Author Topic: DPR-ERR-2079 Firewall Security Rejection.  (Read 22513 times)

Offline SGD

  • Community Leader
  • *****
  • Join Date: Feb 2007
  • Posts: 176
  • Forum Citizenship: +0/-0
DPR-ERR-2079 Firewall Security Rejection.
« on: 07 Mar 2011 01:18:59 am »
Hi,

I am getting below error when I try to create datasource in FM or 'Data Source Connections' section in Cognos portal.

Quote
IBM Cognos 8
 
 
  An error has occurred.

 
   DPR-ERR-2079 Firewall Security Rejection. Your request was rejected by the security firewall. 
 
  CAF rejection details are available in the log. Please contact your administrator.


I have referred this https://www-304.ibm.com/support/docview.wss?uid=swg21339461 for the resolution of this issue but I have installed Cognos server on single machine.

There is only single Web & App Server and I have added the hostname:port entries for the same.

Any suggestion?

« Last Edit: 10 Mar 2011 12:45:50 am by Shirish Dawane »
Regards,
S.G.D.

Offline AussiePete2011

  • Statesman
  • ******
  • Join Date: Feb 2011
  • Posts: 311
  • Forum Citizenship: +19/-0
Re: DPR-ERR-2079 Firewall Security Rejection.
« Reply #1 on: 07 Mar 2011 06:43:12 pm »
Hi there

What I'd suggest (if possible) is turn off caf just for testing so that you can see what the real error is.
Once you have the true error then work with this

If you cant and its a production environment, try testing via the dispatcher URI rather than the Gateway in your browser.

What database are you trying to connect to and what data source connection are you selecting?

Cheers
Peter B

Offline SGD

  • Community Leader
  • *****
  • Join Date: Feb 2007
  • Posts: 176
  • Forum Citizenship: +0/-0
Re: DPR-ERR-2079 Firewall Security Rejection.
« Reply #2 on: 07 Mar 2011 07:31:40 pm »
Hi Peter,

I have already turned off CAF in Cognos Configuration and it started working temporarily however this is not a cognos standard to work with.

I am trying to connect to Oracle server which is installed on different server which is our Oracle database server. Actually this is SAN drive which we have map which acts as a local drive to Cognos server. TNS entries are also properly mentined in .ora file. I can connect with required database using Oracle SQL Plus from Cognos server.

I am selecting 'Oracle' as a datasource connection.

Please suggest.
Regards,
S.G.D.

Offline AussiePete2011

  • Statesman
  • ******
  • Join Date: Feb 2011
  • Posts: 311
  • Forum Citizenship: +19/-0
Re: DPR-ERR-2079 Firewall Security Rejection.
« Reply #3 on: 07 Mar 2011 08:10:32 pm »
Hi Shirish,

Thanks for the update.  I only suggested turning off CAF as a test and then only to see the underlying error, however, if turning off CAF allows this to work then the issue is likely to be a lookup issue as CAF encrypts the requests

See CAF
http://publib.boulder.ibm.com/infocenter/c8bi/v8r4m0/topic/com.ibm.swg.im.cognos.ug_cra.8.4.0.doc/ug_cra_id10940TheCognosApplicationFirewall.html#TheCognosApplicationFirewall

You could enable tracing of the CAF error
1.  Locate the ../<c8install>/configuration/ipfCAFclientconfig.xml.sample file
2.  Make a copy of this file
3.  Rename the copy to ipfclientconfig.xml
4.  Wait about a minute then test the data source connection with CAF on.
5.  Locate the ../<c8install>/logs folder and there shoulod now be a cogclient.log which should provide more details about the CAF error.

Make sure that
1.  All URI settings are using an Resolvable IP address or Server name
2.  The c8 services are started by a valid domain account.

Are you using Oracle as the Content store?  Is this able to connect successfully as this uses JDBC rather than SQLNet
I should also ask what version of Oracle are you attempting to connect to and on which version of Cognos...

