{"id":61,"date":"2014-03-17T00:55:47","date_gmt":"2014-03-16T23:55:47","guid":{"rendered":"http:\/\/eggblog.invertedegg.com\/?p=61"},"modified":"2014-03-17T00:55:47","modified_gmt":"2014-03-16T23:55:47","slug":"setting-up-ubuntu-firewall-ufw-for-nfs","status":"publish","type":"post","link":"http:\/\/eggblog.invertedegg.com\/?p=61","title":{"rendered":"Setting up Ubuntu Firewall (UFW) for NFS"},"content":{"rendered":"<p>I use ufw as my firewall in Ubuntu. \u00c2\u00a0I was recently trying to hook two Ubuntu servers together with NFS, and running into firewall problems. \u00c2\u00a0Here&#8217;s how to get it working, in case you&#8217;re encountering the same problem.<\/p>\n<p>1. \u00c2\u00a0Start by ensuring that you have the basic NFS ports open. \u00c2\u00a0These are going to be 2049 (udp\/tcp) for NFS, and 111 (udp\/tcp) for &#8220;sunrpc&#8221;. \u00c2\u00a0You can add both of these with a straightforward ufw rule, relying on \/etc\/services to identify the ports. \u00c2\u00a0For example, assuming that you have LCL_NET set to your local network, and only want to allow access to machines in that network:<\/p>\n<blockquote><p>ufw allow from ${LCL_NET} to any port nfs<\/p>\n<p>ufw allow from ${LCL_NET} to any port sunrpc<\/p><\/blockquote>\n<p>2. \u00c2\u00a0The next problem you have is that the rpc.mountd port is assigned randomly, unless you fix it otherwise. \u00c2\u00a0So, first, edit \/etc\/default\/nfs-kernel-server and change the line for RPCMOUNTDOPTS to be:<\/p>\n<blockquote><p>RPCMOUNTDOPTS=&#8221;-p 4001 -g&#8221;<\/p><\/blockquote>\n<p>Then go back to ufw and allow this port for both udp and tcp. \u00c2\u00a0(I&#8217;m not including the command, as there are a few different ways to do it, and I do it in a way that&#8217;s simpler in the end, but more complex to explain at the moment.)<\/p>\n<p>Finally, of course, restart ufw and nfs.<\/p>\n<p>Resources:<\/p>\n<ul>\n<li>Check your ports to see what&#8217;s specified, and what&#8217;s picking a random port with: \u00c2\u00a0rpcinfo -p<\/li>\n<li>See <a href=\"http:\/\/ubuntuforums.org\/showthread.php?t=1407246\">this page for a good brief introduction to how to solve this<\/a>.<\/li>\n<li>See<a href=\"http:\/\/www.lowth.com\/LinWiz\/nfs_help.html\"> this page for a detailed description, including how to go after some other ports that may cause you problems<\/a>.<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I use ufw as my firewall in Ubuntu. \u00c2\u00a0I was recently trying to hook two Ubuntu servers together with NFS, and running into firewall problems. \u00c2\u00a0Here&#8217;s how to get it working, in case you&#8217;re encountering the same problem. 1. \u00c2\u00a0Start by ensuring that you have the basic NFS ports open. \u00c2\u00a0These are going to be &hellip; <a href=\"http:\/\/eggblog.invertedegg.com\/?p=61\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Setting up Ubuntu Firewall (UFW) for NFS&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[6],"tags":[],"_links":{"self":[{"href":"http:\/\/eggblog.invertedegg.com\/index.php?rest_route=\/wp\/v2\/posts\/61"}],"collection":[{"href":"http:\/\/eggblog.invertedegg.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/eggblog.invertedegg.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/eggblog.invertedegg.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/eggblog.invertedegg.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=61"}],"version-history":[{"count":1,"href":"http:\/\/eggblog.invertedegg.com\/index.php?rest_route=\/wp\/v2\/posts\/61\/revisions"}],"predecessor-version":[{"id":62,"href":"http:\/\/eggblog.invertedegg.com\/index.php?rest_route=\/wp\/v2\/posts\/61\/revisions\/62"}],"wp:attachment":[{"href":"http:\/\/eggblog.invertedegg.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=61"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/eggblog.invertedegg.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=61"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/eggblog.invertedegg.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=61"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}