Schweiss, Chip
2014-01-22 20:47:38 UTC
A recent change in the NLM for NFSv3 has exposed a problem with the
firewall on Redhat/CentOS.
Connections back to the client are blocked by the firewall because the
connection tracking module is not catching connections as part of the open
NFS connections to the server.
I have attempted to resolve this by opening NFS specific ports but the
server kept connecting to ports that I haven't seen referenced before
including privileged ports.
As a work around I have implemented accept rules for all TCP from the NFS
server.
This could be across all Linux distributions. My tests have only been on
CentOS.
The problem first appears when port 111 is blocked, opening 111 basically
opens a can worms to what seems randomly selected ports of any value. I
know on Linux NFS servers the connection ports can be limited. Is this
possible on Illumos?
-Chip
-------------------------------------------
illumos-zfs
Archives: https://www.listbox.com/member/archive/182191/=now
RSS Feed: https://www.listbox.com/member/archive/rss/182191/23047029-187a0c8d
Modify Your Subscription: https://www.listbox.com/member/?member_id=23047029&id_secret=23047029-2e85923f
Powered by Listbox: http://www.listbox.com
firewall on Redhat/CentOS.
Connections back to the client are blocked by the firewall because the
connection tracking module is not catching connections as part of the open
NFS connections to the server.
I have attempted to resolve this by opening NFS specific ports but the
server kept connecting to ports that I haven't seen referenced before
including privileged ports.
As a work around I have implemented accept rules for all TCP from the NFS
server.
This could be across all Linux distributions. My tests have only been on
CentOS.
The problem first appears when port 111 is blocked, opening 111 basically
opens a can worms to what seems randomly selected ports of any value. I
know on Linux NFS servers the connection ports can be limited. Is this
possible on Illumos?
-Chip
-------------------------------------------
illumos-zfs
Archives: https://www.listbox.com/member/archive/182191/=now
RSS Feed: https://www.listbox.com/member/archive/rss/182191/23047029-187a0c8d
Modify Your Subscription: https://www.listbox.com/member/?member_id=23047029&id_secret=23047029-2e85923f
Powered by Listbox: http://www.listbox.com