Veritas Unstartable Volume
In this example of VXVM 4.0 on a Solaris 8 system, an array was temporarily unavailable, causing problems with a file system whose two plexes resided on the array.
bash-2.03# cd /files04
bash: cd: /files04: I/O error
The volume was in DISABLED ACTIVE state, and both plexes were in DISABLED RECOVER state.
v vol04 - DISABLED ACTIVE 29360128 SELECT - fsgen
pl vol04-01 vol04 DISABLED RECOVER 29367434 STRIPE 3/128 RW
sd appsdg01-04 vol04-01 cs_array07-f0 8392167 2797389 0/0 c1t0d0 ENA
sd appsdg07-01 vol04-01 cs_array03-f2 0 5594778 0/2797389 c4t2d0 ENA
sd appsdg07-04 vol04-01 cs_array03-f2 11189556 1396899 0/8392167 c4t2d0 ENA
sd appsdg02-04 vol04-01 cs_array07-f1 8392167 2797389 1/0 c1t1d0 ENA
sd appsdg10-02 vol04-01 cs_array06-f1 2797389 5594778 1/2797389 c5t1d0 ENA
sd appsdg10-05 vol04-01 cs_array06-f1 13986945 1396899 1/8392167 c5t1d0 ENA
sd appsdg03-04 vol04-01 cs_array07-f2 8392167 2797389 2/0 c1t2d0 ENA
sd appsdg11-02 vol04-01 cs_array06-f2 8392167 6991677 2/2797389 c5t2d0 ENA
pl vol04-02 vol04 DISABLED RECOVER 29367434 STRIPE 3/128 RW
sd appsdg04-02 vol04-02 cs_array07-f3 2797389 2797389 0/0 c1t3d0 ENA
sd appsdg04-05 vol04-02 cs_array07-f3 0 2797389 0/2797389 c1t3d0 ENA
sd appsdg04-06 vol04-02 cs_array07-f3 16784334 894159 0/5594778 c1t3d0 ENA
sd appsdg14-02 vol04-02 cs_array07-f6 12586455 3300129 0/6488937 c1t6d0 ENA
sd appsdg12-03 vol04-02 cs_array06-f3 5594778 2797389 1/0 c5t3d0 ENA
sd appsdg13-02 vol04-02 cs_array07-f4 12586455 5092038 1/2797389 c1t4d0 ENA
sd appsdg12-02 vol04-02 cs_array06-f3 16784334 894159 1/7889427 c5t3d0 ENA
sd appsdg05-02 vol04-02 cs_array03-f0 12586455 1005480 1/8783586 c4t0d0 ENA
sd appsdg09-02 vol04-02 cs_array06-f0 2797389 8392167 2/0 c5t0d0 ENA
sd appsdg09-06 vol04-02 cs_array06-f0 3591 1396899 2/8392167 c5t0d0 ENA
We confirmed that the storage array was available to the operating system.
# luxadm probe
Found Enclosure(s):
...
SENA Name:cs_array06 Node WWN:5080020000038ba8
Logical Path:/dev/es/ses6
Logical Path:/dev/es/ses7
# luxadm display cs_array06
SENA
DISK STATUS
SLOT FRONT DISKS (Node WWN) REAR DISKS (Node WWN)
0 On (O.K.) 2000002037094289 On (O.K.) 200000203709422e
1 On (O.K.) 2000002037093aaf On (O.K.) 2000002037094220
2 On (O.K.) 200000203709410b On (O.K.) 2000002037093ddd
3 On (O.K.) 2000002037094254 On (O.K.) 200000203709422b
4 On (O.K.) 20000020370940da On (O.K.) 2000002037094247
5 Not Installed Not Installed
6 On (O.K.) 2000002037093df0 On (O.K.) 200000203709383f
Next, we reattached the disks to the disk group they were in. You may want to run vxreattach -c diskname to check if a reattach is possible before attempting to reattach the disks.
# vxdisk list
...
- - cs_array06-f0 appsdg failed was:c5t0d0s2
- - cs_array06-f1 appsdg failed was:c5t1d0s2
- - cs_array06-f2 appsdg failed was:c5t2d0s2
- - cs_array06-f3 appsdg failed was:c5t3d0s2
- - cs_array06-r4 appsdg failed spare was:c5t20d0s2
- - cs_array06-f4 appsdg failed was:c5t4d0s2
# cd /usr/lib/vxvm/bin
# ./vxreattach c5t0d0s2
# ./vxreattach c5t1d0s2
# ./vxreattach c5t2d0s2
# ./vxreattach c5t3d0s2
# ./vxreattach c5t20d0s2
# ./vxreattach c5t4d0s2
We then followed the "Recovering an Unstartable Volume with a Disabled Plex in the RECOVER State" procedure in the Volume Manager Troubleshooting Guide.
1. Force plex vol04-01 into the OFFLINE state.
# vxmend -g appsdg -o force off vol04-01
2. Place plex vol04-01 into the STALE state.
# vxmend -g appsdg on vol04-01
3. There are no other clean plexes in the volume, so make plex vol04-01 DISABLED and CLEAN.
# vxmend -g appsdg fix clean vol04-01
4. Start the volume, and perform resynchronization of the plexes in the background.
# vxvol -g appsdg -o bg start vol04
At this point, the file system is unmounted, checked for file system consistency, and remounted.
# umount /files04
# mount /files04
UX:vxfs mount: ERROR: V-3-21268: /dev/vx/dsk/appsdg/vol04 is corrupted. needs checking
# fsck -F vxfs /dev/vx/rdsk/appsdg/vol04
log replay in progress
replay complete - marking super-block as CLEAN
# mount /files04
вторник, 7 апреля 2009 г.
VxVM Veritas notes
Veritas notes
The following notes are for Veritas Volume Manager 3.2 for Solaris.
"vxvm:vxconfigd: ERROR: enable failed: Error in disk group configuration copies
Disk group has no valid configuration copies; transactions are disabled."
When receiving this error during system boot and when running vxinstall, follow the steps detailed in http://www.eng.auburn.edu/pub/mail-lists/veritas-users.May99/msg00048.html
In my case, the rootdg configuration was apparently corrupted. After issuing touch /etc/vx/reconfig.d/state.d/install-db and rebooting the machine, I was able to run vxinstall.
vxvm:vxdg: ERROR: Disk group disk_group: import failed: Disk group has no valid configuration copies"
This error can occur when attempting to import a disk group that was configured using a later version of VxVM. In this case, the disk group was configured with VxVM 3.2, but VxVM 3.1.1 was installed.
# pkginfo -l VRTSvxvm
PKGINST: VRTSvxvm
NAME: VERITAS Volume Manager, Binaries
CATEGORY: system
ARCH: sparc
VERSION: 3.1.1,REV=01.30.2001.22.21
Upgrading to at least the same version of VxVM used to configure the disk group will allow the disk group to be imported.
