Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
NFS question
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
neuron
Advocate
Advocate


Joined: 28 May 2002
Posts: 2371

PostPosted: Thu Nov 04, 2004 1:40 pm    Post subject: NFS question Reply with quote

I'm currently using samba to access my server, but I've had some problems with it lately, and either way I've found nfs to be considerably less resource hungry (encrypted hd's, so cpu is a bottleneck, I get 4mb/sec with samba and 7mb/sec with nfs!), with samba I need a login to access my server, but for nfs (as far as I understand it) read-write control is by ip, not that I dont trust the people on this network, but stealing an ip isn't exactly hard.

Is there any way to do some confirmation thing that that ip is actually the box it should be? And as I said cpu is a bottleneck so I'd rather not mount through ssh.
Back to top
View user's profile Send private message
nightblade
Guru
Guru


Joined: 20 Jul 2004
Posts: 368
Location: back from SE Asia

PostPosted: Thu Nov 04, 2004 1:52 pm    Post subject: Reply with quote

if the NFS client and server are on the same subnet, you can use a static arp entry to uniquely correlate the IP address with the MAC address. This would make messing up with IPs much harder (for every protocol/service, not just NFS), and would protect you from ARP poisoning attacks as well.
_________________
In God we trust. All the others must provide a valid X.509 certificate
Back to top
View user's profile Send private message
neuron
Advocate
Advocate


Joined: 28 May 2002
Posts: 2371

PostPosted: Sat Nov 06, 2004 12:06 am    Post subject: Reply with quote

would make it a bit harder I suppose, it's still possible to alter the MAC address from the bios'es of two of the computers I got standing here (nforce2 chipsets with onboard networking).
Back to top
View user's profile Send private message
nightblade
Guru
Guru


Joined: 20 Jul 2004
Posts: 368
Location: back from SE Asia

PostPosted: Sun Nov 07, 2004 1:36 am    Post subject: Reply with quote

Depends on the situation: keep in mind that switches usually complain when they see the same unicast MAC on more than one port and this would make things hard for someone trying to spoof both the IP and the MAC address.
_________________
In God we trust. All the others must provide a valid X.509 certificate
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum