{"id":128,"date":"2009-10-12T00:37:59","date_gmt":"2009-10-12T00:37:59","guid":{"rendered":"http:\/\/kumouse.aafox.com\/?p=128"},"modified":"2009-10-12T00:37:59","modified_gmt":"2009-10-12T00:37:59","slug":"nfs-iptables-%e8%ae%be%e7%bd%ae","status":"publish","type":"post","link":"https:\/\/www.kumouse.com\/?p=128","title":{"rendered":"nfs iptables \u8bbe\u7f6e"},"content":{"rendered":"<p>\u65b0\u7248\u7684NFS\u548c\u4ee5\u524d\u4e0d\u4e00\u6837\u4e86<br \/>\u7248\u672c\uff1a<\/p>\n<blockquote><p>[root@mydisk ~]# rpcinfo -p<br \/>   program vers proto   port  service<br \/>    100000    4   tcp    111  portmapper<br \/>    100000    3   tcp    111  portmapper<br \/>    100000    2   tcp    111  portmapper<br \/>    100000    4   udp    111  portmapper<br \/>    100000    3   udp    111  portmapper<br \/>    100000    2   udp    111  portmapper<br \/>    100024    1   udp   1011  status<br \/>    100024    1   tcp   1011  status<br \/>    100011    1   udp    875  rquotad<br \/>    100011    2   udp    875  rquotad<br \/>    100011    1   tcp    875  rquotad<br \/>    100011    2   tcp    875  rquotad<br \/>    100003    2   udp   2049  nfs<br \/>    100003    3   udp   2049  nfs<br \/>    100003    4   udp   2049  nfs<br \/>    100021    1   udp   1012  nlockmgr<br \/>    100021    3   udp   1012  nlockmgr<br \/>    100021    4   udp   1012  nlockmgr<br \/>    100021    1   tcp   1012  nlockmgr<br \/>    100021    3   tcp   1012  nlockmgr<br \/>    100021    4   tcp   1012  nlockmgr<br \/>    100003    2   tcp   2049  nfs<br \/>    100003    3   tcp   2049  nfs<br \/>    100003    4   tcp   2049  nfs<br \/>    100005    1   udp   1010  mountd<br \/>    100005    1   tcp   1010  mountd<br \/>    100005    2   udp   1010  mountd<br \/>    100005    2   tcp   1010  mountd<br \/>    100005    3   udp   1010  mountd<br \/>    100005    3   tcp   1010  mountd<\/p><\/blockquote>\n<p>\u60f3\u8bbe\u7f6e\u9632\u706b\u5899\uff0c\u8981\u5148\u628a\u7aef\u53e3\u56fa\u5b9a\u4e0b\u6765(\u4e0a\u8fb9\u662f\u56fa\u5b9a\u540e\u7684\u7aef\u53e3)<br \/>\u7f16\u8f91 vi \/etc\/services<br \/>\u52a0\u5165<\/p>\n<blockquote><p>#mountd<br \/>mountd          1010\/tcp<br \/>mountd          1010\/udp<br \/>#status<br \/>status          1011\/tcp<br \/>status          1011\/udp<br \/>#nlockmgr<br \/>nlockmgr        1012\/tcp<br \/>nlockmgr        1012\/udp<\/p><\/blockquote>\n<p>\u4f46nlockmgr\u5728\u8fd9\u4e2a\u6587\u4ef6\u4e2d\u662f\u56fa\u5b9a\u4e0d\u4e0b\u6765\u7684\uff0c\u6240\u4ee5<br \/>vi \/etc\/sysconfig\/nfs<br \/>\u628a\u6ce8\u89e3\u7684#\u53bb\u6389 \u6539\u6210\u8fd9\u6837\u5b50<br \/>LOCKD_TCPPORT=1012<br \/>LOCKD_UDPPORT=1012<\/p>\n<p>\u518drcpinfo -p\u770b\u770b\uff0c\u662f\u4e0d\u662f\u548c\u6211\u4e0a\u8fb9\u7684\u4e00\u6837\u4e86\u3002<br \/>\u5982\u679c\u7aef\u53e3\u56fa\u5b9a\u4e0b\u6765\u4e86\uff0c\u4e0b\u6765\u6765\u914d\u9632\u706b\u5899<\/p>\n<p>\u5728iptables\u4e2d\u7684*filter\u4e2d\u52a0\u5165\u4ee5\u4e0b\u8bed\u53e5(\/etc\/sysconfig\/iptables)<\/p>\n<p>#============================nfs======================<br \/>-A INPUT -p tcp -s 192.168.1.0\/24 -m multiport &#8211;dport 111,1011,875,1012,1010,2049 -j ACCEPT<br \/>-A INPUT -p udp -s 192.168.1.0\/24 -m multiport &#8211;dport 111,1011,875,1012,1010,2049 -j ACCEPT<br \/>#=======================================================<br \/>\u7136\u540e\u91cd\u542fiptables<br \/>\/etc\/init.d\/iptables restart<br \/>\u770b\u770b\u80fd\u6302\u8f7d\u4e0d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u65b0\u7248\u7684NFS\u548c\u4ee5\u524d\u4e0d\u4e00\u6837\u4e86\u7248\u672c\uff1a [root@mydisk ~]# rpcinfo -p program ve [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[],"class_list":["post-128","post","type-post","status-publish","format-standard","hentry","category-linux"],"_links":{"self":[{"href":"https:\/\/www.kumouse.com\/index.php?rest_route=\/wp\/v2\/posts\/128","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kumouse.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kumouse.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kumouse.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kumouse.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=128"}],"version-history":[{"count":0,"href":"https:\/\/www.kumouse.com\/index.php?rest_route=\/wp\/v2\/posts\/128\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.kumouse.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=128"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kumouse.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=128"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kumouse.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=128"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}