Re: NFS connection dropped
"K. Elo" <[email protected]>
| Newsgroups | gmane.network.guarddog |
|---|---|
| Message-ID | <[email protected]> |
Hi again, I have now checked out the configuration of Guarddog and found out on the laptop the connection between "local" and "h-network" was not permitted. This was a self-made mistake and caused the laptop to drop the outgoing connection from the client. However, this did NOT result in a functioning nfs-connection. The server still refuses to establish a connection. Here the output of my server-side firewall log produced when I tried to browse the available nfs-servers (192.168.1.2 ist the non-public static IP address attached to the laptop NIC): Sep 1 09:03:30 Elot kernel: DROPPED IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:00:c0:9f:bc:fd:a2:08:00 SRC=192.168.1.2 DST=192.168.1.255 LEN=120 TOS=0x00 PREC=0x00 TTL=64 ID=3 DF PROTO=UDP SPT=1025 DPT=111 LEN=100 Sep 1 09:03:36 Elot kernel: DROPPED IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:00:c0:9f:bc:fd:a2:08:00 SRC=85.76.255.219 DST=85.76.255.255 LEN=120 TOS=0x00 PREC=0x00 TTL=64 ID=4 DF PROTO=UDP SPT=1025 DPT=111 LEN=100 Sep 1 09:03:36 Elot kernel: DROPPED IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:00:c0:9f:bc:fd:a2:08:00 SRC=192.168.1.2 DST=192.168.1.255 LEN=120 TOS=0x00 PREC=0x00 TTL=64 ID=5 DF PROTO=UDP SPT=1025 DPT=111 LEN=100 Sep 1 09:03:44 Elot kernel: DROPPED IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:00:c0:9f:bc:fd:a2:08:00 SRC=192.168.1.2 DST=192.168.1.255 LEN=120 TOS=0x00 PREC=0x00 TTL=64 ID=7 DF PROTO=UDP SPT=1025 DPT=111 LEN=100 Sep 1 09:03:54 Elot kernel: DROPPED IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:00:c0:9f:bc:fd:a2:08:00 SRC=192.168.1.2 DST=192.168.1.255 LEN=120 TOS=0x00 PREC=0x00 TTL=64 ID=9 DF PROTO=UDP SPT=1025 DPT=111 LEN=100 Sep 1 09:04:06 Elot kernel: DROPPED IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:00:c0:9f:bc:fd:a2:08:00 SRC=192.168.1.2 DST=192.168.1.255 LEN=120 TOS=0x00 PREC=0x00 TTL=64 ID=11 DF PROTO=UDP SPT=1025 DPT=111 LEN=100 The port 111 the client is trying to connect to is the SUN remote procedure call. In my GD configuration this protocol _is_ served from both "local" and "h-network" to clients in "h-network"/"local"!!! So why on earth are connections to this port dropped by GD?!?!?! The "h-network" zone address range is 192.168.1.0/255.255.255.0 so the DST 192.168.1.255 should fit into this range, right?? Once again: the protocols permitted between "local" and "h-network" are: NFS, rsync, SUN remote procedure call, ssh, ping, ident/auth. Should there be some in addition to these (e.g. ftp)? Any ideas? Kind regards, Kimmo ------------------------------------------------------- SF.Net email is Sponsored by the Better Software Conference & EXPO September 19-22, 2005 * San Francisco, CA * Development Lifecycle Practices Agile & Plan-Driven Development * Managing Projects & Teams * Testing & QA Security * Process Improvement & Measurement * http://www.sqe.com/bsce5sf