Anyway there could be other issues with this but give the above some thought and provide fedback
Cheers
Peter B
 

Offline SGD

  • Community Leader
  • *****
  • Join Date: Feb 2007
  • Posts: 176
  • Forum Citizenship: +0/-0
Re: DPR-ERR-2079 Firewall Security Rejection.
« Reply #4 on: 07 Mar 2011 08:44:12 pm »
Hi Peter,

My Cognos server is in Workgroup not in domain. I have made servername entries in Cognos configuration which works as expected. I am using Cognos 8.4 with SQL Server 2005 as a content store but Oracle 10g as data source for reports.

With CAF off, I am trying to connect to Oracle for creation of new datasource it shows me below error when I test the connection.

Name:
Quote
http://servername:9300/p2pd

Status:
Quote
Failed

Message:
Quote
Handler trace back: [the_dispatcher] com.cognos.pogo.handlers.performance.PerformanceIndicationHandler [the_dispatcher] com.cognos.pogo.handlers.logic.ChainHandler [service_lookup] com.cognos.pogo.handlers.engine.ServiceLookupHandler [load_balancer] com.cognos.pogo.handlers.logic.ChainHandler [lb_forwarder] com.cognos.p2plb.clerver.LoadBalanceHandler [mdaChainHandler] com.cognos.pogo.handlers.logic.ChainHandler [asyncMetadataServiceHandler] com.cognos.pogo.async.impl.AsyncHandler [metadataServiceHandler] com.cognos.metadataService.bibusHandler.MDSRVHandler
Regards,
S.G.D.

Offline SGD

  • Community Leader
  • *****
  • Join Date: Feb 2007
  • Posts: 176
  • Forum Citizenship: +0/-0
Re: DPR-ERR-2079 Firewall Security Rejection.
« Reply #5 on: 07 Mar 2011 09:00:07 pm »
I get following error in cogserver.log file

Quote
IPaddress:9300   6120   2011-03-08 13:52:25.109   +10   Thread-80   caf   6008   1   Audit.dispatcher.caf   Request         Failure      check signature failed: passport => null
IPaddress:9300   6120   2011-03-08 13:52:25.109   +10      Thread-80   caf   6008   1   Audit.dispatcher.caf   Request         Failure      check signature failed: salted => true
IPaddress:9300   6120   2011-03-08 13:52:25.109   +10   Thread-80   caf   6008   1   Audit.dispatcher.caf   Request         Failure      invalid context id: context id => CAFW00000070Q0FGQTNjMDAwMDAwMDlGQUFBQUtacG00djVaQ3VmWUFzVFRXbWZ6cW80ZE9vclhtWFM1ZGRBWlFkMDFXVXJ2WDZXUnJGalBQQV8zNjA5ODZ8cHM_
IPaddress:9300   6120   2011-03-08 13:52:25.109   +10   Thread-80   caf   6008   1   Audit.dispatcher.caf   Request         Failure      check context id failed
IPaddress:9300   6120   2011-03-08 13:52:25.109   +10   Thread-80   caf   6008   1   Audit.dispatcher.caf   Request         Failure      check signature failed: string => 360986|ps
IPaddress:9300   6120   2011-03-08 13:52:25.109   +10   Thread-80   caf   6008   1   Audit.dispatcher.caf   Request         Failure      check signature failed: hmac => FAAAAKZpm4v5ZCufYAsTTWmfzqo4dOorXmXS5ddAZQd01WUrvX6WRrFjPPA_
IPaddress:9300   6120   2011-03-08 13:52:25.109   +10   Thread-80   caf   6008   1   Audit.dispatcher.caf   Request         Failure      unwrap and check signature failed: web64 decoded value => CAFA3c00000009FAAAAKZpm4v5ZCufYAsTTWmfzqo4dOorXmXS5ddAZQd01WUrvX6WRrFjPPA_360986|ps
IPaddress:9300   6120   2011-03-08 13:52:25.109   +10   Thread-80   caf   6008   1   Audit.dispatcher.caf   Request         Failure      context id signature check failed: unwrap context id =>
Regards,
S.G.D.

