Solved

Redhat 6 can not get correct firewall for nfs

Posted on 2014-09-17
8
126 Views
Last Modified: 2014-09-26
I am in a lab environment and am trying to get my nfs to work.

without the firewall showmount -e works just find.

I have permitted nfs, and rpc through however nfs still does not want to work with the firewall up.

the /etc/sysconfig/nfs file use to have a may ports configured in the same range of 400x however if I look at that file on this redhat 6 system the ports are different in the file.

There seems like there should be some sort of easy way to securely let nfs in
0
Comment
Question by:TIMFOX123
8 Comments
 
LVL 34

Expert Comment

by:Seth Simmons
ID: 40328736
what firewall are you using?
0
 

Author Comment

by:TIMFOX123
ID: 40328894
netfilter - iptables , the one that is stock on centos

this is the local firewall that just protects that one system.
0
 
LVL 61

Accepted Solution

by:
gheist earned 500 total points
ID: 40329204
nfs server needs multiple ports open - nfsd, mountd and rpc portmapper (last is 111 tcp/udp, former are dynamic, but more or less visible in rpcinfo -p)
0
 
LVL 21

Expert Comment

by:Mazdajai
ID: 40329303
Try using the firewall terminal user- interface aka
system-config-firewall-tui

Open in new window

and select all NFS to begin with, then lock down to fits your needs:

NFSv2 and NFSv3
TCP
111, 662, 892, 2049, 32803

UDP
111, 662, 892, 2049, 32769

NFSv4
TCP
2049
0
What Should I Do With This Threat Intelligence?

Are you wondering if you actually need threat intelligence? The answer is yes. We explain the basics for creating useful threat intelligence.

 
LVL 61

Expert Comment

by:gheist
ID: 40329356
662 - macosx sharing
892 - unassigned

my RHEL6 has 111 and 2049 + 2 high ports open
you can fix them in /etc/sysconfig/nfs
0
 

Author Comment

by:TIMFOX123
ID: 40332037
gheist:

does showmount -e from a remote system work for you ?
0
 
LVL 61

Expert Comment

by:gheist
ID: 40332149
It should not.
0
 

Author Closing Comment

by:TIMFOX123
ID: 40346083
great job and sorry for not getting back
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

If you have a server on collocation with the super-fast CPU, that doesn't mean that you get it running at full power. Here is a preamble. When doing inventory of Linux servers, that I'm administering, I've found that some of them are running on l…
You ever wonder how to backup Linux system files just like Windows System Restore?  Well you can use Timeshift in Linux to perform those similar action.  This tutorial will show you how to backup your system files and keep regular intervals. Note…
Learn several ways to interact with files and get file information from the bash shell. ls lists the contents of a directory: Using the -a flag displays hidden files: Using the -l flag formats the output in a long list: The file command gives us mor…
Learn how to get help with Linux/Unix bash shell commands. Use help to read help documents for built in bash shell commands.: Use man to interface with the online reference manuals for shell commands.: Use man to search man pages for unknown command…

744 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now