However, I have encountered a few nagging problems: * NFS: I can't seem to find any options for binding nfs to specific ports (-p option), either through the gui or in the scripts, which means that I can't have nfs for my vpn without unblocking all unprivileged ports.
Presumably, you trust users who authenticate themselves to the VPN. Allow access to the full range of ports either to the VPN interfaces (if this box hosts the VPN itself) or to the IP addresses allocated by the VPN server.
* Where is the tool for configuring NIS?
I'd hope that RH would put their effort into LDAP instead, if/when they do.
* firewalling: my firewall is on a dynamic IP and requires specific rules. lokkit does not allow you to specify which ports to add (beyond the basics: http/smtp...).
Yes it does. Look again for the "Other ports" input box.
Why can't wget work properly behing a firewall? (wrong port errors)
Could you be more specific?