[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Condor-users] condor_shared_port and NAT environment



Dear Oori,

We've been using Condor's CCB with VirtualBox's NAT networking with success. Our setup has the headnode/submit node with a proper IP address. All execute nodes are NATed and connect to the headnode using CCB. Putting submit nodes behind a NAT too won't work with CCB because at least one end of the job execution set needs to be able to receive connections.

We haven't tried condor_shared_port yet, but I imagine that you would have to setup VirtualBox's port forwarding to the guest port listening to that shared port. This may require some futzing with the Windows firewall settings too.

    Craig

On Jan 29, 2010, at 9:53 AM, U.H wrote:

Dear condor admins,

I’ve been looking around for a solution that will allow running condor
submit/execute machines behind a NAT dictated by a virtual
environment. Would appreciate any advice regarding the following
scenario: We have idle windows machines (hosts), and they are running
virtualbox with linux/condor installations on them (guests). The
headnode is located on a machine with a proper IP address and domain
name. Currently, in this configuration, the pool works fine.

The only issue is that the linux guests currently need their own IP
addresses, which drinks up IP addresses from our dhcp pool. I’d like
the guests to be able to work in (Virtualboxe's) NAT mode, where they
utilize the host’s IP address publicly. That is, each condor submit
machine works behind a different NAT.

Is it possible to run condor in this situation using the new
condor_shared_port directive so that all communication goes out
through that port? Would the central manager machine know to return
all communication through that port so that this port could be the
only one open in the NAT (i.e., guest machine?). Or is it the case
that while all outgoing communication will go through "shared_port",
returning communication will still expect to have  a large number of
ephemeral ports open?

Any info/hints/experiences, much appreciated.

Oori
_______________________________________________
Condor-users mailing list
To unsubscribe, send a message to condor-users-request@xxxxxxxxxxx with a
subject: Unsubscribe
You can also unsubscribe by visiting
https://lists.cs.wisc.edu/mailman/listinfo/condor-users

The archives can be found at:
https://lists.cs.wisc.edu/archive/condor-users/

--
Craig A. Struble, Ph.D. | 369 Cudahy Hall  | Marquette University
Associate Professor of Computer Science    | (414)288-3783
Director, Master of Bioinformatics Program | (414)288-5472 (fax)
http://www.mscs.mu.edu/~cstruble | craig.struble@xxxxxxxxxxxxx