Limit NFS on network adapter

From: Alan W. Rateliff, II (lists_at_rateliff.net)
Date: 02/13/04

  • Next message: Chris Pelton: "firewall settings for Solstice Backup 6.1"
    To: <focus-sun@securityfocus.com>
    Date: Fri, 13 Feb 2004 17:05:52 -0500
    
    

    I am running Solaris 8/x86 on a couple of boxes that I would like to link
    via NFS. Given the security issues surrounding NFS, I would like to use the
    second NIC on both machines configured with an RFC-1918 address to
    communicate over NFS via a back network, instead of exposing NFS to the
    Internet. I've searched around but cannot find any information on binding
    NFS to a specific NIC. Is this possible?

    -- 
           Alan W. Rateliff, II        :       RATELIFF.NET
     Independent Technology Consultant :    alan2@rateliff.net
          (Office) 850/350-0260        :  (Mobile) 850/559-0100
    -------------------------------------------------------------
    [System Administration][IT Consulting][Computer Sales/Repair]
    

  • Next message: Chris Pelton: "firewall settings for Solstice Backup 6.1"

    Relevant Pages

    • Re: Transport Mode IPSEC
      ... security with environment security. ... NFS server with an arp cache poison, ... If you correct the environment security, ... For example, you put in a decent managed switch, you ...
      (freebsd-questions)
    • Re: Port 135 Probes Continue
      ... People also run FTP servers. ... it's just that you don't hear of folks making ... any efforts to chroot NFS, ... > security mechanism besides hostname / IP restrictions. ...
      (comp.security.misc)
    • Re: Port 135 Probes Continue
      ... People also run FTP servers. ... it's just that you don't hear of folks making ... any efforts to chroot NFS, ... > security mechanism besides hostname / IP restrictions. ...
      (comp.os.linux.security)
    • Re: Port 135 Probes Continue
      ... People also run FTP servers. ... it's just that you don't hear of folks making ... any efforts to chroot NFS, ... > security mechanism besides hostname / IP restrictions. ...
      (comp.security.unix)
    • Re: Port 135 Probes Continue
      ... Sun had never fixed this problem. ... >NFS filesystem security is a form of security through obscurity: ... >secured NFS system, you can guess at available filehandles and write to disk ... You need to fake the IP addresses; I assumed you were talking about ...
      (comp.os.linux.security)