{"id":2884,"date":"2011-02-22T06:15:16","date_gmt":"2011-02-21T20:15:16","guid":{"rendered":"http:\/\/nsrd.info\/blog\/?p=2884"},"modified":"2018-12-11T18:18:48","modified_gmt":"2018-12-11T08:18:48","slug":"networker-firewall-configuration-on-windows","status":"publish","type":"post","link":"https:\/\/nsrd.info\/blog\/2011\/02\/22\/networker-firewall-configuration-on-windows\/","title":{"rendered":"NetWorker Firewall Configuration on Windows"},"content":{"rendered":"<p>I&#8217;ve been involved with an increasing number of NetWorker 7.6 SP1 configurations on Windows 2008 R2, and I&#8217;m not sure whether what I&#8217;ve encountered is specific to Windows 2008 R2 or just a general deficiency in the NetWorker installer&#8217;s firewall configuration process. Either way, since it caused some challenges for me, I wanted to note down the issues I&#8217;ve observed.<\/p>\n<p>First, the firewall configuration is only applied to the &#8220;Public&#8221; profile. This is OK for single-interface servers, but if your system has multiple interfaces, it isn&#8217;t sufficient \u2013 you need to edit the rules to apply to all three of &#8220;Domain&#8221;, &#8220;Private&#8221; and &#8220;Public&#8221;:<\/p>\n<p><a href=\"https:\/\/nsrd.info\/blog\/wp-content\/uploads\/2011\/02\/firewall1.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-2885\" title=\"Firewall configuration 1\" src=\"https:\/\/nsrd.info\/blog\/wp-content\/uploads\/2011\/02\/firewall1.jpg\" alt=\"Firewall configuration 1\" width=\"400\" height=\"528\" srcset=\"https:\/\/nsrd.info\/blog\/wp-content\/uploads\/2011\/02\/firewall1.jpg 400w, https:\/\/nsrd.info\/blog\/wp-content\/uploads\/2011\/02\/firewall1-227x300.jpg 227w\" sizes=\"auto, (max-width: 400px) 100vw, 400px\" \/><\/a><\/p>\n<p>The next issues encountered were relating to tape libraries on storage nodes. In particular, it appeared that the default automatic NetWorker firewall configuration on at least Windows 2008 R2 didn&#8217;t add support for the nsrmmgd or nsrlcpd daemons to communicate.<\/p>\n<p>To create these rules:<\/p>\n<ul>\n<li>On the server:\n<ul>\n<li>Copied two of the existing rules \u2013 one for TCP, one for UDP \u2013 and updated the &#8220;Programs and Services&#8221; pane to reference <em>X:pathtobinnsrmmgd.exe<\/em>.<\/li>\n<\/ul>\n<\/li>\n<li>On each storage node:\n<ul>\n<li>Copied two of the existing rules \u2013 one for TCP, one for UDP \u2013 and updated the &#8220;Programs and Services&#8221; pane to reference <em>X:pathtobinnsrlcpd.exe<\/em>.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>With these sets of changes in play, NetWorker has behaved a lot more normally.<\/p>\n<p>(Obviously, any firewall changes you make in your environment should be considered against site requirements.)<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I&#8217;ve been involved with an increasing number of NetWorker 7.6 SP1 configurations on Windows 2008 R2, and I&#8217;m not sure&hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[16,21,27],"tags":[80,386,665,672,1258,1107],"class_list":["post-2884","post","type-post","status-publish","format-standard","hentry","category-networker","category-security","category-windows","tag-7-6-sp1","tag-firewall","tag-nsrlcpd","tag-nsrmmgd","tag-windows","tag-windows-2008-r2"],"aioseo_notices":[],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_shortlink":"https:\/\/wp.me\/pKpIN-Kw","jetpack_sharing_enabled":true,"jetpack_likes_enabled":true,"_links":{"self":[{"href":"https:\/\/nsrd.info\/blog\/wp-json\/wp\/v2\/posts\/2884","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nsrd.info\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nsrd.info\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nsrd.info\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/nsrd.info\/blog\/wp-json\/wp\/v2\/comments?post=2884"}],"version-history":[{"count":1,"href":"https:\/\/nsrd.info\/blog\/wp-json\/wp\/v2\/posts\/2884\/revisions"}],"predecessor-version":[{"id":7525,"href":"https:\/\/nsrd.info\/blog\/wp-json\/wp\/v2\/posts\/2884\/revisions\/7525"}],"wp:attachment":[{"href":"https:\/\/nsrd.info\/blog\/wp-json\/wp\/v2\/media?parent=2884"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nsrd.info\/blog\/wp-json\/wp\/v2\/categories?post=2884"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nsrd.info\/blog\/wp-json\/wp\/v2\/tags?post=2884"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}