9fans - fans of the OS Plan 9 from Bell Labs
 help / color / mirror / Atom feed
* Re: [9fans] Plan 9 system behind firewall
@ 2008-03-25  1:27 erik quanstrom
  0 siblings, 0 replies; 6+ messages in thread
From: erik quanstrom @ 2008-03-25  1:27 UTC (permalink / raw)
  To: kokamoto, 9fans

> I have two sets of Plan 9 system within different IP domain, one of which
> is sitting behind the firewall made by a brordband router and using fossil+venti+
> auth/cpu server and terminals(Plan 9-1).
> Another is using Ken's fs, standalone auth server, cpu server, and terminals
> (Plan 9-2).
[...]
> Lastly, I tried to login to the Plan 9-1 system behind the firewall from the above
> Plan 9-2 system, and now I have problem.   When I booted the Plan 9 kernel from
> floppy drive (the kernel was read from the Plan 9-2 standalone auth server),
> I had to wait 5 minutes until some response from the Plan 9-1
> auth server behind the firewall.  It asked password, and I typed it, then,
> I can reach the CPU server, not the Plan 9 system.  I suppose this is same as
> cpu command, and then, I have no display for rio.   ---fact 4

are Plan9-1 and Plan9-2 in different authentication domains?  if they
are not, this could explain fact 4.  you would have two auth servers serving
the same authentication domain.   this would explain how cpu could work
when a direct login does not if you also have trouble contacting the remote
authentication server but not the local one.  this would allow plan 9 to know
about the local auth server when drawterm may not.

the long timeouts are sound like dns lookup problems to me.  i generally
double-check my ndb entries in cases like this, especially the auth, ip, and
ipnet entries associated with the auth server.

	- erik


^ permalink raw reply	[flat|nested] 6+ messages in thread
* [9fans] Plan 9 system behind firewall
@ 2008-03-24 11:50 kokamoto
  2008-03-26  9:46 ` Richard Miller
  0 siblings, 1 reply; 6+ messages in thread
From: kokamoto @ 2008-03-24 11:50 UTC (permalink / raw)
  To: 9fans

I have two sets of Plan 9 system within different IP domain, one of which
is sitting behind the firewall made by a brordband router and using fossil+venti+
auth/cpu server and terminals(Plan 9-1).
Another is using Ken's fs, standalone auth server, cpu server, and terminals
(Plan 9-2).

When I use drawtrerm for Wn XP (belong th the same domain as Plan9-2),
it does work fine by such the command as drawterm -a 'IP of auth server'
-c 'IP of cpu server(=auth server)'.  It's fine, no excess time are neccessary,
just done within 30 seconds.   ---fact 1

Then, I tried drawterm for linux (newest stable Debian actually) as the same
command also from the outside of the Plan 9-1 domain.   In this case,
I have to wait 3 to 4 minutes until loging in the cpu server behind the firewall.   ---fact 2

Then, I tried to use the Plan 9-1 system from another Plan 9-2 system I have.
First, I made 9fs from a terminal of Plan 9-2 to the cpu server of the Plan 9-2,
and got good success.
This was done also withing 30 seconds.
I have a line of
auth='machine name of the broadband router' authdom='auth domain of that
Plan 9 system behind the router'
in /lib/ndb/local file on the Plan 9-2 system.   ---fact 3

Lastly, I tried to login to the Plan 9-1 system behind the firewall from the above
Plan 9-2 system, and now I have problem.   When I booted the Plan 9 kernel from
floppy drive (the kernel was read from the Plan 9-2 standalone auth server),
I had to wait 5 minutes until some response from the Plan 9-1
auth server behind the firewall.  It asked password, and I typed it, then,
I can reach the CPU server, not the Plan 9 system.  I suppose this is same as
cpu command, and then, I have no display for rio.   ---fact 4

questions:

Why I can 9fs but not login?
Why such a long time were necceessary for Linux and Plan9
to get factotum responce?
What is different between drawterm and ordinal login mechanism?

Thanks in advance,

Kenji  --now in big confusion



^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2008-03-28 11:25 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2008-03-25  1:27 [9fans] Plan 9 system behind firewall erik quanstrom
  -- strict thread matches above, loose matches on Subject: below --
2008-03-24 11:50 kokamoto
2008-03-26  9:46 ` Richard Miller
2008-03-26 11:19   ` kokamoto
2008-03-26 15:33     ` john
2008-03-28 11:25     ` kokamoto

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).