How to Configure Packet Filter
Read the guidelines and restrictions to follow when you configure the Packet Filter (PF) feature in a cluster. See the "Packet Filter (PF) Feature" bullet item in Oracle Solaris OS Feature Requirements and Restrictions.
Perform this procedure to configure the Packet Filter (PF) feature of Oracle Solaris software on the global cluster.
Note:
Only use PF with failover data services. The use of PF with scalable data services is not supported.For more information about the PF feature, see Oracle Solaris Firewall in Securing the Network in Oracle Solaris 11.4.
Example 2-1 Using an Exclusive IP Zone Cluster
This example shows how to configure an exclusive IP zone cluster.
# clnode status -m --- Node Public Network Status --- Node Name PNM Object Name Status Adapter Status --------- --------------- ------ ------- ------ node1 sc_ipmp0 Online scld02zc2pub1 Online node2 sc_ipmp0 Online scld02zc2pub1 Online # clintr status === Cluster Transport Paths === Endpoint1 Endpoint2 Status --------- --------- ------ node2:scld02zc2priv2 node1:scld02zc2priv2 Path online node2:scld02zc2priv1 node1:scld02zc2priv1 Path online # ipadm show-addr | egrep "scld02zc2priv1|scld02zc2priv2|clprivnet2" scld02zc2priv1/? static ok 172.18.4.66/26 scld02zc2priv2/? static ok 172.18.4.130/26 clprivnet2/? static ok 172.18.4.2/26 # grep -v ^# /etc/firewall/pf.conf | grep -v ^$ set reassemble yes no-df set skip on lo0 ext_if="sc_ipmp0" client_out="{22, 2084, 5201, 111, 8059, 8060, 8061, 8062, 6499, 11161, 11162, 11163, 11164, 11165}" pass in quick on scld02zc2priv1 all flags any pass in quick on scld02zc2priv2 all flags any pass in quick on clprivnet2 all flags any block in log quick on egress proto tcp to port { 22 } block return log all pass in log proto tcp from any to any port 22 <> 23 pass out log proto tcp from any to any pass in log proto udp from any to any pass out inet proto icmp all icmp-type echoreq keep state pass in log proto icmp from any to any pass out on $ext_if proto udp all pass out #
Next Steps
Configure Oracle Solaris Cluster software on the cluster nodes. Go to Establishing a New Global Cluster or New Global-Cluster Node.