From 5bf5cb5a2c94e6d85c2587123ad28d803b2eddba Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Bal=C3=A1zs=20Hajgat=C3=B3?= Date: Wed, 26 Feb 2025 14:44:04 +0100 Subject: [PATCH 1/5] Add outgoing IP/firewall --- mkdocs/docs/HPC/troubleshooting.md | 17 +++++++++++++++++ 1 file changed, 17 insertions(+) diff --git a/mkdocs/docs/HPC/troubleshooting.md b/mkdocs/docs/HPC/troubleshooting.md index 29af13eb9d5f..3514e737699e 100644 --- a/mkdocs/docs/HPC/troubleshooting.md +++ b/mkdocs/docs/HPC/troubleshooting.md @@ -291,6 +291,23 @@ ssh -vvv {{ userid }}@{{ loginnode }} and include the output of that command in the message. {% endif %} +{% if site == gent %} +## Issues reaching servers from HPC infrastructure + +If you have to reach license servers from {{ hpcinfra }} systems or you +have to directly load some database here, then it might not work (you will get +network connection timed out or network connection refused error). Our +firewall rules are quite strict, we only allow outging ports 22 (SSH protocol), + 80 (HTTP protocol), and 443 (HTTPS protcol), so if your download or license server +requires other ports, then we should make a modification in our firewall settings. +For this, please contact us via <{{ hpcinfo }}>, and send the destination IP and ports. +(We only open our fireall for static IP addresses). + +It might possible, that the other end has also firewall, or the license server restricts +the incoming IP addresses. In this case you need the outgoing IP address of our systems, +which is either `157.193.240.251` (nathpca001.ugent.be) or `157.193.241.251` (nathpcb001.ugent.be). +{% endif %} + ## Security warning about invalid host key If you get a warning that looks like the one below, it is possible that From a576931533a3de00c5037a4c7ed2b5ccdb6da67e Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Bal=C3=A1zs=20Hajgat=C3=B3?= Date: Wed, 26 Feb 2025 15:11:07 +0100 Subject: [PATCH 2/5] fix typo --- mkdocs/docs/HPC/troubleshooting.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/mkdocs/docs/HPC/troubleshooting.md b/mkdocs/docs/HPC/troubleshooting.md index 3514e737699e..7ff96df132af 100644 --- a/mkdocs/docs/HPC/troubleshooting.md +++ b/mkdocs/docs/HPC/troubleshooting.md @@ -301,7 +301,7 @@ firewall rules are quite strict, we only allow outging ports 22 (SSH protocol), 80 (HTTP protocol), and 443 (HTTPS protcol), so if your download or license server requires other ports, then we should make a modification in our firewall settings. For this, please contact us via <{{ hpcinfo }}>, and send the destination IP and ports. -(We only open our fireall for static IP addresses). +(We only open our firewall for static IP addresses). It might possible, that the other end has also firewall, or the license server restricts the incoming IP addresses. In this case you need the outgoing IP address of our systems, From 7ec70ae2635e3b4cf813154decf29cae35dbd25c Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Bal=C3=A1zs=20Hajgat=C3=B3?= Date: Wed, 26 Feb 2025 15:12:48 +0100 Subject: [PATCH 3/5] fix typo --- mkdocs/docs/HPC/troubleshooting.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/mkdocs/docs/HPC/troubleshooting.md b/mkdocs/docs/HPC/troubleshooting.md index 7ff96df132af..2d8e2a16c889 100644 --- a/mkdocs/docs/HPC/troubleshooting.md +++ b/mkdocs/docs/HPC/troubleshooting.md @@ -303,7 +303,7 @@ requires other ports, then we should make a modification in our firewall setting For this, please contact us via <{{ hpcinfo }}>, and send the destination IP and ports. (We only open our firewall for static IP addresses). -It might possible, that the other end has also firewall, or the license server restricts +It might be possible, that the other end also has firewall, or the license server restricts the incoming IP addresses. In this case you need the outgoing IP address of our systems, which is either `157.193.240.251` (nathpca001.ugent.be) or `157.193.241.251` (nathpcb001.ugent.be). {% endif %} From 8123340ff3e165d1c08b18fc7909b27a0bbe9720 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Bal=C3=A1zs=20Hajgat=C3=B3?= Date: Wed, 26 Feb 2025 19:02:45 +0100 Subject: [PATCH 4/5] Apply suggestions from code review Co-authored-by: Kenneth Hoste --- mkdocs/docs/HPC/troubleshooting.md | 14 +++++++++----- 1 file changed, 9 insertions(+), 5 deletions(-) diff --git a/mkdocs/docs/HPC/troubleshooting.md b/mkdocs/docs/HPC/troubleshooting.md index 2d8e2a16c889..d3d194791fe4 100644 --- a/mkdocs/docs/HPC/troubleshooting.md +++ b/mkdocs/docs/HPC/troubleshooting.md @@ -295,17 +295,21 @@ and include the output of that command in the message. ## Issues reaching servers from HPC infrastructure If you have to reach license servers from {{ hpcinfra }} systems or you -have to directly load some database here, then it might not work (you will get -network connection timed out or network connection refused error). Our -firewall rules are quite strict, we only allow outging ports 22 (SSH protocol), +have to directly load some database here, then it might not work +(you will get errors like `Network connection timed out` or `Network connection refused`). + +Our firewall rules are quite strict, we only allow outging ports 22 (SSH protocol), 80 (HTTP protocol), and 443 (HTTPS protcol), so if your download or license server requires other ports, then we should make a modification in our firewall settings. For this, please contact us via <{{ hpcinfo }}>, and send the destination IP and ports. (We only open our firewall for static IP addresses). -It might be possible, that the other end also has firewall, or the license server restricts +It is possible that the other end also has firewall, or that the license server restricts the incoming IP addresses. In this case you need the outgoing IP address of our systems, -which is either `157.193.240.251` (nathpca001.ugent.be) or `157.193.241.251` (nathpcb001.ugent.be). +which is either of: + +- `157.193.240.251` (hostname `nathpca001.ugent.be`), or +- `157.193.241.251` (hostname `nathpcb001.ugent.be`) {% endif %} ## Security warning about invalid host key From 53aa1fa7caa2eacbfe7daabb982c6a7d54969464 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Bal=C3=A1zs=20Hajgat=C3=B3?= Date: Thu, 27 Feb 2025 08:48:43 +0100 Subject: [PATCH 5/5] Update mkdocs/docs/HPC/troubleshooting.md Co-authored-by: Kenneth Hoste --- mkdocs/docs/HPC/troubleshooting.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/mkdocs/docs/HPC/troubleshooting.md b/mkdocs/docs/HPC/troubleshooting.md index d3d194791fe4..9de1484c0bf9 100644 --- a/mkdocs/docs/HPC/troubleshooting.md +++ b/mkdocs/docs/HPC/troubleshooting.md @@ -304,7 +304,7 @@ requires other ports, then we should make a modification in our firewall setting For this, please contact us via <{{ hpcinfo }}>, and send the destination IP and ports. (We only open our firewall for static IP addresses). -It is possible that the other end also has firewall, or that the license server restricts +Take into account that the other end may also has a firewall, or that the license server may restrict the incoming IP addresses. In this case you need the outgoing IP address of our systems, which is either of: