LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Other *NIX Forums > Solaris / OpenSolaris
User Name
Password
Solaris / OpenSolaris This forum is for the discussion of Solaris, OpenSolaris, OpenIndiana, and illumos.
General Sun, SunOS and Sparc related questions also go here. Any Solaris fork or distribution is welcome.

Notices


Reply
  Search this Thread
Old 10-15-2012, 10:40 AM   #1
gatsby
Member
 
Registered: Jan 2006
Posts: 59

Rep: Reputation: 16
Controlling port range of RPC ports?


I'm trying to move some RPC-based services behind a firewall (the ancient NIS+ service, specifically).

Is there any potential way to control/specify the range of RPC ports so I can more easily firewall this machine? The default behavior seems to be that RPC services can attach anywhere from the mid-30000s to the mid-60000s. Thanks in advance for any assistance.

Last edited by gatsby; 10-15-2012 at 10:49 AM.
 
Old 11-09-2012, 02:22 AM   #2
tshikose
Member
 
Registered: Apr 2010
Location: Kinshasa, Democratic Republic of Congo
Distribution: RHEL, Fedora, CentOS
Posts: 525

Rep: Reputation: 95
Hi,

The answer is yes.
I think you need to add lines such the below in (I have never really set up NIS) one of /etc/sysconfig/network, /etc/sysconfig/nis, /etc/ypserv.conf.

YPSERV_ARGS="-p 10001" # This is obviously the main TCP port you want to fix to a not used high port
YPPASSWDD_ARGS="-p 10002" # If you also run the service that enables the password change
YPXFRD_ARGS="-p 10003" # If you also have replication, slave or secondary NIS servers
 
Old 11-10-2012, 02:01 PM   #3
gatsby
Member
 
Registered: Jan 2006
Posts: 59

Original Poster
Rep: Reputation: 16
I spoke to Oracle/Solaris support about this issue, and there is no way to predefine the port range of the ports the NIS+ services listen on. To move this service behind a hardware firewall that is not stateful, the NIS+ master must be allowed to communicate to basically TCP/UDP 32000 to TCP/UDP 65000 on the NIS+ client.

From Oracle Support, "There is no method of determining which ports will be used, hence there is no way to configure fixed port numbers to achieve this."
 
Old 11-12-2012, 01:09 AM   #4
tshikose
Member
 
Registered: Apr 2010
Location: Kinshasa, Democratic Republic of Congo
Distribution: RHEL, Fedora, CentOS
Posts: 525

Rep: Reputation: 95
Hi,

Which version of Linux and flavour are you using?
On Red Hat based Linux it is possible and easy as the steps I lead you to in my previous post.
 
Old 11-12-2012, 02:02 AM   #5
jlliagre
Moderator
 
Registered: Feb 2004
Location: Outside Paris
Distribution: Solaris 11.4, Oracle Linux, Mint, Debian/WSL
Posts: 9,789

Rep: Reputation: 492Reputation: 492Reputation: 492Reputation: 492Reputation: 492
Quote:
Originally Posted by tshikose View Post
Which version of Linux and flavour are you using?
None. Have a closer look at this forum name and last gatsby's answer ;-)
 
Old 11-12-2012, 03:03 AM   #6
tshikose
Member
 
Registered: Apr 2010
Location: Kinshasa, Democratic Republic of Congo
Distribution: RHEL, Fedora, CentOS
Posts: 525

Rep: Reputation: 95
Hi,

Yeah, I had just noticed it is a Solaris / OpenSolaris forum.
But still try what I had suggested.
It might work. Who knows!
 
Old 11-12-2012, 04:15 AM   #7
jlliagre
Moderator
 
Registered: Feb 2004
Location: Outside Paris
Distribution: Solaris 11.4, Oracle Linux, Mint, Debian/WSL
Posts: 9,789

Rep: Reputation: 492Reputation: 492Reputation: 492Reputation: 492Reputation: 492
Quote:
Originally Posted by tshikose View Post
Yeah, I had just noticed it is a Solaris / OpenSolaris forum.
But still try what I had suggested.
It might work. Who knows!
It won't as not only Solaris doesn't has/use the configuration files you suggested but the OP is asking about NIS+ which is a very very different beast than NIS.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] open RPC port range bino25 Linux - Networking 2 01-26-2011 07:56 AM
NFS and RPC ports Shibby Linux - Server 0 10-11-2008 10:14 AM
NFS RPC: Port mapper failure - RPC: Unable to receive KEJP Linux - Networking 6 12-18-2006 02:14 AM
controlling ports other than 80 with squid hacidayi Linux - Networking 1 09-08-2006 12:37 PM
rpc open ports helpme0904 Linux - Newbie 2 07-08-2005 04:00 PM

LinuxQuestions.org > Forums > Other *NIX Forums > Solaris / OpenSolaris

All times are GMT -5. The time now is 05:23 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration