NFS through Firewall

Stephan Eckner Stephan Eckner <stephan.eckner@innominate.com>
6 Jul 2001 08:41:35 GMT


Ian Mortimer <ian@physics.uq.edu.au> wrote:

>> I am wondering if it and makes sense to put a firewall between two 
>> networks, that has to accept NFS-traffic in both directions.

> Sure it makes sense and is a good way to protect NFS servers.
> However the number and variability of ports used by NFS makes
> it difficult without a helper module.
> 
>> Has anybody done this an could give me a configuration example?

> There's an rpc module in the kernel patches.  I haven't tried it and
> don't know any more about it but I assume you add it with patch-o-matic 
> and rebuild your kernel.

I'm afraid, an rpc module would only work on the NFS Server itself,
but not on a different machine thats routing.

But I'll have a look at it :)

Stephan

-- 
stephan.eckner@innominate.com                            innominate AG
dipl.-math.                                       technical consultant
tel: +49.30.308806-354  fax: -77             http://www.innominate.com