Re: IPFILTER and NFS

From: Erik Nørgaard (norgaard_at_locolomo.org)
Date: 04/03/05

  • Next message: bob_at_a1poweruser.com: "RE: question"
    Date: Sun, 03 Apr 2005 20:48:22 +0200
    To: Matt Juszczak <matt@atopia.net>
    
    

    Matt Juszczak wrote:
    > I dont have access to the nfs server... only the client. Your
    > configuration info showed me making changes on the server. is there a
    > way to make the client work ok?

    Just let your client connect to any port on the server - keep state so
    you can block incoming connections:

    pass out quick on <interface> proto tcp from <client>/32 \
         to <nfs-server>/32 flags S keep state
    pass out quick on <interface> proto udp from <client>/32 \
         to <nfs-server>/32 keep state

    Erik

    -- 
    Ph: +34.666334818                           web: http://www.locolomo.org
    S/MIME Certificate: http://www.locolomo.org/crt/2004071206.crt
    Subject ID:  A9:76:7A:ED:06:95:2B:8D:48:97:CE:F2:3F:42:C8:F2:22:DE:4C:B9
    Fingerprint: 4A:E8:63:38:46:F6:9A:5D:B4:DC:29:41:3F:62:D3:0A:73:25:67:C2
    _______________________________________________
    freebsd-questions@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-questions
    To unsubscribe, send any mail to "freebsd-questions-unsubscribe@freebsd.org"
    

  • Next message: bob_at_a1poweruser.com: "RE: question"

    Relevant Pages

    • Re: What doesnt lend itself to OO?
      ... >> proxy and instructs the server to constuct the real object. ... rather than client code. ... If 'clock' is instantiated in the server, ... > for the server interface at the OOA level. ...
      (comp.object)
    • This is going straight to the pool room
      ... or not the client has privilege to do what they're trying to do, ... The server environment is this: ... 3GL User action Routines that Tier3 will execute on your behalf during the ... Routine Name: USER_INIT ...
      (comp.os.vms)
    • [Full-Disclosure] R: Full-Disclosure Digest, Vol 3, Issue 42
      ... Full-Disclosure Digest, Vol 3, Issue 42 ... SD Server 4.0.70 Directory Traversal Bug ... Arkeia Network Backup Client Remote Access ...
      (Full-Disclosure)
    • Re: What doesnt lend itself to OO?
      ... > rather than client code. ... no way to do that without also touching the object with clock semantics ... will not encapsulate both clock semantics and network semantics. ... The server can do whatever it wants ...
      (comp.object)
    • RE: Fax monitor incoming + outgoing calls?
      ... problem between the client computer and the SBS server. ... Client is using the internal IP address of the SBS server as the ... To the folder redirection GPO issue: ...
      (microsoft.public.windows.server.sbs)