Re: AFS behind PF

2014-11-26 Thread Predrag Punosevac
"Rowan, Jim"  wrote:

> 
> On Nov 26, 2014, at 8:32 PM, Predrag Punosevac  wrote:
> 
> > 
> > Can anybody point me to any documents 
> 
> google openafs firewall ports, and read the first doc?
After reading that document and little bit of trail and error I am down
to passing out 

UDP 7000, 7003, 7005, 7006

as well as complete pass on

UDP kerberos(88), 7002

It looks like AFS doesn't use any TCP ports.  I will try to tight things
little bit more on Monday but that seems like a significant progress.

Predrag



Re: AFS behind PF

2014-11-26 Thread Rowan, Jim
On Nov 26, 2014, at 8:32 PM, Predrag Punosevac  wrote:

> 
> Can anybody point me to any documents 

google openafs firewall ports, and read the first doc?