All of lore.kernel.org
 help / color / mirror / Atom feed
* ftp passive ports and their state
@ 2006-09-27 22:12 gabrix
  2006-09-27 22:48 ` Shane Hickey
  0 siblings, 1 reply; 2+ messages in thread
From: gabrix @ 2006-09-27 22:12 UTC (permalink / raw)
  To: netfilter

I have a debian sarge kernel 2.6 stable and proftpd as ftpd ... .My ftpd 
is open to internet users and i accept passive ftping.I have inserted a 
PassivePorts 60000 65534 directive in proftpd.conf for passive 
connections which it's still a hole of 5534 ports in my firewall.Could i 
accept connections to this ports  in a state ESTABLISHED,RELATED in my 
iptables script ?

Thanks !


^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: ftp passive ports and their state
  2006-09-27 22:12 ftp passive ports and their state gabrix
@ 2006-09-27 22:48 ` Shane Hickey
  0 siblings, 0 replies; 2+ messages in thread
From: Shane Hickey @ 2006-09-27 22:48 UTC (permalink / raw)
  To: netfilter

gabrix <gabrix@gabrix.ath.cx> [2006-09-28 00:12]:
> I have a debian sarge kernel 2.6 stable and proftpd as ftpd ... .My
> ftpd is open to internet users and i accept passive ftping.I have
> inserted a PassivePorts 60000 65534 directive in proftpd.conf for
> passive connections which it's still a hole of 5534 ports in my
> firewall.Could i accept connections to this ports  in a state
> ESTABLISHED,RELATED in my iptables script ?

If you haven't already, you might want to check out the ip_conntrack_ftp and ip_nat_ftp modules.  I believe they do some sort of magic with passive FTP.

Shane

-- 
Shane Hickey <shane@howsyournetwork.com>: Network/System Consultant
GPG KeyID: 777CBF3F
Key fingerprint: 254F B2AC 9939 C715 278C  DA95 4109 9F69 777C BF3F


^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2006-09-27 22:48 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2006-09-27 22:12 ftp passive ports and their state gabrix
2006-09-27 22:48 ` Shane Hickey

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.