DS-System replication group connection fails in one direction because the remote host firewall rejects replication ports

Modified on Sun, 27 Sep at 2:50 PM

DS-System replication group connection fails in one direction because the remote host firewall rejects replication ports

Machine-distilled from a resolved support ticket on 2026-09-27. Source ref: 09f4dbd4570f. Verify before relying on it.

Applies to: DS-System to DS-System replication (for example live replication used to migrate or export data between DS-Systems), DS-Systems on Linux hosts with a local firewall; version not specific

Symptom: Adding a remote DS-System to a replication group, or sharing an account for replication, fails with a connection error from one side. The same operation started from the other DS-System succeeds, so connectivity appears to work in one direction only.

Cause: The replication ports (4409, and 4401 in the observed case) were not permitted inbound by the remote DS-System host's own firewall. A default RHEL/CentOS style rule set ends the INPUT chain with 'REJECT, reject-with icmp-host-prohibited', so any port without an explicit allow rule is actively rejected. Outbound rules on the originating DS-System were already correct, so the fault was entirely at the receiving end.

Resolution: 1. From the originating DS-System's command line, test each relevant port on the remote DS-System, for example: nc -zv -w5 <remote DS-System address> <port>, for 22, 80, 443, 4401 and 4409.

2. Interpret the results: 'succeeded' means the path, NAT and host are fine for that port. 'timed out' means packets are silently dropped, usually by an edge firewall with a DROP policy. 'No route to host' or an immediate refusal means something is actively rejecting with ICMP administratively prohibited, typically an explicit reject rule in the remote host's own firewall.

3. If the replication ports are actively rejected while other ports such as SSH succeed, have the remote DS-System administrator add inbound allow rules for the replication ports in the host firewall (and on any edge device), limited to the originating DS-System's public address.

4. Re-run the nc tests to confirm the ports now connect, then add the DS-Systems to the replication group again and share the account. Replication should then start.

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article