1)查看端口rpc使用端口https://www.cndba.cn/zhasir/article/3437
#rpcinfo -p
program vers proto port service
100000 4 tcp 111 portmapper
100000 3 tcp 111 portmapper
100000 2 tcp 111 portmapper
100000 4 udp 111 portmapper
100000 3 udp 111 portmapper
100000 2 udp 111 portmapper
100024 1 udp 60653 status
100024 1 tcp 34616 status
100011 1 udp 875 rquotad
100011 2 udp 875 rquotad
100011 1 tcp 875 rquotad
100011 2 tcp 875 rquotad
100005 1 udp 44827 mountd
100005 1 tcp 48606 mountd
100005 2 udp 49265 mountd
100005 2 tcp 33534 mountd
100005 3 udp 51657 mountd
100005 3 tcp 47918 mountd
100003 2 tcp 2049 nfs
100003 3 tcp 2049 nfs
100003 4 tcp 2049 nfs
100227 2 tcp 2049 nfs_acl
100227 3 tcp 2049 nfs_acl
100003 2 udp 2049 nfs
100003 3 udp 2049 nfs
100003 4 udp 2049 nfs
100227 2 udp 2049 nfs_acl
100227 3 udp 2049 nfs_acl
100021 1 udp 49197 nlockmgr
100021 3 udp 49197 nlockmgr
100021 4 udp 49197 nlockmgr
100021 1 tcp 44240 nlockmgr
100021 3 tcp 44240 nlockmgr
100021 4 tcp 44240 nlockmgr
2)配置固定的nfs端口号
#vim /etc/sysconfig/nfs
RQUOTAD_PORT=875
LOCKD_TCPPORT=32803
LOCKD_UDPPORT=32769
MOUNTD_PORT=892
STATD_PORT=662
#service rpcbind restart
Stopping rpcbind: [ OK ]
Starting rpcbind: [ OK ]
#service nfs restart
Shutting down NFS daemon: [ OK ]
Shutting down NFS mountd: [ OK ]
Shutting down NFS quotas: [ OK ]
Shutting down NFS services: [ OK ]
Shutting down RPC idmapd: [ OK ]
Starting NFS services: [ OK ]
Starting NFS quotas: [ OK ]
Starting NFS mountd: [ OK ]
Starting NFS daemon: [ OK ]
Starting RPC idmapd: [ OK ]
4)再次查看端口
#rpcinfo -p
program vers proto port service
100000 4 tcp 111 portmapper
100000 3 tcp 111 portmapper
100000 2 tcp 111 portmapper
100000 4 udp 111 portmapper
100000 3 udp 111 portmapper
100000 2 udp 111 portmapper
100011 1 udp 875 rquotad
100011 2 udp 875 rquotad
100011 1 tcp 875 rquotad
100011 2 tcp 875 rquotad
100005 1 udp 892 mountd
100005 1 tcp 892 mountd
100005 2 udp 892 mountd
100005 2 tcp 892 mountd
100005 3 udp 892 mountd
100005 3 tcp 892 mountd
100003 2 tcp 2049 nfs
100003 3 tcp 2049 nfs
100003 4 tcp 2049 nfs
100227 2 tcp 2049 nfs_acl
100227 3 tcp 2049 nfs_acl
100003 2 udp 2049 nfs
100003 3 udp 2049 nfs
100003 4 udp 2049 nfs
100227 2 udp 2049 nfs_acl
100227 3 udp 2049 nfs_acl
100021 1 udp 32769 nlockmgr
100021 3 udp 32769 nlockmgr
100021 4 udp 32769 nlockmgr
100021 1 tcp 32803 nlockmgr
100021 3 tcp 32803 nlockmgr
100021 4 tcp 32803 nlockmgr
5)添加防火墙规则(添加的位置很重要)https://www.cndba.cn/zhasir/article/3437https://www.cndba.cn/zhasir/article/3437https://www.cndba.cn/zhasir/article/3437https://www.cndba.cn/zhasir/article/3437
#vim /etc/sysconfig/iptables
-A INPUT -p tcp -m tcp -s 10.0.1.7 --dport 111 -j ACCEPT
-A INPUT -p udp -m udp -s 10.0.1.7 --dport 111 -j ACCEPT
-A INPUT -p tcp -m tcp -s 10.0.1.7 --dport 2049 -j ACCEPT
-A INPUT -p udp -m udp -s 10.0.1.7 --dport 2049 -j ACCEPT
-A INPUT -p tcp -m tcp -s 10.0.1.7 --dport 662 -j ACCEPT
-A INPUT -p udp -m udp -s 10.0.1.7 --dport 662 -j ACCEPT
-A INPUT -p tcp -m tcp -s 10.0.1.7 --dport 875 -j ACCEPT
-A INPUT -p udp -m udp -s 10.0.1.7 --dport 875 -j ACCEPT
-A INPUT -p tcp -m tcp -s 10.0.1.7 --dport 892 -j ACCEPT
-A INPUT -p udp -m udp -s 10.0.1.7 --dport 892 -j ACCEPT
-A INPUT -p tcp -m tcp -s 10.0.1.7 --dport 32803 -j ACCEPT
-A INPUT -p udp -m udp -s 10.0.1.7 --dport 32769 -j ACCEPT
6)重启防火墙
#service iptables restart
iptables: Setting chains to policy ACCEPT: filter [ OK ]
iptables: Flushing firewall rules: [ OK ]
iptables: Unloading modules: [ OK ]
iptables: Applying firewall rules: [ OK ]
7)客户端进行测试
正常现象:
https://www.cndba.cn/zhasir/article/3437https://www.cndba.cn/zhasir/article/3437https://www.cndba.cn/zhasir/article/3437https://www.cndba.cn/zhasir/article/3437
#showmount -e 10.0.1.12
Export list for 10.0.1.12:
/rman_backup/coredb 10.0.1.7
异常现象:
#showmount -e 10.0.1.12
clnt_create: RPC: Port mapper failure - Unable to receive: errno 113 (No route to host)
版权声明:本文为博主原创文章,未经博主允许不得转载。
nfs rpcbind iptables