From mboxrd@z Thu Jan 1 00:00:00 1970 From: Andy Furniss Date: Sat, 08 Jan 2005 11:57:14 +0000 Subject: Re: [LARTC] Marking ftp inbound traffic is impossible ? Message-Id: <41DFCA9A.5090605@dsl.pipex.com> List-Id: References: <20050108075557.73544.qmail@web51605.mail.yahoo.com> In-Reply-To: <20050108075557.73544.qmail@web51605.mail.yahoo.com> MIME-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit To: lartc@vger.kernel.org ngo giang wrote: > Hello, > > I searched the archives mailing list of LARTC. Everyone discussed about marking outbound ftp > > traffic . I could not find any thread discussed about marking inbound ftp traffic. > > With inbound ftp traffic , we don't know the random ports specified by ftp servers in passive mode ? > > So marking inbound ftp traffic is impossible ? > > If it is possible, can you tell me, > > Thanks in advance, > > nhgiang There's an ftp protocol netfilter match - if you are conntracking maybe that will do it - never tested it myself. Andy. _______________________________________________ LARTC mailing list / LARTC@mailman.ds9a.nl http://mailman.ds9a.nl/mailman/listinfo/lartc HOWTO: http://lartc.org/