 445 tcp
port 901 tcp
port 4447 tcp
How quickly can this be done? I ask because this blocks us rolling out of OPSI onto the try slaves, and hence the java update to those slaves. This means try slaves are currently different to production slaves, and different test results, which is not good. 

Sorry for the last minute rush here, we should have thought of this before, but we dropped the ball.
OS: Mac OS X → Windows Server 2003
Severity: normal → major
Assignee: server-ops → dmoore
Configured as requested, please test and verify. Feel free to reopen the bug if additional changes are necessary.
Status: NEW → RESOLVED
Closed: 15 years ago
Resolution: --- → FIXED
I missed at least one port. Can you open up 69/udp between those hosts, too?
Status: RESOLVED → REOPENED
Resolution: FIXED → ---
69/udp added
Status: REOPENED → RESOLVED
Closed: 15 years ago15 years ago
Resolution: --- → FIXED
dmoore and I figured out exactly what we needed over irc. Let's go ahead and do this for the rest of the try slaves:
Specifically, between try-w32-slave01 -> 04 and 06 -> 19 we need the following allowed:
ports 137-139 tcp/udp
port 445 tcp
port 901 tcp
port 4447 tcp
icmp ping

thanks a bunch!
Status: RESOLVED → REOPENED
Resolution: FIXED → ---
Identical access granted for slave01 -> slave19
Status: REOPENED → RESOLVED
Closed: 15 years ago15 years ago
Resolution: --- → FIXED
Thanks derek, mrz. We'll plan this better next time, to avoid last-minute-rush-jobs like this.
(I can't believe I have to reopen this bug again, sigh.)

I forgot to mention that the other slaves need these ports opened between them and *production*-opsi.build.mozilla.org

I'm really sorry for all the churn I'm causing with this.
Status: RESOLVED → REOPENED
Resolution: FIXED → ---
Not a problem, identical access has been granted to production-opsi.build for all slaves.
Status: REOPENED → RESOLVED
Closed: 15 years ago15 years ago
Resolution: --- → FIXED
Product: mozilla.org → mozilla.org Graveyard
You need to log in before you can comment on or make changes to this bug.