Re: NFS connection dropped

"K. Elo" <[email protected]>
Newsgroups gmane.network.guarddog
Message-ID <[email protected]>
Hi again,

I have now checked out the configuration of Guarddog and found out on 
the laptop the connection between "local" and "h-network" was not 
permitted. This was a self-made mistake and caused the laptop to drop 
the outgoing connection from the client.

However, this did NOT result in a functioning nfs-connection. The server 
still refuses to establish a connection. Here the output of my 
server-side firewall log produced when I tried to browse the available 
nfs-servers (192.168.1.2 ist the non-public static IP address attached 
to the laptop NIC):

Sep  1 09:03:30 Elot kernel: DROPPED IN=eth0 OUT= 
MAC=ff:ff:ff:ff:ff:ff:00:c0:9f:bc:fd:a2:08:00 SRC=192.168.1.2 
DST=192.168.1.255 LEN=120 TOS=0x00 PREC=0x00 TTL=64 ID=3 DF PROTO=UDP 
SPT=1025 DPT=111 LEN=100 
Sep  1 09:03:36 Elot kernel: DROPPED IN=eth0 OUT= 
MAC=ff:ff:ff:ff:ff:ff:00:c0:9f:bc:fd:a2:08:00 SRC=85.76.255.219 
DST=85.76.255.255 LEN=120 TOS=0x00 PREC=0x00 TTL=64 ID=4 DF PROTO=UDP 
SPT=1025 DPT=111 LEN=100 
Sep  1 09:03:36 Elot kernel: DROPPED IN=eth0 OUT= 
MAC=ff:ff:ff:ff:ff:ff:00:c0:9f:bc:fd:a2:08:00 SRC=192.168.1.2 
DST=192.168.1.255 LEN=120 TOS=0x00 PREC=0x00 TTL=64 ID=5 DF PROTO=UDP 
SPT=1025 DPT=111 LEN=100 
Sep  1 09:03:44 Elot kernel: DROPPED IN=eth0 OUT= 
MAC=ff:ff:ff:ff:ff:ff:00:c0:9f:bc:fd:a2:08:00 SRC=192.168.1.2 
DST=192.168.1.255 LEN=120 TOS=0x00 PREC=0x00 TTL=64 ID=7 DF PROTO=UDP 
SPT=1025 DPT=111 LEN=100 
Sep  1 09:03:54 Elot kernel: DROPPED IN=eth0 OUT= 
MAC=ff:ff:ff:ff:ff:ff:00:c0:9f:bc:fd:a2:08:00 SRC=192.168.1.2 
DST=192.168.1.255 LEN=120 TOS=0x00 PREC=0x00 TTL=64 ID=9 DF PROTO=UDP 
SPT=1025 DPT=111 LEN=100 
Sep  1 09:04:06 Elot kernel: DROPPED IN=eth0 OUT= 
MAC=ff:ff:ff:ff:ff:ff:00:c0:9f:bc:fd:a2:08:00 SRC=192.168.1.2 
DST=192.168.1.255 LEN=120 TOS=0x00 PREC=0x00 TTL=64 ID=11 DF PROTO=UDP 
SPT=1025 DPT=111 LEN=100 

The port 111 the client is trying to connect to is the SUN remote 
procedure call. In my GD configuration this protocol _is_ served from 
both "local" and "h-network" to clients in "h-network"/"local"!!! So 
why on earth are connections to this port dropped by GD?!?!?! The 
"h-network" zone address range is 192.168.1.0/255.255.255.0 so the DST 
192.168.1.255 should fit into this range, right??

Once again: the protocols permitted between "local" and "h-network" are: 
NFS, rsync, SUN remote procedure call, ssh, ping, ident/auth. Should 
there be some in addition to these (e.g. ftp)?

Any ideas?

Kind regards,
Kimmo


-------------------------------------------------------
SF.Net email is Sponsored by the Better Software Conference & EXPO
September 19-22, 2005 * San Francisco, CA * Development Lifecycle Practices
Agile & Plan-Driven Development * Managing Projects & Teams * Testing & QA
Security * Process Improvement & Measurement * http://www.sqe.com/bsce5sf
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.