Bluehost.com Web Hosting $6.95

[Samba] Re: Slow "run as ...", firewall issues.

This is a discussion on [Samba] Re: Slow "run as ...", firewall issues. within the Samba forums, part of the Networking and Network Related category; Update... > So I changed the rules to: > > REJECT tcp -- xxx.xxx.xxx.xxx yyy.yyy.yyy.yyy ...


Go Back   Usenet Forums > Networking and Network Related > Samba

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 09-23-2008
David Mathog
 
Posts: n/a
Default [Samba] Re: Slow "run as ...", firewall issues.

Update...

> So I changed the rules to:
>
> REJECT tcp -- xxx.xxx.xxx.xxx yyy.yyy.yyy.yyy tcp
> dpts:137:139 reject-with icmp-port-unreachable
> REJECT udp -- xxx.xxx.xxx.xxx yyy.yyy.yyy.yyy udp
> dpts:137:139 reject-with icmp-port-unreachable
>
> And "run as..." was fast again.


Except, after several hours, it was slow again! I believe there was
some issue with the Samba server retaining netbios names after the
REJECT is set, but then it eventually loses those due to the REJECT.
Once that happens "run as..." is once again slow, even though ports
137-139 are still REJECTing connections from the client machine.
This is a complex interaction, with what appears to be stored values
timing out - because restarting Samba may be needed to fix it (quickly)
even if the server has the firewall shut off. Rather than experimenting
with further firewall rules for the campus Winbind servers (I think) I
gave up and once again set ports 137-139 to ACCEPT for on campus
machines. Note that that alone did not immediately speed up "run
as...", but a subsequent restart of samba did, and it is still fast 14
hours later.

If one of the Samba developers could explain this messy interaction it
would be greatly appreciated.

Thank you,

David Mathog
mathog@caltech.edu
Manager, Sequence Analysis Facility, Biology Division, Caltech
--
To unsubscribe from this list go to the following URL and read the
instructions: https://lists.samba.org/mailman/listinfo/samba

Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT +1. The time now is 02:11 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0