* ftp passive ports and their state
@ 2006-09-27 22:12 gabrix
2006-09-27 22:48 ` Shane Hickey
0 siblings, 1 reply; 2+ messages in thread
From: gabrix @ 2006-09-27 22:12 UTC (permalink / raw)
To: netfilter
I have a debian sarge kernel 2.6 stable and proftpd as ftpd ... .My ftpd
is open to internet users and i accept passive ftping.I have inserted a
PassivePorts 60000 65534 directive in proftpd.conf for passive
connections which it's still a hole of 5534 ports in my firewall.Could i
accept connections to this ports in a state ESTABLISHED,RELATED in my
iptables script ?
Thanks !
^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: ftp passive ports and their state
2006-09-27 22:12 ftp passive ports and their state gabrix
@ 2006-09-27 22:48 ` Shane Hickey
0 siblings, 0 replies; 2+ messages in thread
From: Shane Hickey @ 2006-09-27 22:48 UTC (permalink / raw)
To: netfilter
gabrix <gabrix@gabrix.ath.cx> [2006-09-28 00:12]:
> I have a debian sarge kernel 2.6 stable and proftpd as ftpd ... .My
> ftpd is open to internet users and i accept passive ftping.I have
> inserted a PassivePorts 60000 65534 directive in proftpd.conf for
> passive connections which it's still a hole of 5534 ports in my
> firewall.Could i accept connections to this ports in a state
> ESTABLISHED,RELATED in my iptables script ?
If you haven't already, you might want to check out the ip_conntrack_ftp and ip_nat_ftp modules. I believe they do some sort of magic with passive FTP.
Shane
--
Shane Hickey <shane@howsyournetwork.com>: Network/System Consultant
GPG KeyID: 777CBF3F
Key fingerprint: 254F B2AC 9939 C715 278C DA95 4109 9F69 777C BF3F
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2006-09-27 22:48 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2006-09-27 22:12 ftp passive ports and their state gabrix
2006-09-27 22:48 ` Shane Hickey
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.