- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Re: Problem with nfs through firewall
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-20-2003 03:10 AM
06-20-2003 03:10 AM
Problem with nfs through firewall
I have some vlans and I try to export a directory from a system in a vlan to the systems belonging to the other vlans. I have the ports 2049 (TCP & UDP) and 111 (TCP & UDP) opened in the firewall, but when I try to mount the exported directory I have this:
mount: RPC: Timed out (if the client is a Linux)
nfs mount: get_fh: xxx.xxx.xxx.xxx:: RPC: Timed out (if the client is HPUX; the server is HPUX)
I can nfs mount in other systems from the same vlan.
Does somebody knows where the problem is?
Regards,
R.O.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-20-2003 03:31 AM
06-20-2003 03:31 AM
Re: Problem with nfs through firewall
rpcinfo -p
to see what all services reachable to your system from the remote host.
Refer
http://docs.hp.com/cgi-bin/fsearch/framedisplay?top=/hpux/onlinedocs/B1031-90043/B1031-90043_top.html&con=/hpux/onlinedocs/B1031-90043/00/00/32-con.html&toc=/hpux/onlinedocs/B1031-90043/00/00/32-toc.html&searchterms=rpcinfo&queryid=20030620-053047
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-20-2003 04:05 AM
06-20-2003 04:05 AM
Re: Problem with nfs through firewall
From client to server:
client# rpcinfo -p server
program vers proto port
100000 4 tcp 111 portmapper
100000 3 tcp 111 portmapper
100000 2 tcp 111 portmapper
100000 4 udp 111 portmapper
100000 3 udp 111 portmapper
100000 2 udp 111 portmapper
100005 1 udp 49356 mountd
100005 3 udp 49356 mountd
100005 1 tcp 60859 mountd
100005 3 tcp 60859 mountd
100003 2 tcp 2049 nfs
100003 2 udp 2049 nfs
100003 3 tcp 2049 nfs
100003 3 udp 2049 nfs
1342177279 4 tcp 51556
1342177279 1 tcp 51556
1342177279 3 tcp 51556
1342177279 2 tcp 51556
From server to client:
server:/#rpcinfo -p client
rpcinfo: can't contact portmapper: RPC: Rpcbind failure - RPC: Failed (unspecified error)
This is what I see...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-20-2003 06:04 AM
06-20-2003 06:04 AM
Re: Problem with nfs through firewall
NFS is not a very secure facility for this reason. Its a good one, but really the industry needs to develop a Secure NFS.
Chris
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-22-2003 06:09 PM
06-22-2003 06:09 PM
Re: Problem with nfs through firewall
You may need to stop and restart your nfs server daemons.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-23-2003 02:08 AM
06-23-2003 02:08 AM
Re: Problem with nfs through firewall
I have seen that I need to open in the firewall the port for rpc.mountd. This daemon uses differents ports everytime it is restarted. So the question is ??Is there any way to force mountd to listen in the same port in the nfs server forever?
I tryed with -p option, but it does not work for this case.
Regards
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-23-2003 11:03 AM
06-23-2003 11:03 AM
Re: Problem with nfs through firewall
Your next option is to ensure that NFS is handled in each LAN separately.
Regards,
Shannon
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-23-2003 01:15 PM
06-23-2003 01:15 PM
Re: Problem with nfs through firewall
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-23-2003 01:17 PM
06-23-2003 01:17 PM
Re: Problem with nfs through firewall
But there's more than one way to do this. Consider creating a private, back-to-back LAN from one server to another directly through the appropriate cable. Then mount the NFS volume either read only, or write only--depending on your need. This is a LOT more secure, but not as much as it might be.
An expensive solution (that we use here) is to use EMC's Celerra product. This is a NFS to fiber gateway, with access both inside and outside the firewall. We use the BCV (Business Continuance Volume) process to mirror data outside the firewall. Once that is done, we logically attach the filesystem to a host inside the firewall, where it goes through virus scanning. Finally, we attach it (again logically) to a 4th host (also inside the firewall) where the data files are acted on by the software. If this sounds complicated and expensive, you're right. Its also REALLY secure, as never does a user from outside the company ever see the systems behind the firewall. But it moves data quite efficiently between environments.
EMC is discontinuing the Celerra, so you can pick one of these up cheap (still over $100kUSD, however). At least go to EMC's website and check it out. They're pretty desperate for sales these days, so you may be able to strike a bargain.
Chris
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-27-2003 03:49 AM
06-27-2003 03:49 AM
Re: Problem with nfs through firewall
Try the following step
1.)You able to ping remote server
2.) You able to reach the remote service through the rpcinfo -p
3.) On server and client end the run the command rpcbind -w
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-27-2003 03:50 AM
06-27-2003 03:50 AM
Re: Problem with nfs through firewall
Try the following step
1.)You able to ping remote server
2.) You able to reach the remote service through the rpcinfo -p
3.) On server and client end the run the command rpcbind -w
4.) check the remote hosts entry in the /etc/hosts file
5.) check the nfsd daemon enable in /etc/rc.config.d/nfsconf file