"ld.so.1: vxconfigd: fatal: libdevid.so.1: open failed: No such file or directory"
With Solaris 8 and VxVM 3.2, the shared library libdevid.so.1 does not get copied to /etc/vx/slib after installing Veritas. If you do not manually copy this shared library to /etc/vx/slib, your system will not boot. Follow these steps to make your system bootable:
1. Boot off a CD-ROM.
2. Mount your root and usr file systems.
3. Copy /usr/lib/libdevid.so.1 to /etc/vx/slib
4. Unmount your root and usr file systems and reboot.
More information:
http://marc.theaimsgroup.com/?l=veritas-vx&m=102636855529467&w=2
Clearing device locks
To clear a device lock, use the vxdisk clearimport command:
vxdisk clearimport devicename
ex. vxdisk clearimport c0t1d0
Using a Sun StorEdge A5000 disk array with Veritas
Make sure the array(s) are recognized by the operating system.
# luxadm probe
Found Enclosure(s):
SENA Name:a1 Node WWN:50800200000276e0
Logical Path:/dev/es/ses2
Logical Path:/dev/es/ses7
SENA Name:a2 Node WWN:5080020000028020
Logical Path:/dev/es/ses3
Logical Path:/dev/es/ses6
SENA Name:a0 Node WWN:5080020000026f38
Logical Path:/dev/es/ses4
Logical Path:/dev/es/ses5
SENA Name:a3 Node WWN:5080020000027060
Logical Path:/dev/es/ses8
Logical Path:/dev/es/ses9
Run Veritas' device discovery program.
# vxdctl enable
Determining maximum size of a volume
vxassist [ -g diskgroup ] maxsize layout=layout [attributes]
Example:
vxassist -g datadg maxsize layout=concat
layout may be concat, mirror, raid5, mirror-stripe, or stripe-mirror.
Veritas disk requirements
Disks managed by VxVM must have (1) two free partitions and (2) 2048 sectors of free space. The prtvtoc command displays how many sectors are in a disk cylinder:
# prtvtoc /dev/rdsk/c0t86d0s2
* /dev/rdsk/c0t86d0s2 partition map
*
* Dimensions:
* 512 bytes/sector
* 133 sectors/track
* 27 tracks/cylinder
* 3591 sectors/cylinder
* 4926 cylinders
* 4924 accessible cylinders
In this example, leave at least 1 cylinder free in your disk layout to allow for VxVM. If the disk is a boot disk, VxVM can shrink the swap partition to create space for VxVM's configuration data, but two free slices are essential for encapsulation.
Creating a volume with vxassist
ex.
# vxassist -g datadg maxsize
Maximum volume size: 35356672 (17264Mb)
# vxassist -g datadg make volume 35356672
Create the vxfs file system:
# mkfs -F vxfs /dev/vx/rdsk/datadg/db_backups
version 4 layout
35356672 sectors, 17678336 blocks of size 1024, log size 16384 blocks
unlimited inodes, largefiles not supported
17678336 data blocks, 17657432 free data blocks
540 allocation units of 32768 blocks, 32768 data blocks
last allocation unit has 16384 data blocks
Create the mount point:
# mkdir /db_backups
Mount the vxfs file system:
# mount -F vxfs /dev/vx/dsk/datadg/db_backups /db_backups
Add an /etc/vfstab entry to mount the file system after a reboot.
Replacing a failed disk
After replacing a failed disk in a SENA, make sure to run vxdctl enable for device discovery. Otherwise, you may encounter vxdmpadm errors:
Initialization of disk device c1t74d0 failed.
Error: vxvm:vxdmpadm: ERROR: Error in ioctl/open
vxdmpadm: No such file or directory
vxvm:vxdmpadm: ERROR: Invalid da_name
vxvm:vxdmpadm: ERROR: Invalid da_name
vxdisksetup: c1t74d0: Device address must be of the form cCtTdD or mcCtTdD where
C = host bus adapter controller number
T = target device controller number, if used
D = logical unit (disk) number within target device controller
# vxdisk list c1t74d0s2
Device: c1t74d0s2
devicetag: c1t74d0
type: sliced
flags: online error private autoconfig
errno: Device path not valid
Multipathing information:
numpaths: 2
c1t74d0s2 state=disabled
c5t74d0s2 state=disabled
When replacing a failed internal disk on a Sun E450 running Solaris 8, I had to spin the disk down using ssaadm stop /dev/rdsk/cxtxdxs2as the vxdiskadm's "Disable (offline) a disk device" did not seem to spin the disk down. If you are using a Sun system with FC-AL devices, you will want to use the luxadm command.
After replacing the disk, I enabled device discovery with vxdctl enable and un-relocated the failed subdisks back to this disk using /usr/lib/vxvm/bin/vxunreloc -g disk_group replaced_disk.
Adding additional users to VxVM electronic mail notifications
By default, VxVM sends electronic mail to the root user when failures are detected and hot-relocation is being performed. To notify additional users,
1. Edit /etc/init.d/vxvm-recover
2. Change the line containing vxrelocd root & to vxrelocd root user1 user2 ... &
This will preserve the change across system reboot.
3. To have the change take effect immediately, make sure that hot-relocation is not currently being performed by running vxtask list, kill the vxrelocd process, and run nohup vxrelocd root user1 user2 ... &
Miscellaneous
Adding a disk to a disk group:
vxdiskadd disk_name
Creating a subdisk:
vxmake [-g groupname] sd subdisk diskname,offset,length
Creating a plex:
vxmake [-g groupname] plex plex sd=subdisk1[,subdisk2,...]
Creating a volume with vxmake:
vxmake [-g groupname] -U fsgen vol volume plex=plex1[,plex2,...]
Note: use gen instead of fsgen if you are creating a raw file system for RDBMS usage. fsgen is appropriate for general file system usage. More information on fsgen vs. gen.
After creating the volume, initialize the volume with vxvol start volume. If applicable, create the file system with newfs, create the mount point, and mount the volume as a file system.
Associating subdisks with plexes:
vxsd assoc plex subdisk1 [subdisk2 subdisk3 ...]
Displaying free disk space in a diskgroup:
vxdg [-g groupname] free
Dissociating subdisks from plexes:
vxsd dis subdisk
Dissociating subdisks from plexes, removing subdisk from VxVM:
vxsd -o rm dis subdisk
Dissociating and removing plexes and all associated subdisks:
vxplex -o rm dis plex
Removing a disk from a disk group:
vxdg [-g groupname] rmdisk diskname
Renaming a disk:
vxedit rename old_diskname new_diskname
Removing a volume (vxassist):
vxassist remove volume volume
Removing a volume (vxedit):
vxedit [-r] [-f] rm volume
-r -- recursive removal
-f -- force removal; needed if volume is enabled
Moving hot-relocated subdisks back to their original disk with vxunreloc:
/usr/lib/vxvm/bin/vxunreloc [-g groupname]original_disk
The following notes are for Veritas Volume Manager 3.2 for Solaris.
"vxvm:vxconfigd: ERROR: enable failed: Error in disk group configuration copies
Disk group has no valid configuration copies; transactions are disabled."
When receiving this error during system boot and when running vxinstall, follow the steps detailed in http://www.eng.auburn.edu/pub/mail-lists/veritas-users.May99/msg00048.html
In my case, the rootdg configuration was apparently corrupted. After issuing touch /etc/vx/reconfig.d/state.d/install-db and rebooting the machine, I was able to run vxinstall.
vxvm:vxdg: ERROR: Disk group disk_group: import failed: Disk group has no valid configuration copies"
This error can occur when attempting to import a disk group that was configured using a later version of VxVM. In this case, the disk group was configured with VxVM 3.2, but VxVM 3.1.1 was installed.
# pkginfo -l VRTSvxvm
PKGINST: VRTSvxvm
NAME: VERITAS Volume Manager, Binaries
CATEGORY: system
ARCH: sparc
VERSION: 3.1.1,REV=01.30.2001.22.21
Upgrading to at least the same version of VxVM used to configure the disk group will allow the disk group to be imported.
"ld.so.1: vxconfigd: fatal: libdevid.so.1: open failed: No such file or directory"
With Solaris 8 and VxVM 3.2, the shared library libdevid.so.1 does not get copied to /etc/vx/slib after installing Veritas. If you do not manually copy this shared library to /etc/vx/slib, your system will not boot. Follow these steps to make your system bootable:
1. Boot off a CD-ROM.
2. Mount your root and usr file systems.
3. Copy /usr/lib/libdevid.so.1 to /etc/vx/slib
4. Unmount your root and usr file systems and reboot.
More information:
http://marc.theaimsgroup.com/?l=veritas-vx&m=102636855529467&w=2
Clearing device locks
To clear a device lock, use the vxdisk clearimport command:
vxdisk clearimport devicename
ex. vxdisk clearimport c0t1d0
Using a Sun StorEdge A5000 disk array with Veritas
Make sure the array(s) are recognized by the operating system.
# luxadm probe
Found Enclosure(s):
SENA Name:a1 Node WWN:50800200000276e0
Logical Path:/dev/es/ses2
Logical Path:/dev/es/ses7
SENA Name:a2 Node WWN:5080020000028020
Logical Path:/dev/es/ses3
Logical Path:/dev/es/ses6
SENA Name:a0 Node WWN:5080020000026f38
Logical Path:/dev/es/ses4
Logical Path:/dev/es/ses5
SENA Name:a3 Node WWN:5080020000027060
Logical Path:/dev/es/ses8
Logical Path:/dev/es/ses9
Run Veritas' device discovery program.
# vxdctl enable
Determining maximum size of a volume
vxassist [ -g diskgroup ] maxsize layout=layout [attributes]
Example:
vxassist -g datadg maxsize layout=concat
layout may be concat, mirror, raid5, mirror-stripe, or stripe-mirror.
Veritas disk requirements
Disks managed by VxVM must have (1) two free partitions and (2) 2048 sectors of free space. The prtvtoc command displays how many sectors are in a disk cylinder:
# prtvtoc /dev/rdsk/c0t86d0s2
* /dev/rdsk/c0t86d0s2 partition map
*
* Dimensions:
* 512 bytes/sector
* 133 sectors/track
* 27 tracks/cylinder
* 3591 sectors/cylinder
* 4926 cylinders
* 4924 accessible cylinders
In this example, leave at least 1 cylinder free in your disk layout to allow for VxVM. If the disk is a boot disk, VxVM can shrink the swap partition to create space for VxVM's configuration data, but two free slices are essential for encapsulation.
Creating a volume with vxassist
ex.
# vxassist -g datadg maxsize
Maximum volume size: 35356672 (17264Mb)
# vxassist -g datadg make volume 35356672
Create the vxfs file system:
# mkfs -F vxfs /dev/vx/rdsk/datadg/db_backups
version 4 layout
35356672 sectors, 17678336 blocks of size 1024, log size 16384 blocks
unlimited inodes, largefiles not supported
17678336 data blocks, 17657432 free data blocks
540 allocation units of 32768 blocks, 32768 data blocks
last allocation unit has 16384 data blocks
Create the mount point:
# mkdir /db_backups
Mount the vxfs file system:
# mount -F vxfs /dev/vx/dsk/datadg/db_backups /db_backups
Add an /etc/vfstab entry to mount the file system after a reboot.
Replacing a failed disk
After replacing a failed disk in a SENA, make sure to run vxdctl enable for device discovery. Otherwise, you may encounter vxdmpadm errors:
Initialization of disk device c1t74d0 failed.
Error: vxvm:vxdmpadm: ERROR: Error in ioctl/open
vxdmpadm: No such file or directory
vxvm:vxdmpadm: ERROR: Invalid da_name
vxvm:vxdmpadm: ERROR: Invalid da_name
vxdisksetup: c1t74d0: Device address must be of the form cCtTdD or mcCtTdD where
C = host bus adapter controller number
T = target device controller number, if used
D = logical unit (disk) number within target device controller
# vxdisk list c1t74d0s2
Device: c1t74d0s2
devicetag: c1t74d0
type: sliced
flags: online error private autoconfig
errno: Device path not valid
Multipathing information:
numpaths: 2
c1t74d0s2 state=disabled
c5t74d0s2 state=disabled
When replacing a failed internal disk on a Sun E450 running Solaris 8, I had to spin the disk down using ssaadm stop /dev/rdsk/cxtxdxs2as the vxdiskadm's "Disable (offline) a disk device" did not seem to spin the disk down. If you are using a Sun system with FC-AL devices, you will want to use the luxadm command.
After replacing the disk, I enabled device discovery with vxdctl enable and un-relocated the failed subdisks back to this disk using /usr/lib/vxvm/bin/vxunreloc -g disk_group replaced_disk.
Adding additional users to VxVM electronic mail notifications
By default, VxVM sends electronic mail to the root user when failures are detected and hot-relocation is being performed. To notify additional users,
1. Edit /etc/init.d/vxvm-recover
2. Change the line containing vxrelocd root & to vxrelocd root user1 user2 ... &
This will preserve the change across system reboot.
3. To have the change take effect immediately, make sure that hot-relocation is not currently being performed by running vxtask list, kill the vxrelocd process, and run nohup vxrelocd root user1 user2 ... &
Miscellaneous
Adding a disk to a disk group:
vxdiskadd disk_name
Creating a subdisk:
vxmake [-g groupname] sd subdisk diskname,offset,length
Creating a plex:
vxmake [-g groupname] plex plex sd=subdisk1[,subdisk2,...]
Creating a volume with vxmake:
vxmake [-g groupname] -U fsgen vol volume plex=plex1[,plex2,...]
Note: use gen instead of fsgen if you are creating a raw file system for RDBMS usage. fsgen is appropriate for general file system usage. More information on fsgen vs. gen.
After creating the volume, initialize the volume with vxvol start volume. If applicable, create the file system with newfs, create the mount point, and mount the volume as a file system.
Associating subdisks with plexes:
vxsd assoc plex subdisk1 [subdisk2 subdisk3 ...]
Displaying free disk space in a diskgroup:
vxdg [-g groupname] free
Dissociating subdisks from plexes:
vxsd dis subdisk
Dissociating subdisks from plexes, removing subdisk from VxVM:
vxsd -o rm dis subdisk
Dissociating and removing plexes and all associated subdisks:
vxplex -o rm dis plex
Removing a disk from a disk group:
vxdg [-g groupname] rmdisk diskname
Renaming a disk:
vxedit rename old_diskname new_diskname
Removing a volume (vxassist):
vxassist remove volume volume
Removing a volume (vxedit):
vxedit [-r] [-f] rm volume
-r -- recursive removal
-f -- force removal; needed if volume is enabled
Moving hot-relocated subdisks back to their original disk with vxunreloc:
/usr/lib/vxvm/bin/vxunreloc [-g groupname]original_disk
VxVM Veritas licenses
Veritas licenses
The following information pertains to Veritas Volume Manager 3.2 for Solaris.
Location of license keys:
/etc/vx/elm
The key is the fourth line of the license file, below:
!
# DO NOT EDIT/COPY/MOVE/TOUCH THIS FILE!
# DOING SO WILL INVALIDATE THE KEY!
Check validity of license keys:
vxliccheck -pv
vrts:vxliccheck: INFO: License 95 valid
vrts:vxliccheck: INFO: License 96 valid
vrts:vxliccheck: INFO: License 98 valid
Print license details:
vxlicense -p
Create a license key file:
vxlicense -c
The following information pertains to Veritas Volume Manager 3.2 for Solaris.
Location of license keys:
/etc/vx/elm
The key is the fourth line of the license file, below:
!
# DO NOT EDIT/COPY/MOVE/TOUCH THIS FILE!
# DOING SO WILL INVALIDATE THE KEY!
Check validity of license keys:
vxliccheck -pv
vrts:vxliccheck: INFO: License 95 valid
vrts:vxliccheck: INFO: License 96 valid
vrts:vxliccheck: INFO: License 98 valid
Print license details:
vxlicense -p
Create a license key file:
vxlicense -c
VxVM Unencapsulating a root disk
Unencapsulating a root disk
If your system partitions (/, swap, /usr, /var) are located on more than one physical disk, you will have to manually "unencapsulate" your root disk instead of using Veritas' vxunroot command below.
1. Modify /etc/vfstab to reference the cxtxdxsx devices instead of the VxVM devices.
2. Comment out the lines in /etc/system between:
* vxvm_START (do not remove)
* vxvm_END (do not remove)
3. Run the following command to prevent VxVM from starting up after reboot:
touch /etc/vx/reconfig.d/state.d/install-db
4. Reboot the system. After the reboot, you may uninstall VxVM if needed.
System partitions on boot disk
The Veritas vxunroot command is used to unencapsulate a root disk that contains all your system partitions. However, if the root disk is mirrored, you have to remove the mirror plexes.
Example:
# /etc/vx/bin/vxunroot
This operation will convert the following file systems from
volumes to regular partitions: root swap usr var opt home
ERROR: There are 2 plexes associated with volume rootvol
The vxunroot operation cannot proceed.
Listing of all volumes in rootdg:
# vxprint -v -g rootdg
TY NAME ASSOC KSTATE LENGTH PLOFFS STATE TUTIL0 PUTIL0
v opt gen ENABLED 4198392 - ACTIVE - -
v rootvol root ENABLED 1050776 - ACTIVE - -
v swapvol swap ENABLED 4198392 - ACTIVE - -
v usr gen ENABLED 4198392 - ACTIVE - -
v var gen ENABLED 4198392 - ACTIVE - -
Here we see that rootdg contains volumes opt, rootvol, swapvol, usr, and var. Let's see if the volumes consist of more than one plex.
# vxprint opt rootvol swapvol usr var
Disk group: rootdg
TY NAME ASSOC KSTATE LENGTH PLOFFS STATE TUTIL0 PUTIL0
v opt gen ENABLED 4198392 - ACTIVE - -
pl opt-01 opt ENABLED 4198392 - ACTIVE - -
sd rootdisk-04 opt-01 ENABLED 4198392 0 - - -
pl opt-02 opt ENABLED 4198392 - ACTIVE - -
sd rootdisk-mirror-01 opt-02 ENABLED 4198392 0 - - -
v rootvol root ENABLED 1050776 - ACTIVE - -
pl rootvol-01 rootvol ENABLED 1050776 - ACTIVE - -
sd rootdisk-B0 rootvol-01 ENABLED 1 0 - - Block0
pl rootvol-02 rootvol ENABLED 1050776 - ACTIVE - -
sd rootdisk-02 rootvol-01 ENABLED 1050775 1 - - -
v swapvol swap ENABLED 4198392 - ACTIVE - -
pl swapvol-01 swapvol ENABLED 4198392 - ACTIVE - -
sd rootdisk-01 swapvol-01 ENABLED 4198392 0 - - -
pl swapvol-02 swapvol ENABLED 4198392 - ACTIVE - -
sd rootdisk-mirror-03 swapvol-02 ENABLED 4198392 0 - - -
v usr gen ENABLED 4198392 - ACTIVE - -
pl usr-01 usr ENABLED 4198392 - ACTIVE - -
sd rootdisk-03 usr-01 ENABLED 4198392 0 - - -
pl usr-02 usr ENABLED 4198392 - ACTIVE - -
sd rootdisk-mirror-04 usr-02 ENABLED 4198392 0 - - -
v var gen ENABLED 4198392 - ACTIVE - -
pl var-01 var ENABLED 4198392 - ACTIVE - -
sd rootdisk-05 var-01 ENABLED 4198392 0 - - -
pl var-02 var ENABLED 4198392 - ACTIVE - -
sd rootdisk-mirror-05 var-02 ENABLED 4198392 0 - - -
VM disk rootdisk-mirror contains mirror plexes for volumes opt,rootvol, swapvol, usr, and var. We have to remove the plexes before proceeding with vxunroot.
# vxplex -o rm dis opt-02 rootvol-02 swapvol-02 usr-02 var-02
# vxprint opt rootvol swapvol usr var
Disk group: rootdg
TY NAME ASSOC KSTATE LENGTH PLOFFS STATE TUTIL0 PUTIL0
v opt gen ENABLED 4198392 - ACTIVE - -
pl opt-01 opt ENABLED 4198392 - ACTIVE - -
sd rootdisk-04 opt-01 ENABLED 4198392 0 - - -
v rootvol root ENABLED 1050776 - ACTIVE - -
pl rootvol-01 rootvol ENABLED 1050776 - ACTIVE - -
sd rootdisk-B0 rootvol-01 ENABLED 1 0 - - Block0
sd rootdisk-02 rootvol-01 ENABLED 1050775 1 - - -
v swapvol swap ENABLED 4198392 - ACTIVE - -
pl swapvol-01 swapvol ENABLED 4198392 - ACTIVE - -
sd rootdisk-01 swapvol-01 ENABLED 4198392 0 - - -
v usr gen ENABLED 4198392 - ACTIVE - -
pl usr-01 usr ENABLED 4198392 - ACTIVE - -
sd rootdisk-03 usr-01 ENABLED 4198392 0 - - -
v var gen ENABLED 4198392 - ACTIVE - -
pl var-01 var ENABLED 4198392 - ACTIVE - -
sd rootdisk-05 var-01 ENABLED 4198392 0 - - -
# /etc/vx/bin/vxunroot
This operation will convert the following file systems from
volumes to regular partitions: root swap usr var opt home
Replace volume rootvol with c0t0d0s0.
This operation will require a system reboot. If you choose to
continue with this operation, system configuration will be updated
to discontinue use of the volume manager for your root and swap
devices.
Do you wish to do this now [y,n,q,?] (default: y)
After a reboot, the root disk will be unencapsulated.
If your system partitions (/, swap, /usr, /var) are located on more than one physical disk, you will have to manually "unencapsulate" your root disk instead of using Veritas' vxunroot command below.
1. Modify /etc/vfstab to reference the cxtxdxsx devices instead of the VxVM devices.
2. Comment out the lines in /etc/system between:
* vxvm_START (do not remove)
* vxvm_END (do not remove)
3. Run the following command to prevent VxVM from starting up after reboot:
touch /etc/vx/reconfig.d/state.d/install-db
4. Reboot the system. After the reboot, you may uninstall VxVM if needed.
System partitions on boot disk
The Veritas vxunroot command is used to unencapsulate a root disk that contains all your system partitions. However, if the root disk is mirrored, you have to remove the mirror plexes.
Example:
# /etc/vx/bin/vxunroot
This operation will convert the following file systems from
volumes to regular partitions: root swap usr var opt home
ERROR: There are 2 plexes associated with volume rootvol
The vxunroot operation cannot proceed.
Listing of all volumes in rootdg:
# vxprint -v -g rootdg
TY NAME ASSOC KSTATE LENGTH PLOFFS STATE TUTIL0 PUTIL0
v opt gen ENABLED 4198392 - ACTIVE - -
v rootvol root ENABLED 1050776 - ACTIVE - -
v swapvol swap ENABLED 4198392 - ACTIVE - -
v usr gen ENABLED 4198392 - ACTIVE - -
v var gen ENABLED 4198392 - ACTIVE - -
Here we see that rootdg contains volumes opt, rootvol, swapvol, usr, and var. Let's see if the volumes consist of more than one plex.
# vxprint opt rootvol swapvol usr var
Disk group: rootdg
TY NAME ASSOC KSTATE LENGTH PLOFFS STATE TUTIL0 PUTIL0
v opt gen ENABLED 4198392 - ACTIVE - -
pl opt-01 opt ENABLED 4198392 - ACTIVE - -
sd rootdisk-04 opt-01 ENABLED 4198392 0 - - -
pl opt-02 opt ENABLED 4198392 - ACTIVE - -
sd rootdisk-mirror-01 opt-02 ENABLED 4198392 0 - - -
v rootvol root ENABLED 1050776 - ACTIVE - -
pl rootvol-01 rootvol ENABLED 1050776 - ACTIVE - -
sd rootdisk-B0 rootvol-01 ENABLED 1 0 - - Block0
pl rootvol-02 rootvol ENABLED 1050776 - ACTIVE - -
sd rootdisk-02 rootvol-01 ENABLED 1050775 1 - - -
v swapvol swap ENABLED 4198392 - ACTIVE - -
pl swapvol-01 swapvol ENABLED 4198392 - ACTIVE - -
sd rootdisk-01 swapvol-01 ENABLED 4198392 0 - - -
pl swapvol-02 swapvol ENABLED 4198392 - ACTIVE - -
sd rootdisk-mirror-03 swapvol-02 ENABLED 4198392 0 - - -
v usr gen ENABLED 4198392 - ACTIVE - -
pl usr-01 usr ENABLED 4198392 - ACTIVE - -
sd rootdisk-03 usr-01 ENABLED 4198392 0 - - -
pl usr-02 usr ENABLED 4198392 - ACTIVE - -
sd rootdisk-mirror-04 usr-02 ENABLED 4198392 0 - - -
v var gen ENABLED 4198392 - ACTIVE - -
pl var-01 var ENABLED 4198392 - ACTIVE - -
sd rootdisk-05 var-01 ENABLED 4198392 0 - - -
pl var-02 var ENABLED 4198392 - ACTIVE - -
sd rootdisk-mirror-05 var-02 ENABLED 4198392 0 - - -
VM disk rootdisk-mirror contains mirror plexes for volumes opt,rootvol, swapvol, usr, and var. We have to remove the plexes before proceeding with vxunroot.
# vxplex -o rm dis opt-02 rootvol-02 swapvol-02 usr-02 var-02
# vxprint opt rootvol swapvol usr var
Disk group: rootdg
TY NAME ASSOC KSTATE LENGTH PLOFFS STATE TUTIL0 PUTIL0
v opt gen ENABLED 4198392 - ACTIVE - -
pl opt-01 opt ENABLED 4198392 - ACTIVE - -
sd rootdisk-04 opt-01 ENABLED 4198392 0 - - -
v rootvol root ENABLED 1050776 - ACTIVE - -
pl rootvol-01 rootvol ENABLED 1050776 - ACTIVE - -
sd rootdisk-B0 rootvol-01 ENABLED 1 0 - - Block0
sd rootdisk-02 rootvol-01 ENABLED 1050775 1 - - -
v swapvol swap ENABLED 4198392 - ACTIVE - -
pl swapvol-01 swapvol ENABLED 4198392 - ACTIVE - -
sd rootdisk-01 swapvol-01 ENABLED 4198392 0 - - -
v usr gen ENABLED 4198392 - ACTIVE - -
pl usr-01 usr ENABLED 4198392 - ACTIVE - -
sd rootdisk-03 usr-01 ENABLED 4198392 0 - - -
v var gen ENABLED 4198392 - ACTIVE - -
pl var-01 var ENABLED 4198392 - ACTIVE - -
sd rootdisk-05 var-01 ENABLED 4198392 0 - - -
# /etc/vx/bin/vxunroot
This operation will convert the following file systems from
volumes to regular partitions: root swap usr var opt home
Replace volume rootvol with c0t0d0s0.
This operation will require a system reboot. If you choose to
continue with this operation, system configuration will be updated
to discontinue use of the volume manager for your root and swap
devices.
Do you wish to do this now [y,n,q,?] (default: y)
After a reboot, the root disk will be unencapsulated.
VxVM Resizing a file system
Resizing a file system
In this example, I will resize a UFS file system under VxVM control from 3GB to 4GB using vxresize.
