Firewall and nfs mounts

Bill McGonigle bill at bfccomputing.com
Mon Aug 24 14:44:20 UTC 2009


On 08/24/2009 08:15 AM, Anne Wilson wrote:
> What ports are necessarily opened on an nfs server?  Does the client need any 
> ports opened?

If you can limit yourself to NFSv4 you're much better off in this
department.  I have this on an NFSv4 server:

# NFS
  -A RH-Firewall-1-INPUT -m state --state NEW -m tcp -p tcp --source
192.168.1.32/27 --dport 2049 -j ACCEPT

and nothing on a working client other than the standard:

  -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT

-Bill


-- 
Bill McGonigle, Owner
BFC Computing, LLC
http://bfccomputing.com/
Telephone: +1.603.448.4440
Email, IM, VOIP: bill at bfccomputing.com
VCard: http://bfccomputing.com/vcard/bill.vcf
Social networks: bill_mcgonigle/bill.mcgonigle




More information about the fedora-list mailing list