> Its actually not. 192.168.X.X is not routed through the internet
> so it will be very hard to "jump" on it, especially if you mount it

But on the public interface of your fire wall is routed to
internet. And more service you add, more yu are prone to a bug in one
service. And if you miss configure your filtering...

I am thinking of using FreeBSD bridge facility with IP firewall,
network interface are not configured to run P, no IP service seen,
only Ethernet service (like a hub) but enhanced with firewall. No need
to say there would be no NFS available, but even no telnet/ssh to that
machine :)

> What does amcheck say regarding that?
> 
> nuthin.

I have seen in this list several times that you better back-up on th
client rather than NFS mount.

> > Now if you plan to use dump, this is completely hopeless as dump works
> > by disk block and knows nothing about the file system.
> > 
> 
> Now what the kind of logic behind that ;-))))

 Dump back-up a complete disk partition, so it simply goes disk block
by dick block and does not bother about the filse system logic set
above the disk blocks.


Olivier

Reply via email to