Current capacity:
# df -k /dbfiles03
Filesystem kbytes used avail capacity Mounted on
/dev/vx/dsk/dg20/dbvol03
3079710 2709166 308950 90% /dbfiles03
File system type:
# mount -v | grep /dbfiles03
/dev/vx/dsk/dg20/dbvol03 on /dbfiles03 type ufs read/write/setuid/intr/largefiles/onerror=panic/dev=3d1349e on Sun Aug 3 16:21:54 2003
Volume information:
# vxprint dbvol03
Disk group: dg20
TY NAME ASSOC KSTATE LENGTH PLOFFS STATE TUTIL0 PUTIL0
v dbvol03 fsgen ENABLED 6291456 - ACTIVE - -
pl dbvol03-01 dbvol03 ENABLED 6298619 - ACTIVE - -
sd dg2007-03 dbvol03-01 ENABLED 3149307 0 - - -
sd dg2006-03 dbvol03-01 ENABLED 3149307 0 - - -
Plex information:
# vxprint -l dbvol03-01
Disk group: dg20
Plex: dbvol03-01
info: len=6298619 contiglen=6298491
type: layout=STRIPE columns=2 width=128
state: state=ACTIVE kernel=ENABLED io=read-write
assoc: vol=dbvol03 sd=dg2007-03,dg2006-03
flags: busy complete
Increasing the volume to 4GB using vxresize:
# vxresize dbvol03 4g
/dev/vx/rdsk/dg20/dbvol03: 8388608 sectors in 4096 cylinders of 32 tracks, 64 sectors
4096.0MB in 88 cyl groups (47 c/g, 47.00MB/g, 7872 i/g)
super-block backups (for fsck -F ufs -o b=#) at:
32, 96352, 192672, 288992, 385312, 481632, 577952, 674272, 770592, 866912,
963232, 1059552, 1155872, 1252192, 1348512, 1444832, 1541152, 1637472,
1733792, 1830112, 1926432, 2022752, 2119072, 2215392, 2311712, 2408032,
2504352, 2600672, 2696992, 2793312, 2889632, 2985952, 3080224, 3176544,
3272864, 3369184, 3465504, 3561824, 3658144, 3754464, 3850784, 3947104,
4043424, 4139744, 4236064, 4332384, 4428704, 4525024, 4621344, 4717664,
4813984, 4910304, 5006624, 5102944, 5199264, 5295584, 5391904, 5488224,
5584544, 5680864, 5777184, 5873504, 5969824, 6066144, 6160416, 6256736,
6353056, 6449376, 6545696, 6642016, 6738336, 6834656, 6930976, 7027296,
7123616, 7219936, 7316256, 7412576, 7508896, 7605216, 7701536, 7797856,
7894176, 7990496, 8086816, 8183136, 8279456, 8375776,
New capacity:
# df -k /dbfiles03
Filesystem kbytes used avail capacity Mounted on
/dev/vx/dsk/dg20/dbvol03
4106286 2709166 1335526 67% /dbfiles03
New volume information (two new subdisks):
# vxprint dbvol03
Disk group: dg20
TY NAME ASSOC KSTATE LENGTH PLOFFS STATE TUTIL0 PUTIL0
v dbvol03 fsgen ENABLED 8388608 - ACTIVE - -
pl dbvol03-01 dbvol03 ENABLED 8395767 - ACTIVE - -
sd dg2007-03 dbvol03-01 ENABLED 3149307 0 - - -
sd dg2007-05 dbvol03-01 ENABLED 1048572 3149307 - - -
sd dg2006-03 dbvol03-01 ENABLED 3149307 0 - - -
sd dg2006-05 dbvol03-01 ENABLED 1048572 3149307 - - -
New plex information:
# vxprint -l dbvol03-01
Disk group: dg20
Plex: dbvol03-01
info: len=8395767 contiglen=8395639
type: layout=STRIPE columns=2 width=128
state: state=ACTIVE kernel=ENABLED io=read-write
assoc: vol=dbvol03 sd=dg2007-03,dg2007-05,dg2006-03,dg2006-05
flags: busy complete
In this example, I will resize a UFS file system under VxVM control from 3GB to 4GB using vxresize.
Current capacity:
# df -k /dbfiles03
Filesystem kbytes used avail capacity Mounted on
/dev/vx/dsk/dg20/dbvol03
3079710 2709166 308950 90% /dbfiles03
File system type:
# mount -v | grep /dbfiles03
/dev/vx/dsk/dg20/dbvol03 on /dbfiles03 type ufs read/write/setuid/intr/largefiles/onerror=panic/dev=3d1349e on Sun Aug 3 16:21:54 2003
Volume information:
# vxprint dbvol03
Disk group: dg20
TY NAME ASSOC KSTATE LENGTH PLOFFS STATE TUTIL0 PUTIL0
v dbvol03 fsgen ENABLED 6291456 - ACTIVE - -
pl dbvol03-01 dbvol03 ENABLED 6298619 - ACTIVE - -
sd dg2007-03 dbvol03-01 ENABLED 3149307 0 - - -
sd dg2006-03 dbvol03-01 ENABLED 3149307 0 - - -
Plex information:
# vxprint -l dbvol03-01
Disk group: dg20
Plex: dbvol03-01
info: len=6298619 contiglen=6298491
type: layout=STRIPE columns=2 width=128
state: state=ACTIVE kernel=ENABLED io=read-write
assoc: vol=dbvol03 sd=dg2007-03,dg2006-03
flags: busy complete
Increasing the volume to 4GB using vxresize:
# vxresize dbvol03 4g
/dev/vx/rdsk/dg20/dbvol03: 8388608 sectors in 4096 cylinders of 32 tracks, 64 sectors
4096.0MB in 88 cyl groups (47 c/g, 47.00MB/g, 7872 i/g)
super-block backups (for fsck -F ufs -o b=#) at:
32, 96352, 192672, 288992, 385312, 481632, 577952, 674272, 770592, 866912,
963232, 1059552, 1155872, 1252192, 1348512, 1444832, 1541152, 1637472,
1733792, 1830112, 1926432, 2022752, 2119072, 2215392, 2311712, 2408032,
2504352, 2600672, 2696992, 2793312, 2889632, 2985952, 3080224, 3176544,
3272864, 3369184, 3465504, 3561824, 3658144, 3754464, 3850784, 3947104,
4043424, 4139744, 4236064, 4332384, 4428704, 4525024, 4621344, 4717664,
4813984, 4910304, 5006624, 5102944, 5199264, 5295584, 5391904, 5488224,
5584544, 5680864, 5777184, 5873504, 5969824, 6066144, 6160416, 6256736,
6353056, 6449376, 6545696, 6642016, 6738336, 6834656, 6930976, 7027296,
7123616, 7219936, 7316256, 7412576, 7508896, 7605216, 7701536, 7797856,
7894176, 7990496, 8086816, 8183136, 8279456, 8375776,
New capacity:
# df -k /dbfiles03
Filesystem kbytes used avail capacity Mounted on
/dev/vx/dsk/dg20/dbvol03
4106286 2709166 1335526 67% /dbfiles03
New volume information (two new subdisks):
# vxprint dbvol03
Disk group: dg20
TY NAME ASSOC KSTATE LENGTH PLOFFS STATE TUTIL0 PUTIL0
v dbvol03 fsgen ENABLED 8388608 - ACTIVE - -
pl dbvol03-01 dbvol03 ENABLED 8395767 - ACTIVE - -
sd dg2007-03 dbvol03-01 ENABLED 3149307 0 - - -
sd dg2007-05 dbvol03-01 ENABLED 1048572 3149307 - - -
sd dg2006-03 dbvol03-01 ENABLED 3149307 0 - - -
sd dg2006-05 dbvol03-01 ENABLED 1048572 3149307 - - -
New plex information:
# vxprint -l dbvol03-01
Disk group: dg20
Plex: dbvol03-01
info: len=8395767 contiglen=8395639
type: layout=STRIPE columns=2 width=128
state: state=ACTIVE kernel=ENABLED io=read-write
assoc: vol=dbvol03 sd=dg2007-03,dg2007-05,dg2006-03,dg2006-05
flags: busy complete
VxVM Creating a volume with vxmake
Creating a volume with vxmake
In this example, I create a 26 GB concatenated volume named EZTK-NEW using disks in disk group dg15. The volume consists of 3 plexes (3 copies of the data). Each plex is composed of two 13 GB subdisks.
