Re: access control for mountd, statd, and lockd?

On Sun, Feb 07, 2010 at 12:19:31PM -0500, Steven Bellovin wrote:
> > The NFS and mount services are special-cased in the RPC standard: they
> > have static port numbers.
> mountd also has a -p option to specify a port number.

On my NFS server "mountd", "rpc.statd" and "rpc.lockd" all listen on
privileged port numbers (<1024). My firewall blocks all of those
except specific exceptions which hopefully keeps this services safe.

