Unsolved
12 Posts
0
368
April 11th, 2023 11:00
Unity NAS / NFS host masking not working
I have an NFS share on one of my unity arrays, and it keeps showing up on my nesus scans. I configured host access to limit what can connect to the share, but it does not appear to be working.
I can't figure out what I am missing.
No Events found!
DELL-Josh Cr
Moderator
•
9.2K Posts
0
April 12th, 2023 08:00
What version of the OE are you on? Which Unity device are you using?
Evraz
12 Posts
0
April 12th, 2023 08:00
Thank you for that. However, if i were to disallow root on the NFS mounts, my VMware would not be able to mount the volumes as datastores for VMs and Content Libraries.
How do I get both; VMware mounting the NFS volumes, and the NFS exports not showing up on my nesus scans?
DELL-Josh Cr
Moderator
•
9.2K Posts
0
April 12th, 2023 08:00
Hi,
Thanks for your question. This should specifically cover this showing up on scans. https://dell.to/3GyKN3V
To specifically disallow non-root users from mounting exports from Unity, enter the following at a Unity command line:
svc_nas ALL -param -f mount -m checkPort -v 1
Let us know if you have any additional questions.
Evraz
12 Posts
0
April 12th, 2023 08:00
4 Unity 600F, and 2 Unity 550F, all running 5.2.1.0.5.013
DELL-Josh Cr
Moderator
•
9.2K Posts
0
April 12th, 2023 09:00
What steps did you take to set up the host masking? Does it block other devices not given access? In that same article You could use root= to specify that Vmware could still have root but block root for other users.
Evraz
12 Posts
0
April 12th, 2023 10:00
I added my 4 VMware hosts to Host Access for the NAS Share, nothing else is there. Yet, Nessus still finds it.
I am not proficient with the unity CLI ... can you help me with a statement that will allow my vSphere hosts with root, but nothing else to access the NAS share?
DELL-Josh Cr
Moderator
•
9.2K Posts
0
April 12th, 2023 10:00
I think you need to disallow the default access so that only the specified hosts can access. Page 376 https://dell.to/3mryYWv /stor/prov/fs/nfs -defAccess na