ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Xen Orchestra Backup, Single VM Failing

    IT Discussion
    xen orchestra delta backup
    12
    65
    14.1k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • stacksofplatesS
      stacksofplates @DustinB3403
      last edited by

      @DustinB3403 said:

      @johnhooks said:

      @dafyre said:

      I'm having a similar issue, but different, lol. I am unable to backup any of my XenServer VMs. I am using an XO Machine built with @DustinB3403 's instructions. I am connecting to my XenServer using it's inside IP address (192.168.15.1/24) from my XO Server (192.168.15.2/24).

      When the backup jobs try to run, my XO Server tires to connect to the PUBLIC IP address of my XenServer.

      This poses a problem this is a hosted XenServer instance with a single public IP address... I am using ports 80 and 443 to run an Nginx proxy as a VM.

      Is this a bug in XO, by any chance? @olivier ?

      If the answer to that question is "NO", then what can I do to fix XenServer so that it only listens on my inside IP addresses?

      You're running XO in a vm on the XenServer?

      Yes.

      That is normal.

      I just wanted to make sure I understood how he set it up.

      1 Reply Last reply Reply Quote 0
      • DustinB3403D
        DustinB3403
        last edited by

        Now it wouldn't hurt to have a separate host, but on the primary host is also normal.

        1 Reply Last reply Reply Quote 0
        • stacksofplatesS
          stacksofplates @dafyre
          last edited by

          @dafyre said:

          I'm having a similar issue, but different, lol. I am unable to backup any of my XenServer VMs. I am using an XO Machine built with @DustinB3403 's instructions. I am connecting to my XenServer using it's inside IP address (192.168.15.1/24) from my XO Server (192.168.15.2/24).

          When the backup jobs try to run, my XO Server tires to connect to the PUBLIC IP address of my XenServer.

          This poses a problem this is a hosted XenServer instance with a single public IP address... I am using ports 80 and 443 to run an Nginx proxy as a VM.

          Is this a bug in XO, by any chance? @olivier ?

          If the answer to that question is "NO", then what can I do to fix XenServer so that it only listens on my inside IP addresses?

          Another question, is this a bridge for an internal network? Or did they give you a local network for your server?

          dafyreD 1 Reply Last reply Reply Quote 0
          • dafyreD
            dafyre @Alex Sage
            last edited by

            @anonymous said:

            @dafyre How does it even know what the public IP is? 😕

            This is what I'd like to know, lol. I am expecting it is something in the XAPI or something with XenServer configs somewhere... It should be noted that this is a Dedicated machine rented from KimSufi in France. I have exactly 1 public IP that I can use for this server.

            1 Reply Last reply Reply Quote 0
            • DashrenderD
              Dashrender
              last edited by

              I was wondering if the XO VM has external DNS servers instead of internal ones. Or maybe both, and it's failed over to the external one.

              I've found that I can never have internal and external DNS servers if I have a split-brain/split-horizon DNS situation. I can only use internal DNS or I WILL end up with problems.

              1 Reply Last reply Reply Quote 0
              • dafyreD
                dafyre @stacksofplates
                last edited by dafyre

                @johnhooks said:

                @dafyre said:

                I'm having a similar issue, but different, lol. I am unable to backup any of my XenServer VMs. I am using an XO Machine built with @DustinB3403 's instructions. I am connecting to my XenServer using it's inside IP address (192.168.15.1/24) from my XO Server (192.168.15.2/24).

                When the backup jobs try to run, my XO Server tires to connect to the PUBLIC IP address of my XenServer.

                This poses a problem this is a hosted XenServer instance with a single public IP address... I am using ports 80 and 443 to run an Nginx proxy as a VM.

                Is this a bug in XO, by any chance? @olivier ?

                If the answer to that question is "NO", then what can I do to fix XenServer so that it only listens on my inside IP addresses?

                Another question, is this a bridge for an internal network? Or did they give you a local network for your server?

