Thread: NFS through PF
View Single Post
  #4   (View Single Post)  
Old 14th November 2012
jggimi's Avatar
jggimi jggimi is online now
More noise than signal
 
Join Date: May 2008
Location: USA
Posts: 7,983
Default

That redesign could include the use of a VPN. The OpenBSD FAQ section on NFS, FAQ 6.7, recommends as ipsec(4) solution for NFS over an insecure network.

I suppose an admin might prefer net/openvpn, or ssh(1) tunneling to IPSec, but those solutions should be very carefully tested. I believe their higher communications overheads may have significant functional impact: I/O delays or I/O timeouts leading to functional problems with an application; perhaps even application failures.

Last edited by jggimi; 14th November 2012 at 08:07 PM. Reason: clarity
Reply With Quote