Re: Firewall problems with NFS

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Bill Davidsen wrote:
I have a firewall problem with running an NFS server on FC6 or FC8, due to the GUI configuration interface not opening the firewall when I check the NFS protocol support. It seems to only allow use as an NFS client, since that worked fine when I tested it.

I can put the needed rules in the "RH-Firewall-1-INPUT" chain, but mixing GUI administration and manual administration is undesirable to prevent unexpected behavior, conflicts, etc, in the future. Is there really no way to open the ports for NFS server other than by hand?

Opening NFS servers is tricky - the default GUI is too simple to do it well.

You'll probably need to:

1) Learn about port "pinning" for NFS (so it always uses the same ports).

2) Use a fancier GUI, like firestarter (http://www.fs-security.com/), to control your firewall.

NFS is insecure anyways, so you'll want to have another firewall outside the client network also. Do not expose the NFS server to public access.

- Mike


--
fedora-list mailing list
fedora-list@xxxxxxxxxx
To unsubscribe: https://www.redhat.com/mailman/listinfo/fedora-list
[Index of Archives]     [Older Fedora Users]     [Fedora Announce]     [Fedora Package Announce]     [EPEL Announce]     [Fedora Magazine]     [Fedora News]     [Fedora Summer Coding]     [Fedora Laptop]     [Fedora Cloud]     [Fedora Advisory Board]     [Fedora Education]     [Fedora Security]     [Fedora Scitech]     [Fedora Robotics]     [Fedora Maintainers]     [Fedora Infrastructure]     [Fedora Websites]     [Anaconda Devel]     [Fedora Devel Java]     [Fedora Legacy]     [Fedora Desktop]     [Fedora Fonts]     [ATA RAID]     [Fedora Marketing]     [Fedora Management Tools]     [Fedora Mentors]     [SSH]     [Fedora Package Review]     [Fedora R Devel]     [Fedora PHP Devel]     [Kickstart]     [Fedora Music]     [Fedora Packaging]     [Centos]     [Fedora SELinux]     [Fedora Legal]     [Fedora Kernel]     [Fedora OCaml]     [Coolkey]     [Virtualization Tools]     [ET Management Tools]     [Yum Users]     [Tux]     [Yosemite News]     [Gnome Users]     [KDE Users]     [Fedora Art]     [Fedora Docs]     [Asterisk PBX]     [Fedora Sparc]     [Fedora Universal Network Connector]     [Libvirt Users]     [Fedora ARM]

  Powered by Linux