XCP-ng
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    NBD setup - No such item

    Scheduled Pinned Locked Moved Management
    43 Posts 3 Posters 5.7k Views 4 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Tristis OrisT Offline
      Tristis Oris Top contributor @florent
      last edited by

      @florent everything is default except NBD rule. looks similar.

      Chain INPUT (policy ACCEPT 0 packets, 0 bytes)
       pkts bytes target     prot opt in     out     source               destination
         16   960 xapi_nbd_input_chain  tcp  --  *      *       0.0.0.0/0            0.0.0.0/0            tcp dpt:10809
          0     0 ACCEPT     47   --  *      *       0.0.0.0/0            0.0.0.0/0
      9872M  155T RH-Firewall-1-INPUT  all  --  *      *       0.0.0.0/0            0.0.0.0/0
          0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0            tcp dpt:10809 /* NBD */
          0     0 ACCEPT     udp  --  *      *       0.0.0.0/0            0.0.0.0/0            udp dpt:10809 /* NBD */
      
      Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
       pkts bytes target     prot opt in     out     source               destination
          0     0 RH-Firewall-1-INPUT  all  --  *      *       0.0.0.0/0            0.0.0.0/0
      
      Chain OUTPUT (policy ACCEPT 22M packets, 34G bytes)
       pkts bytes target     prot opt in     out     source               destination
          0     0 xapi_nbd_output_chain  tcp  --  *      *       0.0.0.0/0            0.0.0.0/0            tcp spt:10809
          4   240 ACCEPT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0            tcp dpt:10809 /* NBD */
          0     0 ACCEPT     udp  --  *      *       0.0.0.0/0            0.0.0.0/0            udp dpt:10809 /* NBD */
      
      Chain RH-Firewall-1-INPUT (2 references)
       pkts bytes target     prot opt in     out     source               destination
       341M 9622G ACCEPT     all  --  lo     *       0.0.0.0/0            0.0.0.0/0
         29  5104 ACCEPT     icmp --  *      *       0.0.0.0/0            0.0.0.0/0            icmptype 255
          0     0 ACCEPT     udp  --  xenapi *       0.0.0.0/0            0.0.0.0/0            udp dpt:67
      9530M  146T ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0            ctstate RELATED,ESTABLISHED
          0     0 ACCEPT     udp  --  *      *       0.0.0.0/0            0.0.0.0/0            ctstate NEW udp dpt:694
          1    52 ACCEPT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0            ctstate NEW tcp dpt:22
      65232 3914K ACCEPT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0            ctstate NEW tcp dpt:80
       488K   29M ACCEPT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0            ctstate NEW tcp dpt:443
          0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0            tcp dpt:21064
          0     0 ACCEPT     udp  --  *      *       0.0.0.0/0            0.0.0.0/0            multiport dports 5404,5405
       588K 4800M REJECT     all  --  *      *       0.0.0.0/0            0.0.0.0/0            reject-with icmp-host-prohibited
      
      Chain xapi_nbd_input_chain (1 references)
       pkts bytes target     prot opt in     out     source               destination
          0     0 ACCEPT     all  --  xenbr0 *       0.0.0.0/0            0.0.0.0/0            ctstate NEW,ESTABLISHED
         16   960 REJECT     all  --  *      *       0.0.0.0/0            0.0.0.0/0            reject-with icmp-port-unreachable
      
      Chain xapi_nbd_output_chain (1 references)
       pkts bytes target     prot opt in     out     source               destination
          0     0 RETURN     all  --  *      xenbr0  0.0.0.0/0            0.0.0.0/0
          0     0 REJECT     all  --  *      *       0.0.0.0/0            0.0.0.0/0            reject-with icmp-port-unreachable
      
      Tristis OrisT 1 Reply Last reply Reply Quote 0
      • Tristis OrisT Offline
        Tristis Oris Top contributor @Tristis Oris
        last edited by

        after telnet request to 10809, rejected packages increased.

        Chain xapi_nbd_input_chain (1 references)
         pkts bytes target     prot opt in     out     source               destination
            0     0 ACCEPT     all  --  xenbr0 *       0.0.0.0/0            0.0.0.0/0            ctstate NEW,ESTABLISHED
           17  1020 REJECT     all  --  *      *       0.0.0.0/0            0.0.0.0/0            reject-with icmp-port-unreachable
        
        Tristis OrisT 1 Reply Last reply Reply Quote 0
        • Tristis OrisT Offline
          Tristis Oris Top contributor @Tristis Oris
          last edited by Tristis Oris

          if i have no errors during backup, it means XO didn't try to use NBD?

          but at begining of each NBD backup i got +1 to iptables rejected list.

          florentF 1 Reply Last reply Reply Quote 0
          • florentF Offline
            florent Vates 🪐 XO Team @Tristis Oris
            last edited by

            @Tristis-Oris said in NBD setup - No such item:

            but at begining of each NBD backup i got +1 to iptables rejected list.

            I think there is something with the network configuration, but I am far out of my element here .

            Tristis OrisT 1 Reply Last reply Reply Quote 0
            • Tristis OrisT Offline
              Tristis Oris Top contributor @florent
              last edited by

              @florent is it any requirements for network\switch etc. Any layers outside of Xen.

              florentF 1 Reply Last reply Reply Quote 0
              • florentF Offline
                florent Vates 🪐 XO Team @Tristis Oris
                last edited by

                @Tristis-Oris it hae to let the encrypted traffic flow through the 10809 port. XO will connect directly to the hosts through NBD, not only to the master

                Tristis OrisT 1 Reply Last reply Reply Quote 0
                • Tristis OrisT Offline
                  Tristis Oris Top contributor @florent
                  last edited by

                  @florent sounds pretty simple. Nothing at my network should block that traffic.

                  Anyway, if i got rejected packets at iptables - backup task try to connect NBD server. Then it can't do something, so i should get an error at XO, but it not happens.

                  1 Reply Last reply Reply Quote 0
                  • Tristis OrisT Offline
                    Tristis Oris Top contributor
                    last edited by

                    No such item task happens when host interface at status none without IP.

                    1 Reply Last reply Reply Quote 0
                    • Tristis OrisT Offline
                      Tristis Oris Top contributor
                      last edited by

                      @olivierlambert i hope your vacation WAS good, be we are stuck a bit here 😃

                      1 Reply Last reply Reply Quote 0
                      • Tristis OrisT Tristis Oris referenced this topic on
                      • Tristis OrisT Offline
                        Tristis Oris Top contributor
                        last edited by

                        bump 😞 😢

                        1 Reply Last reply Reply Quote 0
                        • olivierlambertO Online
                          olivierlambert Vates 🪐 Co-Founder CEO
                          last edited by

                          Re Ping @florent or @julien-f

                          1 Reply Last reply Reply Quote 0
                          • Tristis OrisT Offline
                            Tristis Oris Top contributor
                            last edited by Tristis Oris

                            once again i configured it on fresh, test cluster, and it working.
                            c512512c-aa9f-4feb-b76b-53060d1936bb-изображение.png

                            so it some problem with iptables on production. But it default, same 8.2.1 clean installation.

                            Both this hosts have only 1 connected link, so it both backup and management.
                            On prod i try empty default backup network, or NBD link network - no effect. So maybe it still going through managemnt link without NBD?

                            aaaaand enabled NBD on Mng link - now it working. SO yes, it ignore specified backup link.
                            Or this option didn't work, because NBD now enabled only on Mng link, so it can't go through backup link. 2a682bfd-5a39-4b8c-a2ee-27d88c821553-изображение.png

                            Tristis OrisT 1 Reply Last reply Reply Quote 0
                            • Tristis OrisT Offline
                              Tristis Oris Top contributor @Tristis Oris
                              last edited by Tristis Oris

                              next weird thing.
                              i enabled NBD on all manage interfaces at all pools.

                              d1f4630b-d98c-4f7a-a149-65ce236c7834-изображение.png
                              c268c78e-0499-4bfe-b2e4-b7d425096e65-изображение.png

                              it working with CR backup, but shouldn't, at least because it no option to enable NBD.

                              it working with half of other delta backup tasks, but not for all. Main backup is still without nbd.
                              7628f07d-d31f-43b3-b014-a68f13cd3b91-изображение.png
                              ef0f1305-b5ce-436a-94ad-43168d89a04e-изображение.png

                              only idea, it probably because of 1 small pool with few vm, where i forget to enable NBD. so 1 VM without nbd, force it to work in usual mode?

                              florentF 1 Reply Last reply Reply Quote 0
                              • florentF Offline
                                florent Vates 🪐 XO Team @Tristis Oris
                                last edited by

                                @Tristis-Oris said in NBD setup - No such item:

                                next weird thing.
                                i enabled NBD on all manage interfaces at all pools.

                                d1f4630b-d98c-4f7a-a149-65ce236c7834-изображение.png
                                c268c78e-0499-4bfe-b2e4-b7d425096e65-изображение.png

                                it working with CR backup, but shouldn't, at least because it no option to enable NBD.

                                it working with half of other delta backup tasks, but not for all. Main backup is still without nbd.
                                7628f07d-d31f-43b3-b014-a68f13cd3b91-изображение.png
                                ef0f1305-b5ce-436a-94ad-43168d89a04e-изображение.png

                                only idea, it probably because of 1 small pool with few vm, where i forget to enable NBD. so 1 VM without nbd, force it to work in usual mode?

                                that is really puzzling. I don't forget this issue, but I don't have much idea of how to fix this

                                Did you add the preferNbd flag to the config files ?

                                Tristis OrisT 1 Reply Last reply Reply Quote 0
                                • Tristis OrisT Offline
                                  Tristis Oris Top contributor @florent
                                  last edited by Tristis Oris

                                  @florent lets a brief summary.

                                  nbd work only via management interface. If nbd enabled on any another interface and specified as pool backup interface, it don't work (the issue with blocked packets at iptables). That was a main reason of my problem.

                                  For now i made it work at all my pools. Max single thread speed increased 80-90 > 140-150. At usual backup task (when daily delta very small) it show same 10-40Mb, because it done too fast. Average task time decreased fo about twice.

                                  florentF 1 Reply Last reply Reply Quote 1
                                  • florentF Offline
                                    florent Vates 🪐 XO Team @Tristis Oris
                                    last edited by

                                    @Tristis-Oris said in NBD setup - No such item:

                                    @florent lets a brief summary.

                                    nbd work only via management interface. If nbd enabled on any another interface and specified as pool backup interface, it don't work (the issue with blocked packets at iptables). That was a main reason of my problem.

                                    For now i made it work at all my pools. Max single thread speed increased 80-90 > 140-150. At usual backup task (when daily delta very small) it show same 10-40Mb, because it done too fast. Average task time decreased fo about twice.

                                    That is really strange, but it is also useful. We'll try to see why , and update the doc accordingly

                                    Tristis OrisT 1 Reply Last reply Reply Quote 0
                                    • Tristis OrisT Offline
                                      Tristis Oris Top contributor @florent
                                      last edited by Tristis Oris

                                      @florent also it works too good.
                                      i don' used advanced mode for CR backup, so NBD is disabled for job.
                                      68798612-4cf6-41d8-ad9e-799ee11cdb69-изображение.png

                                      d22da31a-1b0f-4339-9581-413d0238e275-изображение.png

                                      but task is working with nbd)
                                      894c9ff9-7b1f-4a9c-b829-ee66ac93b143-изображение.png

                                      1 Reply Last reply Reply Quote 1
                                      • Tristis OrisT Offline
                                        Tristis Oris Top contributor
                                        last edited by

                                        that log appear again, without any actions from my side.

                                        bab449b6-55cb-4e9f-b0af-ce8e9bb19d22-изображение.png

                                        1 Reply Last reply Reply Quote 0
                                        • First post
                                          Last post