Joseph Mack wrote:
> you're going to have to find the ports involved with Kerberos and LVS them
> too.
hmm, there's lot of ports involved. I seem to remember that people don't
like Kerberos for this reason.
http://www.lns.cornell.edu/public/COMP/krb5/krb5-admin/Configuring-Your-Firewall-to-Work-With-Kerberos-V5.html
If all these ports listen, then you could group them with fwmark.
If any of them are making callbacks (like ftp) then you'll need to
use port 0 with persistence or write a helper.
Joe
--
Joseph Mack PhD, High Performance Computing & Scientific Visualization
LMIT, Supporting the EPA Research Triangle Park, NC 919-541-0007
Federal Contact - John B. Smith 919-541-1087 - smith.johnb@xxxxxxx
|