Firewalling NFS

Eygene Ryabinkin rea-fbsd at codelabs.ru
Fri Jun 15 17:55:39 UTC 2007


Bruce, good day.

Fri, Jun 15, 2007 at 06:47:07PM +0100, Bruce M. Simpson wrote:
> I added the -p switch to mountd(8) a few years ago, as I needed to run a 
> read-only NFS server exposed to the outside world; to firewall it I needed a 
> deterministic RPC port number, which is what -p gives you. Otherwise you have 
> to rely on the TCP wrapper support built into rpcbind(8). The rpc.lockd and 
> rpc.statd daemons were recently changed to incorporate this switch too, 
> although I don't think it has been backported to the 6-STABLE branch yet.

OK, thanks for the explanations.

So, Jeremie, you will need to wait for merge of the change or backport
it manually.
-- 
Eygene


More information about the freebsd-net mailing list