HP Visualize J5000 hp enterprise file system: planning and configuring hp DCE/ - Page 143

Configuring Gateway Server Machines

Page 143 highlights

The DFS/NFS Secure Gateway Configuring Gateway Server Machines Configuring Gateway Server Machines A Gateway Server machine provides authenticated access to the DFS filespace to users on NFS clients. You can configure any machine that is configured as a DFS client and an NFS server as a Gateway Server. Following successful configuration, the machine provides authenticated access to the DFS filespace, and it exports the root of the DCE namespace, /..., via NFS. You can configure multiple Gateway Server machines to provide DFS access from multiple sources. However, users do not randomly select Gateway Server machines from NFS clients. By default, users on an NFS client contact the Gateway Server machine that exports /.... to the client. If you want to balance the load among multiple Gateway Servers, you must configure your NFS clients so that each client mounts /.... from a different Gateway Server machine. (The "Configuring NFS Clients to Access DFS" section in this appendix provides information about configuring NFS clients.) Depending on how closely you want to control access to the DFS filespace, configure your Gateway Server machines in one of the following ways: • Configure the Gateway Server machines so that users cannot issue the dfs_login command to authenticate to DCE. This configuration allows system administrators to manage all DCE authentication from the Gateway Server machines. You can allow users to issue the dfsgw add command themselves, or you can limit use of the command to administrators only. To configure a Gateway Server machine without enabling remote authentication via the dfs_login command, follow the instructions in "Configuring a Gateway Server Without Enabling Remote Authentication." • Configure the Gateway Server machines so that users can issue the dfs_login command to authenticate to DCE. This configuration allows users of NFS clients to acquire their own DCE credentials from the NFS clients. To configure a Gateway Server machine and enable remote authentication via the dfs_login command, follow the instructions in "Configuring a Gateway Server and Enabling Remote Authentication." 143

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164

143
The DFS/NFS Secure Gateway
Configuring Gateway Server Machines
Configuring Gateway Server Machines
A Gateway Server machine provides authenticated access to the DFS
filespace to users on NFS clients. You can configure any machine that is
configured as a DFS client and an NFS server as a Gateway Server.
Following successful configuration, the machine provides authenticated
access to the DFS filespace, and it exports the root of the DCE namespace,
/...
, via NFS.
You can configure multiple Gateway Server machines to provide DFS
access from multiple sources. However, users do not randomly select
Gateway Server machines from NFS clients. By default, users on an NFS
client contact the Gateway Server machine that exports
/...
. to the client. If
you want to balance the load among multiple Gateway Servers, you must
configure your NFS clients so that each client mounts
/...
. from a different
Gateway Server machine. (The “Configuring NFS Clients to Access DFS”
section in this appendix provides information about configuring NFS
clients.)
Depending on how closely you want to control access to the DFS filespace,
configure your Gateway Server machines in one of the following ways:
Configure the Gateway Server machines so that users
cannot
issue the
dfs_login
command to authenticate to DCE.
This configuration allows system administrators to manage all DCE
authentication from the Gateway Server machines. You can allow users to issue
the
dfsgw add
command themselves, or you can limit use of the command to
administrators only. To configure a Gateway Server machine without enabling
remote authentication via the
dfs_login
command, follow the instructions in
“Configuring a Gateway Server Without Enabling Remote Authentication.”
Configure the Gateway Server machines so that users
can
issue the
dfs_login
command to authenticate to DCE.
This configuration allows users of NFS clients to acquire their own DCE
credentials from the NFS clients. To configure a Gateway Server machine and
enable remote authentication via the
dfs_login
command, follow the instructions
in “Configuring a Gateway Server and Enabling Remote Authentication.”