Source port on AIX for NAS is same?


Login or Register to Reply

 
Thread Tools Search this Thread
# 15  
Quote:
Originally Posted by anil1000
How to keep it alive? What do you mean by this, which connection to keep it alive? Kindly suggest..
In regular intervals packets are sent in an existing connection to make sure the partner still is there. These packets are called "keepalive" packets. If these packets are not received the partner assumes that the other side went dead and closes the connection.

Think of a connection like a telephone call: when you talk to someone you expect some sort of acknowledgement that the other is still listening at times, be it "aha" or "hmm" or something such. If you don't get that you may ask "are you still there" - and if there is no answer you hang up. This is quite the same mechanism.

I hope that helps.

bakunin
# 16  
In addition to what Bakunin said:
A firewall drops or rejects a connection after a certain period if there is no activity.
A keep-alive message can be sent as a null packet periodically by the client to keep a service alive. This keeps the firewall from dropping the connection. Of course if this is done liberally by every host for every connection then the connection table in the firewall would become too long. That is why some firewalls detect this behavior and ignore keepalives messages.
# 17  
I know this is an old discussion - but your problem is, imho, self-inflicted.

Code:
michael@x071:[/home/michael]nfso -h nfs_use_reserved_ports
Purpose:
Specifies using nonreserved IP port number.
Values:
        Default: 0
        Range: 0 - 1
        Type: Dynamic
        Unit: On/Off
Tuning:
Value of 0 will use nonreserved IP port number when the NFS client communicates with the NFS server.

The default is zero (0)
Code:
michael@x071:[/home/michael]nfso -o nfs_use_reserved_ports
nfs_use_reserved_ports = 0

In the early 1980's there was this idea that port numbers less than 1024 could be "trusted" because only the super-user (aka root) could access them. This trust has been misplaced since the late 1980's as too many processes can access this so-called trusted ports. Why trust NFS (on port 2049)? It is well above 1024. Why it that number above 2049 trust-worthy and not other numbers.

In short, "trusted ports" exist in that it is still specified that a kernel privilege is needed to "open" aka request a connection from/to any other port.

If someone, even from your local security, says they MUST be 1023 and smaller - of course you can comply - BUT they are causing another security concept to become breached - availability. Not enough ports means no connectivity.

In short, port numbers - there is no added trust because a specific port number is being used. There might be a technical reason (e.g., firewall rules) to stay in a particular range - but the port number itself neither adds nor subtracts from the application security.

My 4 cents - hope it gets you decent coffee Smilie
Login or Register to Reply

|
Thread Tools Search this Thread
Search this Thread:
Advanced Search

More UNIX and Linux Forum Topics You Might Find Helpful
Changing source port number of a TCP client packet
anuragrai134
Hi all, I need to change the source port number of an outgoing TCP packet. First I have to bind the socket to a particular port(suppose 9001) but when I send the TCP packet I want to change the source port number lets say to 9002 still letting the socket to be bound to the same old port (9001)....... Programming
0
Programming
AIX(VIO/LPAR) with Free NAS ISCSI solution
kabir
Hi, I was looking on Google for AIX-VIO/LPAR with ISCSI solution and found following really nice tutorial about how to setup ISCSI with free NAS. 1) Build Your Own Open Source NAS Device Using FreeNAS | Train Signal Training - Free Computer Training Videos 2) Build Your Own Open Source...... AIX
4
AIX
how to port a package to huge source code having its own make and compilers
Gopi Krishna P
In general for intalling a package like we do ./configure, make , make install But if we want to integrate the package with a huge source base what are the things to be taken care could some one have a light on purpose of ./configure , make and make install along with above question. I...... UNIX for Advanced & Expert Users
1
UNIX for Advanced & Expert Users
Source code for serial port
smartgupta
Hi, I am working with sun Solaris 5.9 and in my application,I have to communicate with Serial port(i.e /dev/term/a). So I need source code to by which I can do the following things-- 1)check the port is available or not.If it dosn't find the port,it should throw the error message(i.e. port not...... Programming
0
Programming