Re: keep state "issue" / possible feature for the future?

This is a discussion on Re: keep state "issue" / possible feature for the future? within the IPFilter forums, part of the System Security and Security Related category; chrisj@ucia.gov wrote: > ... > I issue the mount command to do an NFS mount of a remote filesystem. &...


Go Back   Usenet Forums > System Security and Security Related > IPFilter

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 03-03-2007
Darren Reed
 
Posts: n/a
Default Re: keep state "issue" / possible feature for the future?

chrisj@ucia.gov wrote:
> ...
> I issue the mount command to do an NFS mount of a remote filesystem.
>
> The remote server is running IPMP - each of the two NIC's
> on the remote server has a test IP address
> (deprecated, non-failover) and an active/usable IP address.
>
> My mount command specifies one of the two active IP addresses
>
> By snoop'ing my interface I see my machine send off a
> PORTMAP C GETPORT ... packet to
> the IP address I specified but (sometimes) the
> remote NFS server decides to reply using its alternate IP
> address which means that the packet is not seen as being
> part of the conversation I initiated and so is dropped.
>
> Any ideas that would allow me to continue to benefit from
> the elegance of the 'keep state' lines above?



This sounds like a bug in mountd in how it sends back UDP
based replies. It should be sending back replies with the
source address set to the original destination address, even
if it has to open a UDP socket for each IP address involved.

If the packet comes out of the same interface as the one it
went in then there might be an option you can use with the
route command to force all packets leaving that interface
to have its source address.

If the packet isn't coming out the same interface and it has
a source address for the "other" interface, I would be filing
a bug with Sun about this problem. I think there is a very
clear expectation on how it *should* work and that this
isn't happening. Include the bugid when you hear back from
Sun on it :)

Darren

Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 04:31 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0