I beg to differ, jggimi. You can sysctl net.inet.tcp.baddynamic to all ports except the one you want mountd to use =P
Just kidding, really, there's not really a good solution to this other than redesigning so you aren't using nfs across a firewall.
__________________
Linux/Network-Security Engineer by Profession. OpenBSD user by choice.
|