On Fri, 26 Jan 2001, Crist J. Clark wrote:

> I wanted to point out that you cannot really 'block' RPC services
> effectively with ipfw(8) rules. RPC services do not live on certain
> well-known ports[0]. The only way you can effectively block RPC
> services is with default deny rules.

I've gotten around this in the past by putting 'rpcinfo -p | awk' commands
in rc.firewall, polling the portmapper on protected hosts and then
building firewall rules dynamically for them. It doesn't completely work,
because you have to flush & reload your rules when an NFS server bounces,
but for cases where that's "good enough", it does the job.