1. Identify disks in disk group dg15 that have enough free space to create a 13 GB subdisk.
# vxdg -g dg15 free
DISK DEVICE TAG OFFSET LENGTH FLAGS
S-f0 c1t0d0s2 c1t0d0 35302304 61256 -
S-f1 c1t1d0s2 c1t1d0 35302304 61256 -
S-f2 c1t2d0s2 c1t2d0 35302304 61256 -
S-f3 c1t3d0s2 c1t3d0 35302304 61256 -
S-f4 c1t4d0s2 c1t4d0 35302304 61256 -
S-f6 c1t6d0s2 c1t6d0 35302304 61256 -
S-f9 c1t9d0s2 c1t9d0 17062152 18301408 -
S-f10 c1t10d0s2 c1t10d0 20973112 14385736 -
The LENGTH column displays the number of free sectors on the disk (each sector is 512 bytes). Although not displayed here, disks b1-r2, b1-r9, b1-f4, b1-f6, b2-f4, and b2-r2 have enough free space to create 13 GB subdisks.
2. Create the subdisks.
Syntax:
# vxmake sd subdisk diskname,offset,length
Plex one:
# vxmake -g dg15 sd b1-r2-01 b1-r2,0,13g
# vxmake -g dg15 sd b1-r9-01 b1-r9,0,13g
Plex two:
# vxmake -g dg15 sd b1-f4-01 b1-f4,6582664,13g
# vxmake -g dg15 sd b1-f6-01 b1-f6,0,13g
Plex three:
# vxmake -g dg15 sd b2-f4-01 b2-f4,6582664,13g
# vxmake -g dg15 sd b2-r2-01 b2-r2,0,13g
3. Create the three plexes and associate the subdisks with them.
Syntax:
# vxmake plex plex sd=subdisk1[,subdisk2,...]
Plex one named EZTK-P01:
# vxmake -g dg15 plex EZTK-NEW-P01 sd=b1-r2-01,b1-r9-01
Plex two named EZTK-P02:
# vxmake -g dg15 plex EZTK-NEW-P02 sd=b1-f4-01,b1-f6-01
Plex three named EZTK-P03:
# vxmake -g dg15 plex EZTK-NEW-P03 sd=b2-f4-01,b2-r2-01
4. Create the volume consisting of the three plexes.
Creating volume EZTK-NEW composed of plexes EZTK-P01, EZTK-P02, and EZTK-P03:
# vxmake -g dg15 -U gen vol EZTK-NEW plex=EZTK-NEW-P01,EZTK-NEW-P02,EZTK-NEW-P03
5. Initialize the volume.
# vxvol start EZTK-NEW
The volume has been created. Before you are able to mount this volume as a file system, you will have to create a file system (UFS or vxfs) using newfs.
In this example, I create a 26 GB concatenated volume named EZTK-NEW using disks in disk group dg15. The volume consists of 3 plexes (3 copies of the data). Each plex is composed of two 13 GB subdisks.
1. Identify disks in disk group dg15 that have enough free space to create a 13 GB subdisk.
# vxdg -g dg15 free
DISK DEVICE TAG OFFSET LENGTH FLAGS
S-f0 c1t0d0s2 c1t0d0 35302304 61256 -
S-f1 c1t1d0s2 c1t1d0 35302304 61256 -
S-f2 c1t2d0s2 c1t2d0 35302304 61256 -
S-f3 c1t3d0s2 c1t3d0 35302304 61256 -
S-f4 c1t4d0s2 c1t4d0 35302304 61256 -
S-f6 c1t6d0s2 c1t6d0 35302304 61256 -
S-f9 c1t9d0s2 c1t9d0 17062152 18301408 -
S-f10 c1t10d0s2 c1t10d0 20973112 14385736 -
The LENGTH column displays the number of free sectors on the disk (each sector is 512 bytes). Although not displayed here, disks b1-r2, b1-r9, b1-f4, b1-f6, b2-f4, and b2-r2 have enough free space to create 13 GB subdisks.
2. Create the subdisks.
Syntax:
# vxmake sd subdisk diskname,offset,length
Plex one:
# vxmake -g dg15 sd b1-r2-01 b1-r2,0,13g
# vxmake -g dg15 sd b1-r9-01 b1-r9,0,13g
Plex two:
# vxmake -g dg15 sd b1-f4-01 b1-f4,6582664,13g
# vxmake -g dg15 sd b1-f6-01 b1-f6,0,13g
Plex three:
# vxmake -g dg15 sd b2-f4-01 b2-f4,6582664,13g
# vxmake -g dg15 sd b2-r2-01 b2-r2,0,13g
3. Create the three plexes and associate the subdisks with them.
Syntax:
# vxmake plex plex sd=subdisk1[,subdisk2,...]
Plex one named EZTK-P01:
# vxmake -g dg15 plex EZTK-NEW-P01 sd=b1-r2-01,b1-r9-01
Plex two named EZTK-P02:
# vxmake -g dg15 plex EZTK-NEW-P02 sd=b1-f4-01,b1-f6-01
Plex three named EZTK-P03:
# vxmake -g dg15 plex EZTK-NEW-P03 sd=b2-f4-01,b2-r2-01
4. Create the volume consisting of the three plexes.
Creating volume EZTK-NEW composed of plexes EZTK-P01, EZTK-P02, and EZTK-P03:
# vxmake -g dg15 -U gen vol EZTK-NEW plex=EZTK-NEW-P01,EZTK-NEW-P02,EZTK-NEW-P03
5. Initialize the volume.
# vxvol start EZTK-NEW
The volume has been created. Before you are able to mount this volume as a file system, you will have to create a file system (UFS or vxfs) using newfs.
понедельник, 30 марта 2009 г.
Solaris snoop
Запускаем snoop c опцией вывода в файл:
# snoop -o traff.snoop
Using device /dev/bge0 (promiscuous mode)
947 ^C
Читаем файл:
# snoop -i traff.snoop
1 0.00000 onehost -> sechost TCP D=45945 S=22 Push Ack=2115280484 Seq=3528084879 Len=48 Win=49232 ..
2 0.00034 sechost -> onehost TCP D=22 S=45945 Ack=3528084927 Seq=2115280484 Len=0 Win=306 ..
3 0.46298 onehost -> sechost TCP D=49560 S=3389 Push Ack=2640744155 Seq=289264955 Len=19 ..
4 0.00018 192.168.1.27 -> onehost TCP D=49560 S=3389 Push Ack=2640744155 Seq=289264955 Len=19 ..
...
C помощью опции -N можно создать файл хостов, который потом пригодится:
# snoop -i traff.snoop -N
Creating name file traff.snoop.names
# cat traff.snoop.names
192.168.1.1 onehost
192.168.1.2 sechost
А можно не резолвить имена хостов (с помощью опции -r):
# snoop -i traff.snoop -r
Loading name file traff.snoop.names
1 0.00000 192.168.1.1 -> 192.168.1.2 TCP D=45945 S=22 Push Ack=2115280484 Seq=3528084879 Len=48 Win=49232 ..
