Re: NFS daemon port numbers for firewall config

Edgar Fuß <[email protected]>
Newsgroups gmane.os.netbsd.devel.network
Message-ID <[email protected]>
> For firewalling a static port is easier. That's why mountd started
> to offer a static port too. The other protocols (lock/stat/quota)
> are rarely used through a firewall.
I *do* run them through a firewall. I run a local ipf on every server for
a) anti-spoofing
b) blocking services the daemon can't be told to only serve on certain 
   interfaces/nets.

> Real firewalls inspect the portmapper protocol, learn about what
> ports get registered and automatically allow sessions to the registered
> ports.
So what, in your opinion is an example for a "real firewall"?

> NFSv4 got rid of all the SunRPC details. It uses only a single
> services (for nfs, mount, locking, etc..) on the static port 2049
> for everything. No rpcbind involved.
NFSv4 daemon for NetBSD, anyone?

> You configure firewalls to limit traffic between networks, not interfaces.
In my setup, on most interfaces, each interface (vlan*) only carries one 
network.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.