                The public interface is bridged to my internal VM network... ie:

                XenBr1 = MyPublicIP
                xapi1 = 192.168.15.1/24 (on the physical XenServer host).

                XO = 192.168.15.2 / 24 (VM)
                IIS Server = 192.168.15.3/24 (VM)
                Nginx = 192.168.15.4/24 (VM)

                I can surf the web just fine from all of the VMs (Ubutnu 15 server using Lynx, or Windows 2012 R2 using IE).

                When I have my IIS server turned on, my NGINX Proxy does its job and serves up the pages.

                And I now have iptables & NGinx working nicely together with XenServer and I can run XenCenter and communicate with the XenServer over HTTPS through the Nginx proxy (Yes, I realize this is convoluted, lol).

                The problem that I am now having is that XO is trying to communicate with the XenServer via public IP instead of the private IP. I could fix it by setting iptables up for hairpin NAT, but I want to avoid this.

                stacksofplatesS 1 Reply Last reply Reply Quote 0
                • stacksofplatesS
                  stacksofplates @dafyre
                  last edited by

                  @dafyre said:

                  run XenCenter and communicate with the XenServer over HTTPS through the Nginx proxy

                  Where is XenCenter running? Local to you, or on a VM in the XenServer? If it's running local to you that might be the issue. XO might be trying to connect to XenServer and nginx is only allowing outside 443 to XenServer.

                  1 Reply Last reply Reply Quote 0
                  • dafyreD
                    dafyre
                    last edited by

                    If I undo all my iptables trickery, XenCenter and XO work fine if they are run locally from my home network.

                    If I leave all my iptables trickery undone, XO works fine if I run it as a VM behind the XenServer, except for backups.

                    My problem is that XenServer uses ports 80 and 443 for itself on the public IP address. I need those ports to run my web sites from.

                    travisdh1T 1 Reply Last reply Reply Quote 0
                    • travisdh1T
                      travisdh1 @dafyre
                      last edited by

                      @dafyre said:

                      If I undo all my iptables trickery, XenCenter and XO work fine if they are run locally from my home network.

                      If I leave all my iptables trickery undone, XO works fine if I run it as a VM behind the XenServer, except for backups.

                      My problem is that XenServer uses ports 80 and 443 for itself on the public IP address. I need those ports to run my web sites from.

                      Install a software firewall of some sort, and assign that the public IP address. Choose a different subnet for XenServer, and forward different ports from the Public IP software router to XenServer's 80 and 443. I wouldn't want my VM host sitting on the public net. Dunno how easy it is to "go touch the box" if you mess something up along the way, but that'd be the minimum to me.

                      dafyreD 1 Reply Last reply Reply Quote 1
                      • dafyreD
                        dafyre @travisdh1
                        last edited by

                        @travisdh1 said:

                        @dafyre said:

                        If I undo all my iptables trickery, XenCenter and XO work fine if they are run locally from my home network.

                        If I leave all my iptables trickery undone, XO works fine if I run it as a VM behind the XenServer, except for backups.

                        My problem is that XenServer uses ports 80 and 443 for itself on the public IP address. I need those ports to run my web sites from.

                        Install a software firewall of some sort, and assign that the public IP address. Choose a different subnet for XenServer, and forward different ports from the Public IP software router to XenServer's 80 and 443. I wouldn't want my VM host sitting on the public net. Dunno how easy it is to "go touch the box" if you mess something up along the way, but that'd be the minimum to me.

                        This is a physical server hosted @ Kimsufi in France, lol. Physical trips are not an option. 🙂

                        If I snafu it that badly, I can wipe & reload the machine through their web interface. Once I get it set up right, I'll be locking down the ports for XenCenter, etc, to only allow connections from my home IP address.

                        travisdh1T 1 Reply Last reply Reply Quote 1
                        • travisdh1T
                          travisdh1 @dafyre
                          last edited by

                          @dafyre said:

                          @travisdh1 said:

                          @dafyre said:

                          If I undo all my iptables trickery, XenCenter and XO work fine if they are run locally from my home network.

