At UIUC we run with our portmapper closed to the outside world via tcp wrappers (/etc/hosts.allow|deny) The incoming LDM clients do initially beat on the portmapper looking for the LDM service, but they quickly give up and use the default port 388. So far there have been no problems, but the point is that the portmapper is available internally to LDM.
ldm-users
archives: