Re: NFS daemon port numbers for firewall config

[email protected] (Michael van Elst)
Newsgroups gmane.os.netbsd.devel.network
Organization Serpens User Group
Message-ID <[email protected]>
[email protected] (Mouse) writes:

>SunRPC details to comment on CALLIT.  I _think_ it is useless if port
>111 is blocked, but I wouldn't trust my systems' security to that
>memory without checking it out first.)

The CALLIT procedure is provided by the service that runs on
port 111 (rpcbind). So nothing can happen if you block port 111.

Our implementation has a permanent UDP client socket opened for
the CALLIT procedure to proxy calls to other RPC services.
That socket is bound to a (privileged) ephemeral port and
may receive UDP packets from anywhere.

So, blocking UDP by default is required. But that should be
the setup for any host that needs to be protected.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.