Re: [fw-wiz] NFS for NAS across FW or virt Interface in DMZ.



Cary, Kim wrote:
Folks, if you had to have a single NAS system projected via NFS into
DMZ1 & DMZ2 from Firewall Zone 3 would you do this by providing NAS IP
inside DMZ1 & DMZ2 or by allowing sunrpc/nfs to cross the firewall from
specified hosts?

The NFS protocol is completely insecure. If you really need to do filesharing
between machines, then put those machines into the same subnet and security
zone, rather than disable your firewall to the extent of letting filesharing
pass through it.

(Alternatively, if your security requirements mandate that these machines be in
separate DMZ's or security zones, then your security requirements have indicated
that they shouldn't be sharing files with each other. :)

--
-Chuck
_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxx
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards



Relevant Pages

  • Re: Norton 2005 Int Security, Trend PCcillin or Zone Alarm ???????
    ... > I want security I can run on both machines. ... System overhead is higher than standard firewall applications. ... Symantec products do not remove (uninstall) well. ... Micro Trends PC-Cillan is very good (possibly the best in home network ...
    (alt.computer.security)
  • Re: Setting Up A WorkGroup for file and Share Printing
    ... Tried that amd could access only one of the two drives, the D drive, however ... I Turned off NIS 2008 firewall ... I made sure the Registry setting "IRPStackSize" on both machines ... Here are general network troubleshooting steps. ...
    (microsoft.public.windowsxp.network_web)
  • Re: Sharing a printer
    ... It may look daunting, but if you follow the steps at the links and suggestions below systematically and calmly, you will have no difficulty in setting up your sharing. ... start by running the Network Setup Wizard on all machines. ... Problems sharing files between computers on a network are generally caused by 1) a misconfigured firewall; or 2) inadvertently running two firewalls such as the built-in Windows Firewall and a third-party firewall; and/or 3) not having identical user accounts and passwords on all Workgroup machines; 4) trying to create shares where the operating system does not permit it. ...
    (microsoft.public.windowsxp.network_web)
  • Re: Map drives between 2 XP SP2 machines...
    ... CheckPoint's VPN software has a Stateful Packet Inspection firewall, I believe, that is on, even when the VPN connection is not established. ... Doug Knox, MS-MVP Windows Media Center\Windows Powered Smart Display\Security ... > subnet) - But I still am not able to get an comminucation b/w the machines. ... MS-MVP Windows Media Center\Windows Powered Smart Display\Security ...
    (microsoft.public.windowsxp.security_admin)
  • Re: File sharing
    ... >>> firewall, but it doesn't work. ... >>> machines here this configuration works fine. ... I would also use telnet to try and access TCP port 139 and 445 on a machine that works correctly and one that does not to help determine if it is a network access or other problem. ... If the port is open you will see a blank command window with a blinking cursor like you will see if you run telnet 127.0.0.1 445 on your computer. ...
    (microsoft.public.windowsxp.security_admin)