2 0.00034 192.168.1.2 -> 192.168.1.1 TCP D=22 S=45945 Ack=3528084927 Seq=2115280484 Len=0 Win=306 ..
3 0.46298 192.168.1.1 -> 192.168.1.2 TCP D=49560 S=3389 Push Ack=2640744155 Seq=289264955 Len=19 ..
4 0.00018 192.168.1.27 -> 192.168.1.1 TCP D=49560 S=3389 Push Ack=2640744155 Seq=289264955 Len=19 ..
...
Ищем пакеты до/от хоста onehost:
# snoop -i traff.snoop onehost
Ищем пакеты между хостами onehost и sechost:
# snoop -i traff.snoop onehost sechost
Ищем пакеты от/до onehost или от/до sechost:
# snoop -i traff.snoop 192.168.1.1 192.168.1.2
Фильтруем по номеру порта (из /etc/services) или IP-адресу или имени хоста:
# snoop -i traff.snoop port 22
# snoop -i traff.snoop onehost sechost port 22
# snoop -i traff.snoop onehost sechost port 20 or port 21
# snoop -i traff.snoop rpc nfs
# snoop -i traff.snoop rpc nfs or rpc mount
# snoop -i traff.snoop onehost sechost port 2049
# snoop -i traff.snoop onehost sechost port 2049 or port 111 or rpc nfs or rpc mount
Фильтруем по порту клиента:
# snoop -i traff.snoop port 31337
# snoop -i traff.snoop onehost sechost port 31337
Loading name file traff.snoop.names
1 0.00000 sechost-> onehost SMTP C port=31337
2 0.00003 onehost -> sechost SMTP R port=31337
3 0.00035 sechost -> onehost SMTP C port=31337
Смотрим пакеты с определенным номером (если слишком большой файл):
# snoop -i traff.snoop -p 3000,3005
Loading name file traff.snoop.names
3000 0.00011 onehost -> sechost TCP D=2049 S=43979 Ack=390431550 Seq=222075593 Len=0 Win=24820
3001 0.00024 onehost -> sechost TCP D=2049 S=43979 Fin Ack=390431550 Seq=222075593 Len=0 Win=24820
3002 0.00033 sechost -> onehost TCP D=43979 S=2049 Ack=222075594 Seq=390431550 Len=0 Win=24820
3003 0.00039 sechost -> onehost TCP D=43979 S=2049 Fin Ack=222075594 Seq=390431550 Len=0 Win=24820
3004 0.00475 onehost -> sechost TCP D=2049 S=43979 Ack=390431551 Seq=222075594 Len=0 Win=24820
3005 0.00021 onehost -> sechost TCP D=2049 S=698 Syn Seq=222184946 Len=0 Win=24820 Options=
Применяем различные фильтры:
# snoop -i traff.snoop arp
1 0.00000 192.168.1.2 -> (broadcast) ARP C Who is 192.168.1.1, 192.168.1.1 ?
2 0.34124 192.168.1.2 -> (broadcast) ARP C Who is 192.168.1.1, 192.168.1.1 ?
# snoop -i traff.snoop icmp
1 0.00000 192.168.1.2 -> 192.168.1.1 ICMP Echo request (ID: 5217 Sequence number: 0)
2 0.04178 192.168.1.2 -> 1192.168.1.1 ICMP Echo request (ID: 5219 Sequence number: 0)
# snoop -i traff.snoop udp
1 0.00000 192.168.1.2 -> 192.168.168.255 NIS C DOMAIN_NONACK sechost
2 2.23892 192.168.1.2 -> 192.168.1.255 NIS C DOMAIN_NONACK sechost (retransmit)
Выводим информацию по протоколу:
# snoop -i nfs.snoop -p23 -V
Loading name file nfs.snoop.names
23 0.00000 onehost -> sechost ETHER Type=0800 (IP), size = 206 bytes
23 0.00000 onehost -> sechost IP D=192.168.1.1 S=192.168.55.106 LEN=192, ID=45661, TOS=0x0, TTL=64
23 0.00000 onehost -> sechost TCP D=2049 S=698 Push Ack=390460868 Seq=222184947 Len=152 Win=24820
23 0.00000 onehost -> sechost RPC C XID=1096378150 PROG=100003 (NFS) VERS=3 PROC=19
23 0.00000 onehost -> sechost NFS C FSINFO3 FH=0222
# snoop -i nfs.snoop -p23 -v
Loading name file nfs.snoop.names
......
ETHER:
IP: ----- IP Header -----
IP:
IP: Version = 4
IP: Header length = 20 bytes
IP: Type of service = 0x00
IP: xxx. .... = 0 (precedence)
IP: ...0 .... = normal delay
IP: .... 0... = normal throughput
IP: .... .0.. = normal reliability
IP: .... ..0. = not ECN capable transport
IP: .... ...0 = no ECN congestion experienced
IP: Total length = 192 bytes
IP: Identification = 45661
IP: Flags = 0x4
IP: .1.. .... = do not fragment
IP: ..0. .... = last fragment
IP: Fragment offset = 0 bytes
IP: Time to live = 64 seconds/hops
IP: Protocol = 6 (TCP)
IP: Header checksum = 2175
Ищем Seq/Ack номер:
# snoop -i traff.snoop -V | grep TCP
1 0.00000 onehost -> sechost TCP D=8080 S=32867 Syn Seq=317534064 Len=0 Win=49640 Options=
2 0.00049 sechost -> onehost TCP D=32867 S=8080 Syn Ack=317534065 Seq=178080057 Len=0 Win=49640 Options=
3 0.00008 onehost -> sechost TCP D=8080 S=32867 Ack=178080058 Seq=317534065 Len=0 Win=49640
4 0.00377 onehost -> sechost TCP D=8080 S=32867 Push Ack=178080058 Seq=317534065 Len=209 Win=49640
Определяем время прохождения пакета:
# snoop -i traff.snoop -ta -p9,13
Loading name file traff.snoop.names
5 18:10:54.71861 onehost -> sechost HTTP (proxy) R port=41579
6 18:10:55.03142 onehost -> sechost HTTP HTTP/1.1 200 OK
7 18:10:55.03168 sechost -> onehost HTTP (proxy) C port=41579
8 18:10:56.37426 onehost -> sechost HTTP (body)
9 18:10:56.47427 sechost -> onehost HTTP (proxy) C port=41579
Определяем время передачи данных по FTP:
# snoop -i ftp.snoop -tr port 20 | tail -1
123 1.347823 192.168.1.1 -> 192.168.1.2 FTP-DATA C port=32725
Итого: 1.347823 sec
Просматриваем содержимое пакета:
# snoop -i traff.snoop -p4 -x0
0.00778 onehost -> sechost HTTP GET http://sunhelp.ru/files/memstat.tar.gz HTTP/1.1
0: 0008 a4d2 5e40 0800 20a0 166a 0800 4500 ....^@.. ..f..Y.
16: 00f9 dc05 4000 4006 b0be 0a0e 025f 819e ...@.@......_..
32: 1f30 8063 1f90 12ed 2f71 0a9d 493a 5018 .N.d..../w..I:P.
48: c1e8 d859 0000 4745 5420 6874 7470 3a2f ...Y..GET http:/
Подписаться на:
Сообщения (Atom)
