- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- NFS though a firewall
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Discussions
Discussions
Discussions
Forums
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-04-2005 06:44 AM
тАО11-04-2005 06:44 AM
DBA's say we will need NFS exported from SAP web app on solaris 9 box that will be in the DMZ.
Needs a hpux rp7400 to mount the NFS volume.
response center says its not recommended.
Opinions, comments, recommendations?
thanks!
Phil
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-04-2005 07:34 AM
тАО11-04-2005 07:34 AM
Re: NFS though a firewall
Instead, use autofs and it will drop the connection from the client side after certain duration of inactivity, which, in turn, will let you remount it when you need it again, atoMAGICally.
Hard NFS thru firewalls is not recommended at all DMZ or otherwise. AutoFS has matured enough to replace the hard NFS anyway.
HTH
UNIX because I majored in cryptology...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-04-2005 12:53 PM
тАО11-04-2005 12:53 PM
Re: NFS though a firewall
But gathering from your question you probably require to export the share to a host in your shielded LAN.
Apart from the perils of stale lingering NFS mounts already mentioned by Mel I personally would regard this as an infringement of security, defeating the purpose of a DMZ.
If you cannot avoid it however, I would strongly put SecureNFS into consideration.
I have no experience setting this up
but I would imagine NFS as an RPC based protocol to be very intricate to configure the DMZ's firewalls securely for.
You will most likely find many references describing the implementation of SNFS or some sort of NFS tunnelling.
I just googled these two with emphasis on a Solaris NFS server:
http://docs.sun.com/app/docs/doc/816-4555/6maoqui98?a=view
http://www.sunhelp.org/faq/nfs.html#nfs13
Good luck
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-05-2005 05:30 AM
тАО11-05-2005 05:30 AM
SolutionBill Hassell, sysadmin
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-05-2005 07:30 PM
тАО11-05-2005 07:30 PM
Re: NFS though a firewall
The bigger problem is that NFS takes a random port number and you need to open a large range to accommodate it.
This is a security nightmare.
My recommendation is redesign the system.
SEP
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-07-2005 04:07 AM
тАО11-07-2005 04:07 AM
Re: NFS though a firewall
Compensating control examples: 1) VPN 2) SSL tunnel 3) IPSec
Depending on your available infrastructure, this could be a pain, especially as NFS uses a large port range.
NFSv4 does have native integrity protection, but I don't think that's available yet. You may want to consider CIFS(Samba). It does have per-packet integrity protection (though not privacy), and can be used to share files/directories.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-30-2005 03:33 AM
тАО11-30-2005 03:33 AM