NFS over linux server to another linux server

I have a server1 that is directly connect to another server2 with two nic cards.  The other nic on server2 is connected to the internet.  I would like to be able to connect nfs to the server1 from another server3 from the internet.  Since I can't mount nfs to nfs mount (I don't think there is a way?)  so I need another way.  I would like the most speed out of it I can since everything is on 100Mbit connections.

Can I setup port forwards with iptables on server2 to forward certain ports to server1?  if so can you should me an example.  NOTE:  I do know how to setup static ports in nfs.


Thank you.
W00dyW00dAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

NotLogicalCommented:
Hi W00dyW00d,

There is a little ambiguity in your question: which is the client, which is the server? Is server1 a server and server3 a client? Does server2 expose any NFS mounts currently (or will it)?

Is your connection to the 'net via some sort of dedicated high-speed or do you have a cable modem (or some type of dynamic-based address)?

If you can provide a little more info, it will be easier to provide you a solution.

NFS to NFS is possible - but so dangerous, that it's not even worth considering!   =8^O

Thanks,

NotLogical
0
W00dyW00dAuthor Commented:
server1 (10.0.0.1 server with nfs mounts)
  connects to server2 eth1 (10.0.0.2)

server2 (10.0.0.2 server with nfs mounts)
   connects to server1 eth1 (10.0.0.1)
   connect to internet with eth0 (123.123.123.123)


server3 client for both nfs servers (321.321.321.321)
   currently connects to server2 with nfs mounts
   needs to connect to server1 with nfs mounts
0
arrkerr1024Commented:
How about putting OpenVPN on servers 2 and 3, and connect server 3 to the network that has server1 and 2 on it.  That'll give you a nice, encrypted tunnel, with full access in both directions.
0
Firewall Management 201 with Professor Wool

In this whiteboard video, Professor Wool highlights the challenges, benefits and trade-offs of utilizing zero-touch automation for security policy change management. Watch and Learn!

W00dyW00dAuthor Commented:
Well that is interesting idea.  I was also thinking of ssh tunnel.  How would speed be when moving files sizing around 100MB to 1GB over vpn.  The line is 100Mbit between the server2 and server3 (client).

Thank you for the help.
0
arrkerr1024Commented:
SSH would be fine if you just want nfs access occasionally, and you are able to log in manually each time and establish the ssh tunnel.  Certainly the easiest thing to do.

OpenVPN or any VPN for that matter is better if you want a permanent tunnel between two networks, especially if you want to use more than one service.  With the VPN you could allow a while network behind server3 to access server1 if you wanted.  Might be over-kill for your scenario - thats up to you.

Performance  is hard to tell.  The machines are certainly going to have to do some work to encrypt the data.  If the CPUs are fast, then it wouldn't be too bad.  If they are slow it might really slow you down.  Any modern CPU should be fine.  It is really going to depend on your internet connection between server1 and server3.  Residential lines are usually faster in one direction (downstream), so it would also matter what direction traffic is flowing.

Hope that helps...
0
arrkerr1024Commented:
Here's a good link on tunneling nfs over ssh - I'm sure  you found it too with some quick googling.
http://blogs.sun.com/shepler/entry/tunneling_nfs_traffic_via_ssh
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
W00dyW00dAuthor Commented:
Okay thank you for the great replies.  I'm try to set it up over the weekend.  I'm going to leave this question open just in case i have questions.

Thanks
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Linux

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.