Re: iptables and NFS

On Tue, 13 Dec 2005, Ansgar -59cobalt- Wiechers wrote:

NFS is not supposed to traverse any firewall, since it does not provide
any kind of security mechanism whatsoever.

I second that, even if NVFv4 is a litlle bit better. However, if you really,
really, REALLY MUST let NFS traverse a firewall, go to the official
netfilter web site and download the latest patch-o-matic. Then use it to
selectively apply only the required patches to enable NFS connection
tracking. This will enable you to have a much cleaner (and less insecure)
firewalling setup, since you will not need to blindly accept UDP connections
over a range of ports. Instead, you can let NFS clients (and only them)
connect to your portmapper (which runs on a well-defined port) and then let
through RELATED traffic. Another solution would be to establish a crypted,
authenticated connection between clients and servers (e.g. using IPSec using
one of the iplementations available, or ssh tunnels, or one of the many
other alternatives) and then letting relatively insecure traffic go through
the tunnels (this is what I do). It is a bit more complicated to set up, but
much more secure.



Reply to: