Can RPC port 111(portmap) be disabled in ONTAP?
Applies to
- Data ONTAP operating in 7-Mode
- Data ONTAP 8
- ONTAP 9
Answer
- There is currently no way to disable portmapper (port 111) in either Data ONTAP 7-Mode
-
In ONTAP 9.3 and earlier (including Clustered Data ONTAP 8.x), the portmap service (rpcbind) was always accessible on port 111 in network configurations that relied on the built-in ONTAP firewall rather than a third-party firewall.
-
Starting in ONTAP 9.4, you can modify firewall policies to control whether the portmap service is accessible on particular LIFs.
-
Starting in ONTAP 9.7, the portmap firewall service is eliminated, and the portmap port is opened automatically for all LIFs that support the NFS service.
Additional Information
For more information, see Configuring firewall services and policies for LIFs