3.3.12 nfs_use_reserved_ports - portcheck

Information

The portcheck and nfs_use_reserved_ports parameters force the NFS server process on the local system to ignore NFS client requests that do not originate from the privileged ports range (ports less than 1024).

Rationale:

The portcheck and nfs_use_reserved_ports parameters will both be set to 1. This value means that NFS client requests that do not originate from the privileged ports range (ports less than 1024) will be ignored by the local system.

Solution

In /etc/tunables/nextboot, add the portcheck and nfs_use_reserved_ports entries:

nfso -p -o portcheck=1
nfso -p -o nfs_use_reserved_ports=1

This makes the change permanent by adding the entry into /etc/tunables/nextboot

Default Value:

0

See Also

https://workbench.cisecurity.org/files/4119

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6

Plugin: Unix

Control ID: 3143adcf625d9e34646c691bef1b4e9dac9a1ff6efe299e1b5e12da2fc1fc736