[OpenAFS] AFS client behind NAT

Tim Spriggs tims@arizona.edu
Tue, 15 Jan 2008 23:11:30 -0700


Jason C. Wells wrote:
> Derrick Brashear wrote:
>
> > get addressless tickets.
>
> Even if you get addressless tickets you may still have a problem with 
> hostname canonicalization that is performed by kerberos if you don't 
> have proper reverse DNS mapping.  I ran into this once upon a time.
It would sure be nice if OpenAFS worked with IPv6. It's really easy to 
deploy IPv6 to a NAT'd network and Kerberos works over IPv6 without a 
problem. Maybe you could use IPv6 to fix the Kerberos name/ip issues and 
then use the rest of OpenAFS behind a NAT. It's ugly but... it would 
would be kinda cool.