==============================================================================================shell
rsync服務端開啓的iptables防火牆vim
[root@nfs01 tmp]# rsync -avz /etc/hosts rsync_backup@172.16.1.41::backup安全
rsync: failed to connect to 172.16.1.41: No route to host (113)服務器
rsync error: error in socket IO (code 10) at clientserver.c(124) [sender=3.0.6]ssh
異常問題解決:socket
關閉rsync服務端的防火牆服務(iptables)tcp
[root@backup mnt]# /etc/init.d/iptables stop測試
iptables: Setting chains to policy ACCEPT: filter [ OK ]ui
iptables: Flushing firewall rules: [ OK ]rest
iptables: Unloading modules: [ OK ]
[root@backup mnt]# /etc/init.d/iptables status
iptables: Firewall is not running.
==============================================================================================
rsync客戶端執行rsync命令錯誤:
客戶端的錯誤現象:
[root@nfs01 tmp]# rsync -avz /etc/hosts rsync_backup@172.16.1.41::/backup
ERROR: The remote path must start with a module name not a /
rsync error: error starting client-server protocol (code 5) at main.c(1503) [sender=3.0.6]
異常問題解決:
rsync命令語法理解錯誤,::/backup是錯誤的語法,應該爲::backup(rsync模塊)
==============================================================================================
3. @ERROR: auth failed on module oldboy
客戶端的錯誤現象:
[root@nfs01 tmp]# rsync -avz /etc/hosts rsync_backup@172.16.1.41::backup
Password:
@ERROR: auth failed on module backup
rsync error: error starting client-server protocol (code 5) at main.c(1503) [sender=3.0.6]
異常問題解決:
1. 密碼真的輸入錯誤,用戶名真的錯誤
2. secrets file = /etc/rsync.password指定的密碼文件和實際密碼文件名稱不一致
3. /etc/rsync.password文件權限不是600
4. rsync_backup:123456密碼配置文件後面注意不要有空格
5. rsync客戶端密碼文件中只輸入密碼信息便可,不要輸入虛擬認證用戶名稱
==============================================================================================
4. Unknown module 'backup'
[root@nfs01 tmp]# rsync -avz /etc/hosts rsync_backup@172.16.1.41::backup
@ERROR: Unknown module 'backup'
rsync error: error starting client-server protocol (code 5) at main.c(1503) [sender=3.0.6]
異常問題解決:
一、 /etc/rsyncd.conf配置文件模塊名稱書寫錯誤
二、配置文件中網段限制不對
==============================================================================================
[root@nfs01 tmp]# rsync -avz /etc/hosts rsync_backup@172.16.1.41::backup
Password:
sending incremental file list
hosts
rsync: mkstemp ".hosts.5z3AOA" (in backup) failed: Permission denied (13)
sent 196 bytes received 27 bytes 63.71 bytes/sec
total size is 349 speedup is 1.57
rsync error: some files/attrs were not transferred (see previous errors) (code 23) at main.c(1039) [sender=3.0.6]
異常問題解決:
1. 共享目錄的屬主和屬組不正確,不是rsync
2. 共享目錄的權限不正確,不是755
==============================================================================================
[root@nfs01 tmp]# rsync -avz /etc/hosts rsync_backup@172.16.1.41::backup
Password:
@ERROR: chdir failed
rsync error: error starting client-server protocol (code 5) at main.c(1503) [sender=3.0.6]
異常問題解決:
1. 備份存儲目錄沒有創建
2. 創建的備份存儲目錄和配置文件定義不一致
[root@backup backup]# /etc/init.d/xinetd restart
shell-init: error retrieving current directory: getcwd: cannot access parent directories: No such file or directory
Stopping xinetd: [ OK ]
Starting xinetd: shell-init: error retrieving current directory: getcwd: cannot access parent directories: No such file or directory
[ OK ]
說明:若是沒有備份存儲目錄,xinetd服務都不能正確啓動
==============================================================================================
[root@nfs01 tmp]# rsync -avz /etc/hosts rsync_backup@172.16.1.41::backup
Password:
@ERROR: invalid uid rsync
rsync error: error starting client-server protocol (code 5) at main.c(1503) [sender=3.0.6]
異常問題解決:
rsync服務對應rsync虛擬用戶不存在了
==============================================================================================
password file must not be other-accessible
[root@nfs01 tmp]# rsync -avz /etc/hosts rsync_backup@172.16.1.41::backup --password-file=/etc/rsync.password
password file must not be other-accessible
continuing without password file
Password:
sending incremental file list
sent 26 bytes received 8 bytes 5.23 bytes/sec
total size is 349 speedup is 10.26
異常問題解決:
rsync客戶端的祕鑰文件也必須是600權限
==============================================================================================
錯誤日誌輸出
2017/03/08 20:14:43 [3422] params.c:Parameter() - Ignoring badly formed line in configuration file: ignore errors
2017/03/08 20:14:43 [3422] name lookup failed for 172.16.1.31: Name or service not known
2017/03/08 20:14:43 [3422] connect from UNKNOWN (172.16.1.31)
2017/03/08 20:14:43 [3422] rsync to backup/ from rsync_backup@unknown (172.16.1.31)
2017/03/08 20:14:43 [3422] receiving file list
2017/03/08 20:14:43 [3422] sent 76 bytes received 83 bytes total size 349
正確日誌輸出
2017/03/08 20:16:45 [3443] params.c:Parameter() - Ignoring badly formed line in configuration file: ignore errors
2017/03/08 20:16:45 [3443] connect from nfs02 (172.16.1.31)
2017/03/08 20:16:45 [3443] rsync to backup/ from rsync_backup@nfs02 (172.16.1.31)
2017/03/08 20:16:45 [3443] receiving file list
2017/03/08 20:16:45 [3443] sent 76 bytes received 83 bytes total size 349
異常問題解決:
查看日誌進行分析
==============================================================================================
[root@oldboy-muban ~]# rsync -avz /etc/hosts rsync_backup@172.16.1.41::backup
rsync: failed to connect to 172.16.1.41: Connection refused (111)
rsync error: error in socket IO (code 10) at clientserver.c(124) [sender=3.0.6]
解決 rsync服務沒開啓
[root@oldboy-muban ~]# rsync --daemon
[root@oldboy-muban ~]# ss -lntup |grep rsync
tcp LISTEN 0 5 :::873 :::* users:(("rsync",1434,5))
tcp LISTEN 0 5 *:873 *:* users:(("rsync",1434,4))
[root@oldboy-muban ~]# rsync -avz /etc/hosts rsync_backup@172.16.1.41::backup
Password:
sending incremental file list
hosts
sent 196 bytes received 27 bytes 49.56 bytes/sec
total size is 349 speedup is 1.57
==============================================================================================
環境:本地服務器集羣內部傳輸利用遠程ssh 報錯
利用(telnet 172.16.1.31 22) 排查服務監聽狀態後採起的解決方法
[root@oldboy-muban ~]# rsync /etc/hosts 172.16.1.31:/tmp
ssh: connect to host 172.16.1.31 port 22: Connection refused
rsync: connection unexpectedly closed (0 bytes received so far) [sender]
rsync error: error in rsync protocol data stream (code 12) at io.c(600) [sender=3.0.6]
排錯思路:
[root@oldboy-muban ~]# ping 172.16.1.31
PING 172.16.1.31 (172.16.1.31) 56(84) bytes of data.
64 bytes from 172.16.1.31: icmp_seq=1 ttl=64 time=0.628 ms
64 bytes from 172.16.1.31: icmp_seq=2 ttl=64 time=0.393 ms
64 bytes from 172.16.1.31: icmp_seq=3 ttl=64 time=1.06 ms
64 bytes from 172.16.1.31: icmp_seq=4 ttl=64 time=0.745 ms
[root@oldboy-muban ~]# traceroute 172.16.1.31
traceroute to 172.16.1.31 (172.16.1.31), 30 hops max, 60 byte packets
1 nfs01 (172.16.1.31) 0.597 ms 0.189 ms 0.965 ms
/etc/init.d/iptables status
iptables: Firewall is not running.
[root@backup ~]#
[root@backup ~]# netstat -lntup|grep 22
p 0 0 10.0.0.31:22 0.0.0.0:* LISTEN 1187/sshd
故障緣由:沒法鏈接
telnet 172.16.1.31 22
解決方法:
[root@oldboy-backup-41]# vim /etc/ssh/sshd_config
#Port 22
#AddressFamily any
#ListenAddress 10.0.0.31 改成 0.0.0.0
#ListenAddress ::
總結:內網傳輸經過SSH pro 22 代表22端口連接不上
==============================================================================================
報錯:--passwd-file=/etc/rsync.passwd: unknown option
錯誤案例 本地rsync.password 文件要保持一致缺乏字母都會報錯
echo "123456">>/etc/rsync.passwd
[root@nfs01 ~]# chmod 600 /etc/rsync.passwd
[root@nfs01 ~]# ll /etc/rsync.passwd
-rw------- 1 root root 7 Mar 9 13:47 /etc/rsync.passwd
[root@nfs01 ~]# rsync -az -P /root/ rsync_backup@172.16.1.41::backup --passwd-file=/etc/rsync.passwd
rsync: --passwd-file=/etc/rsync.passwd: unknown option
rsync error: syntax or usage error (code 1) at main.c(1422) [client=3.0.6]
正確作法:
[root@nfs01 ~]# echo "123456">>/etc/rsync.password
[root@nfs01 ~]# chmod 600 /etc/rsync.password
[root@nfs01 ~]# ll /etc/rsync.password
-rw------- 1 root root 7 Mar 9 13:49 /etc/rsync.password
rsync -az -P /server/files/secure-20161219 rsync_backup@172.16.1.41::backup --password-file=/etc/rsync.password
sending incremental file list
secure-20161219
51053780 100% 14.31MB/s 0:00:03 (xfer#1, to-check=0/1)
rsync: mkstemp ".secure-20161219.lcnuWA" (in backup) failed: Permission denied (13)
sent 2210982 bytes received 27 bytes 491335.33 bytes/sec
total size is 51053780 speedup is 23.09
rsync error: some files/attrs were not transferred (see previous errors) (code 23) at main.c(1039) [sender=3.0.6]
[root@backup ~]# ls /backup/
100.log cc.txt optimize-init_sys.sh
anaconda-ks.cfg
1)多是服務沒有開啓
2)iptables SELinux
3)本次碰見sshd傳輸受限 限制了傳輸的ip(安全)
==============================================================================================
m 查看rsync服務配置文件路徑是否正確 /etc/rsyncd.conf
m 查看配置文件例的host allow,host deny,容許的ip網段是不是容許客戶端訪問的ip網段
m 查看配置文件中path參數裏的路徑是否存在,權限是否正確(正常應爲配置文件中的UUID參數對應的屬主和組)
m 查看rsync服務是否啓動,端口是否存在 ps -ef netstat -lntup
m 查看iptables防火牆和SELinux是否開啓容許rsync服務經過,也能夠關閉
m 查看服務端rsync配置文件裏的密碼權限是否爲600 密碼文件格式是否正確,正確格式(用戶名:密碼)文件路徑和配置文件裏的secrect files 參數對應
m 若是是推送數據,要查看,配置rsyncd.conf 文件中用戶是否對模塊下目錄有可讀的權限
==============================================================================================
m 查看客戶端rsync配置的密碼文件是否爲600的權限,密碼文件格式是否正確,注意:僅須要有密碼,而且和服務端的密碼一致
m 用telnet連接rsync服務器ip地址873端口,查看服務是否啓動(可測試服務端防火牆是否阻擋telnet10.0.0.100 873)
m 客戶端執行命令是 rsync -avzP rsync_backup@10.0.0.100::backup/test/test/ --password-file=/etc/rsync.password
m 此命令要記清楚尤爲10.0.0.100::backup/test/處的雙引號及隨後的backup爲模塊名稱
==============================================================================================