                          If I leave all my iptables trickery undone, XO works fine if I run it as a VM behind the XenServer, except for backups.

                          My problem is that XenServer uses ports 80 and 443 for itself on the public IP address. I need those ports to run my web sites from.

                          Install a software firewall of some sort, and assign that the public IP address. Choose a different subnet for XenServer, and forward different ports from the Public IP software router to XenServer's 80 and 443. I wouldn't want my VM host sitting on the public net. Dunno how easy it is to "go touch the box" if you mess something up along the way, but that'd be the minimum to me.

                          This is a physical server hosted @ Kimsufi in France, lol. Physical trips are not an option. 🙂

                          If I snafu it that badly, I can wipe & reload the machine through their web interface. Once I get it set up right, I'll be locking down the ports for XenCenter, etc, to only allow connections from my home IP address.

                          I haven't tried this myself, but I bet you could get ZeroTier running on a XenServer. I might have to attempt that at work tomorrow actually, would be really handy.

                          1 Reply Last reply Reply Quote 1
                          • dafyreD
                            dafyre
                            last edited by

                            I have actually considered that. That doesn't fix my underlying problem though. I can't change the ip or ports that XenServer is listening on through config files, etc that I have found.

                            1 Reply Last reply Reply Quote 0
                            • stacksofplatesS
                              stacksofplates
                              last edited by

                              One more question, are the backups being done on a local folder on the XO server or NFS?

                              dafyreD 1 Reply Last reply Reply Quote 0
                              • dafyreD
                                dafyre @stacksofplates
                                last edited by

                                @johnhooks said:

                                One more question, are the backups being done on a local folder on the XO server or NFS?

                                I started with a local folder on XO, and someone else suggested NFS as well. Either makes no difference. I can see in the XO log files that it is connecting to my public IP and failing because by default, IPTables doesn't like hairpin connections.

                                1 Reply Last reply Reply Quote 0
                                • stacksofplatesS
                                  stacksofplates
                                  last edited by

                                  I'll have to play around with it. I'm using a separate physical NFS share for backups. I wonder if the XO backups don't run through 443? If I get a chance I'll wireshark and see what's going on.

                                  1 Reply Last reply Reply Quote 0
                                  • dafyreD
                                    dafyre
                                    last edited by

                                    Well, a sudden bright idea later, and my backups are running... . I modified the hosts file on the XenServer to point to my internal IP address, and now XenOrchestra seems to be working... My backup is running as we speak. lol.

                                    stacksofplatesS 1 Reply Last reply Reply Quote 3
                                    • stacksofplatesS
                                      stacksofplates @dafyre
                                      last edited by

                                      @dafyre said:

                                      Well, a sudden bright idea later, and my backups are running... . I modified the hosts file on the XenServer to point to my internal IP address, and now XenOrchestra seems to be working... My backup is running as we speak. lol.

                                      Nice!

                                      1 Reply Last reply Reply Quote 0
                                      • dafyreD
                                        dafyre
                                        last edited by

                                        The only other thing I have an issue with is that XO still tries to connect to the public IP address when I need to connect to the VM consoles and such. (I can't actually install any VMs at the moment, since I can't get console access).

                                        1 Reply Last reply Reply Quote 0
                                        • olivierO
                                          olivier
                                          last edited by olivier

                                          Hi there!

                                          XO just uses the host.address value from XAPI, for all operations (backup which use the XAPI HTTP handler for export but also import, consoles, etc.)

                                          You'll have to find a way to have XAPI telling that host.address is the one you want.

                                          The XAPI doc says:

                                          The address by which this host can be contacted from any other host in the pool

                                          See http://xapi-project.github.io/xen-api/classes/host.html

                                          1 Reply Last reply Reply Quote 2
                                          • 1
                                          • 2
                                          • 3
                                          • 4
                                          • 3 / 4
                                          • First post
                                            Last post