{"id":80,"date":"2004-02-23T15:44:39","date_gmt":"2004-02-23T15:44:39","guid":{"rendered":"https:\/\/143-42-55-146.ip.linodeusercontent.com\/?p=80"},"modified":"2004-02-23T15:44:39","modified_gmt":"2004-02-23T15:44:39","slug":"nfs-versus-firewall","status":"publish","type":"post","link":"https:\/\/nax.cz\/?p=80","title":{"rendered":"NFS VERSUS FIREWALL"},"content":{"rendered":"<p>Dnes sem musel zase po n\u00c4\u009bjak\u0102\u0160 dob\u00c4\u009b vyrestartovat server a v\u0139\u0104iml jsem si, \u0139\u017ee kdy\u0139\u017e jsem pak zap\u0102\u00adnal m\u0139\u017bj desktop, tak m\u00c4\u009bl probl\u0102\u0160my p\u0139\u0099ipojit disky sd\u0102\u00adlen\u0102\u0160 p\u0139\u0099es nfs (co\u0139\u017e je unixov\u0102\u02dd zp\u0139\u017bsob sd\u0102\u00adlen\u0102\u00ad disk\u0139\u017b). Kouknul jsem se na porty otev\u0139\u0099en\u0102\u0160 na serveru a hned jsem zjistil v \u00c4\u008dem je probl\u0102\u0160m. Oni toti\u0139\u017e porty rpc.mountd byli otev\u0139\u0099eny jinde ne\u0139\u017e kdy\u0139\u017e jsem d\u00c4\u009blal firewall, tak\u0139\u017ee logicky museli b\u0102\u02ddt povolen\u0102\u0160 z vnit\u0139\u0099n\u0102\u00ad s\u0102\u00adt\u00c4\u009b jin\u0102\u0160 porty ne\u0139\u017e te\u00c4\u008f byli pot\u0139\u0099eba.<\/p>\n<p>Trochu jsem pohledal na internetu a zjistil jsem, \u0139\u017ee je to t\u0102\u00adm, \u0139\u017ee portmap (u\u0139\u017e v\u0102\u00adm pro\u00c4\u008d se mus\u0102\u00ad pou\u0139\u0104t\u00c4\u009bt p\u0139\u0099ed nab\u00c4\u009bhnut\u0102\u00adm nfs \ud83d\ude09 p\u0139\u0099id\u00c4\u009bluje rpc.mountd porty dynamicky &#8211; poka\u0139\u017ed\u0102\u0160 jinam.  Kdy\u0139\u017e si pak vzd\u0102\u0104len\u0102\u02dd po\u00c4\u008d\u0102\u00adta\u00c4\u008d p\u0139\u0099eje n\u00c4\u009bco p\u0139\u0099ipojit, tak se nejd\u0139\u0099\u0102\u00adv portmapu na portu 111 zept\u0102\u0104 kde m\u0102\u0104 hledat ostatn\u0102\u00ad porty. Dost mrzut\u0102\u0104 v\u00c4\u009bc, kdy\u0139\u017e pot\u0139\u0099ebujete firewall. Nicm\u0102\u0160n\u00c4\u009b \u0139\u0099e\u0139\u0104en\u0102\u00ad existuje. Konkr\u0102\u0160tn\u00c4\u009b v dokumentu <a href=\"http:\/\/www.ba.infn.it\/calcolo\/documenti\/NFSServer.html#Firewall\">Setting up a Linux NFS server<\/a> jsem na\u0139\u0104el odpov\u00c4\u009b\u00c4\u008f skoro na v\u0139\u0104echny ot\u0102\u0104zky. Jedin\u0102\u0160 co bych poopravil je pr\u0102\u0104v\u00c4\u009b port nfs.mountd, kter\u0102\u02dd definujete parametrem -P (na debianu se pou\u0139\u0104t\u0102\u00ad v \/etc\/init.d\/nfs-server.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Dnes sem musel zase po n\u00c4\u009bjak\u0102\u0160 dob\u00c4\u009b vyrestartovat server a v\u0139\u0104iml jsem si, \u0139\u017ee kdy\u0139\u017e jsem pak zap\u0102\u00adnal m\u0139\u017bj desktop, tak m\u00c4\u009bl probl\u0102\u0160my p\u0139\u0099ipojit disky sd\u0102\u00adlen\u0102\u0160 p\u0139\u0099es nfs (co\u0139\u017e je unixov\u0102\u02dd zp\u0139\u017bsob sd\u0102\u00adlen\u0102\u00ad disk\u0139\u017b). Kouknul jsem se na porty otev\u0139\u0099en\u0102\u0160 na serveru a hned jsem zjistil v \u00c4\u008dem je probl\u0102\u0160m. Oni toti\u0139\u017e porty rpc.mountd byli [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[35,1],"tags":[],"class_list":["post-80","post","type-post","status-publish","format-standard","hentry","category-linux","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/nax.cz\/index.php?rest_route=\/wp\/v2\/posts\/80","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nax.cz\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nax.cz\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nax.cz\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/nax.cz\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=80"}],"version-history":[{"count":0,"href":"https:\/\/nax.cz\/index.php?rest_route=\/wp\/v2\/posts\/80\/revisions"}],"wp:attachment":[{"href":"https:\/\/nax.cz\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=80"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nax.cz\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=80"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nax.cz\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=80"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}