Offline AussiePete2011

  • Statesman
  • ******
  • Join Date: Feb 2011
  • Posts: 311
  • Forum Citizenship: +19/-0
Re: DPR-ERR-2079 Firewall Security Rejection.
« Reply #6 on: 07 Mar 2011 11:19:50 pm »
Thanks for the details.
This logs tells me there is a permission issue with the access to the location where you are read the database from using the Cognos credentials.
When CAF is on the account creating the data source is failing to pass the session information

This is a good link to understand Authentication across the network with CAF
http://www.ibm.com/developerworks/data/library/cognos/security/cognos8_platform/page511.html?ca=drs-

Out of curiousity, are you able to make an ODBC connection to the Oracle database?

Cheers
Peter B


Offline SGD

  • Community Leader
  • *****
  • Join Date: Feb 2007
  • Posts: 176
  • Forum Citizenship: +0/-0
Re: DPR-ERR-2079 Firewall Security Rejection.
« Reply #7 on: 07 Mar 2011 11:22:39 pm »

No, I have not tried to connect ODBC connection with Oracle. Could you please guide me how can I create and test the same?
Regards,
S.G.D.

Offline SGD

  • Community Leader
  • *****
  • Join Date: Feb 2007
  • Posts: 176
  • Forum Citizenship: +0/-0
Re: DPR-ERR-2079 Firewall Security Rejection.
« Reply #8 on: 08 Mar 2011 12:04:50 am »
I have uninstalled Cognos and reinstalled to the same SAN drive where Oracle is installed and it allowed me to create new Oracle data source connection keeping CAF off in Cognos Configuration.  :o
« Last Edit: 08 Mar 2011 01:07:52 am by Shirish Dawane »
Regards,
S.G.D.

Offline AussiePete2011

  • Statesman
  • ******
  • Join Date: Feb 2011
  • Posts: 311
  • Forum Citizenship: +19/-0
Re: DPR-ERR-2079 Firewall Security Rejection.
« Reply #9 on: 09 Mar 2011 06:12:44 pm »
Hi Shirish,

Sorry about the delay... you know.. work got in the way ;-)

Anyway thats interesting in that you installed Cognos to the SAN and it allows a connection to succeed although this was also the case with having Cognos installed else where with the CAF off.  With Cognos now installed on the SAN, can you successfully test a connection to Oracle with CAF on?

Cheers
Peter B

Offline SGD

  • Community Leader
  • *****
  • Join Date: Feb 2007
  • Posts: 176
  • Forum Citizenship: +0/-0
Re: DPR-ERR-2079 Firewall Security Rejection.
« Reply #10 on: 09 Mar 2011 09:29:44 pm »

No, it does not work with CAF 'ON' with Cognos installed on SAN drive and shows same error as mentioned at start of the post.  :(
Regards,
S.G.D.

Offline vybhav1908

  • Associate
  • **
  • Join Date: Apr 2015
  • Posts: 1
  • Forum Citizenship: +0/-0
Re: DPR-ERR-2079 Firewall Security Rejection.
« Reply #11 on: 28 Apr 2015 05:10:10 am »
Hello SGD

Are you able to get rid of this issue? I am on 10.2.1 and getting the exact same issue, disabled the siteminder, ssl still no good. I get the error on Cognos Connection wherever I click "More", "Set Properties", "Test Connection" etc. I am also getting the same errors in the CAF logs. Please advise.

Vaibhav

Offline gvsp

  • Associate
  • **
  • Join Date: Nov 2017
  • Posts: 2
  • Forum Citizenship: +0/-0
Re: DPR-ERR-2079 Firewall Security Rejection.
« Reply #12 on: 23 Feb 2018 06:12:10 am »
Hi , I too got same firewall security rejection error while opening the Report studio. To have this issue fixed, I have uninstalled CISCO anyconnect. Now, i am good to go with.

Thank you,
GVSP

 


       
Twittear