Re: NFS connection dropped
Kevin Ferguson <[email protected]>
| Newsgroups | gmane.network.guarddog |
|---|---|
| Message-ID | <[email protected]> |
Hi Kimmo Because I've not used Suse I would assume its has some wizard that allows you configure NFS server? Ok if your able to connect to your server, with out guarddog. This would suggest not all your ports are open, or the NFS server option has not been enabled in guarddog. If you go to Local zone, -->file transfer - Netork file system --> put a tick in H-zone. LEAVE INTERNET ALONE. Do the same for Lan zone and put a check in h-zone. click apply then ok. This needs to be done both for server and client NFS. You are right if the protocals are enabled in the zones the ports become active. If protocals are not enabled. Then the service won't work. Kimmo can you type tail +f /var/log/messages as root. Try to connect your nfs server what should be shown is *DROPED in=Eth0 *this will show what was blocked along with source and destination port too. Let me know how you get on Regards Kevin K. Elo wrote: >Hi again, > >Kevin Ferguson wrote on 31.5.2005 at 13:26: > > >>Hi Kimmo >> >>I've attempted NFS using guraddog and it does work. However this was >>some months ago. It worth checking you exports are setup correctly, >>in /etc/exports. I got this wrong, although I could ping the server, >>I could not connect to the share. It sounds more like a >>configuration problem than guarddog issue. have you tried dropping >>the firewall and testing your nfs connection? Have you previosly had >>your nfs server working prior to installing guarddog? >> >> > >Well, the problem seems to be linked with Guarddog. When I dropped the >firewall I could establish a connection to the nfs server and transport >data between it and the client. The /etc/exports file is configured >with YaST and seems to be OK, too. So, obviously the firewall is too >"hardened" - I just cannot figure out what services should be enabled >(ftp, http ... ). As I mentioned, the connection is dropped by Guarddog >on laptop (I controlled the log console after I had given the "mount" >command) so the attempt never reaches the server... > >BTW, if I have understood the logic of guarddog right, permitting *all* >protocols between "local" and "h-network" zones should do no or only >little harm, if at the same time there are _no_ permitted protocols >between "internet" and "h-network" zones and only the crucially needed >between "internet" and "local" zones. The "h-network" has no public IP >addresses and, thus, is not browseable from outside, right? Only if >someone from outside could intrude the PC/laptop, he/she should be able >to attack the nfs-server/client. > >Kind regards, > >Kimmo > > >------------------------------------------------------- >SF.Net email is Sponsored by the Better Software Conference & EXPO >September 19-22, 2005 * San Francisco, CA * Development Lifecycle Practices >Agile & Plan-Driven Development * Managing Projects & Teams * Testing & QA >Security * Process Improvement & Measurement * http://www.sqe.com/bsce5sf >_______________________________________________ >Guarddog-user mailing list >[email protected] >https://lists.sourceforge.net/lists/listinfo/guarddog-user > > > > ------------------------------------------------------- SF.Net email is Sponsored by the Better Software Conference & EXPO September 19-22, 2005 * San Francisco, CA * Development Lifecycle Practices Agile & Plan-Driven Development * Managing Projects & Teams * Testing & QA Security * Process Improvement & Measurement * http://www.sqe.com/bsce5sf