Re: NFS connection dropped

Kevin Ferguson <[email protected]>
Newsgroups gmane.network.guarddog
Message-ID <[email protected]>
Hi Kimmo

Because I've not used Suse I would assume its has some wizard that 
allows you configure NFS server?  Ok if your able to connect to your 
server, with out guarddog.  This would suggest not all your ports are 
open, or the NFS server option has not been enabled in guarddog.  If you 
go to Local zone, -->file transfer - Netork file system --> put a tick 
in H-zone.  LEAVE INTERNET ALONE.  Do the same for Lan zone and put a 
check in h-zone. 

click apply then ok.  This needs to be done both for server and client 
NFS.  You are right if the protocals are enabled in the zones the ports 
become active.  If protocals are not enabled.  Then the service won't 
work.  Kimmo can you type  tail +f /var/log/messages as root.  Try to 
connect your nfs server what should be shown is *DROPED in=Eth0 *this 
will show what was blocked along with source and destination port too.

Let me know how you get on

Regards
Kevin

K. Elo wrote:

>Hi again,
>
>Kevin Ferguson wrote on 31.5.2005 at 13:26:
>  
>
>>Hi Kimmo
>>
>>I've attempted NFS using guraddog and it does work.  However this was
>>some months ago.  It worth checking you exports are setup correctly,
>>in /etc/exports.  I got this wrong, although I could ping the server,
>>I could not connect to the share.  It sounds more like a
>>configuration problem than guarddog issue.  have you tried dropping
>>the firewall and testing your nfs connection? Have you previosly had
>>your nfs server working prior to installing guarddog?
>>    
>>
>
>Well, the problem seems to be linked with Guarddog. When I dropped the 
>firewall I could establish a connection to the nfs server and transport 
>data between it and the client. The /etc/exports file is configured 
>with YaST and seems to be OK, too. So, obviously the firewall is too 
>"hardened" - I just cannot figure out what services should be enabled 
>(ftp, http ... ). As I mentioned, the connection is dropped by Guarddog 
>on laptop (I controlled the log console after I had given the "mount" 
>command) so the attempt never reaches the server...
>
>BTW, if I have understood the logic of guarddog right, permitting *all* 
>protocols between "local" and "h-network" zones should do no or only 
>little harm, if at the same time there are _no_ permitted protocols 
>between "internet" and "h-network" zones and only the crucially needed 
>between "internet" and "local" zones. The "h-network" has no public IP 
>addresses and, thus, is not browseable from outside, right? Only if 
>someone from outside could intrude the PC/laptop, he/she should be able 
>to attack the nfs-server/client.
>
>Kind regards,
>
>Kimmo
>
>
>-------------------------------------------------------
>SF.Net email is Sponsored by the Better Software Conference & EXPO
>September 19-22, 2005 * San Francisco, CA * Development Lifecycle Practices
>Agile & Plan-Driven Development * Managing Projects & Teams * Testing & QA
>Security * Process Improvement & Measurement * http://www.sqe.com/bsce5sf
>_______________________________________________
>Guarddog-user mailing list
>[email protected]
>https://lists.sourceforge.net/lists/listinfo/guarddog-user
>
>
>  
>



-------------------------------------------------------
SF.Net email is Sponsored by the Better Software Conference & EXPO
September 19-22, 2005 * San Francisco, CA * Development Lifecycle Practices
Agile & Plan-Driven Development * Managing Projects & Teams * Testing & QA
Security * Process Improvement & Measurement * http://www.sqe.com/bsce5sf
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.