|
From: Alexander S. <as...@jw...> - 2004-03-18 23:23:43
|
Hi Bradley, Now I think understand what you want. There are generally 2 ways for it to go. 1. allow your clients behind the firewall to NAT out. This should work instantly. You won't need to make any further port-forwards, etc. In addition you should not care wether there is a node accessible directly in your group at all. AFAIK, you will go through an relay of the net-peer group if you can access the internet from your physical box. Anyway, if this does not work, come back. 2. allow only one machine of your subnet to (at best accessible as a server) access the internet (at best directly - no NAT) and deploy the minimum gateway node on it (as I made available to you). All other clients behind the firewall without access to the internet should be able to use this node as a relay to the outside. You should set the gateway node as rendevouz or relay as mentioned in my initial mail. (This szenario would be of most interest for me, so if possible, test it!) Let me know about both possibilities Thx Alex Bradley Stec wrote: >Thanks Alexander. > >I set it up on my Linux box and it started up just fine, confirmed that in >the log and could see open ports where you said they should be using >netstat. > >I appreciate you moving on this, but I don't think I explained my situation. >I should have been more descriptive. > >Here's the model I'm shooting for: > > Clients scattered throughout the Internet, most behind firewalls, >some not. > Mostly Windows clients, some Linux. All the clients would be using >the GUI interface. > >I was trying to figure out how to allow this group of clients to find each >other using a Linux server I have running outside of a firewall. I would >like to then run JXTA_IM as a service somehow and lock it as a rendezvous >server to allow this group of clients to find each other. > >I understand the peer-to-peer nature of JXTA and I'm very excited about the >potential to free myself and my friends from the AIM/MSN chat tool >advertisement quagmire. > >I was trying to circumvent the firewalls. Am I going down the wrong path? >Should I instead be focusing on allowing specific port traffic through >firewalls and using one-to-one NAT on specific clients? > >Thanks. >Brad Stec > > >-----Original Message----- >From: Alexander Sack [mailto:as...@jw...] >Sent: Thursday, March 18, 2004 11:00 AM >To: jxt...@li... >Cc: bs...@wh... >Subject: Re: [ jxtaim-Bugs-913259 ] Run As JXTA-Rendezvous without GUI > > >Hi, > >I uploaded a test pack for you. You can grab it from this url: > >http://jxtaim.sourceforge.net/jxta-test.tar.bz2 > >The archive contains 2 folders: jxtaim-test.1 & jxtaim-test-gate.1 > >The gateway tree must run on your gateway node. It should not open a >Gui. It is reduced to the jxta >core. I already preconfigured it so it is listening on port 9707 (tcp) & >9706 (http). Further I preconfigured it as a relay & rdv. So usually >this should not need any modifications. > > -- Remember this is designed for a scenario, where you want to build a >bridge from the inside to the outside through this gateway jxtaim >instance (e.g. your clients cannot access the internet, but your gateway >can) > >The second tree is the client tree. In order to test if the gateway node >works you need to ensure that your client will not be able to access the >inet. You can modify the entries for relay & rendevouz in the >conf/DefaultConfiguration.xml > >I predefined some values for my machine, so you can easily figure out >how to set it. You typically will need to replace my IP (192.168.0.2) >with the one of your gateway node. > >To test all this, simply start up the gateway node. There is no output >... nothing. It will be started up in a few seconds usually. You may want to >wait until the JIM.log tells that it became a rendevouz. > >After that, start the client. If all settings are correct you should see >your gateways ip & port during start up pop up in the JIM.log configured >as relay & rendevouz. Further just after startup you should see a single >rendevouz id for both, the netgroup & the VSISProjectGroup in Tools -> >Network Info. > > > > -- PGP messages preferred. | .''`. ** Debian GNU/Linux ** Alexander Sack | : :' : The universal as...@jw... | `. `' Operating System http://www.jwsdot.com/ | `- http://www.debian.org/ |