From mboxrd@z Thu Jan 1 00:00:00 1970 From: "Peter Marshall" Subject: Re: proxy and ftp Date: Wed, 26 May 2004 09:17:20 -0300 Sender: netfilter-admin@lists.netfilter.org Message-ID: <0e2101c4431b$64ec6b10$49caa8c0@caris.priv> References: <0da401c44315$730d6b50$49caa8c0@caris.priv> Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="----=_NextPart_000_0E1E_01C44302.3F934C30" Return-path: Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: To: Peter Marshall , netfilter@lists.netfilter.org This is a multi-part message in MIME format. ------=_NextPart_000_0E1E_01C44302.3F934C30 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable I should have also mentioned, that my concern with ftp is mostly weather = to configure the rules with passive or active mode ... I realize the = active mode is "better" for me as a server admin ... however could cause = many problems on the client side ....=20 Peter ----- Original Message -----=20 From: Peter Marshall=20 To: netfilter@lists.netfilter.org=20 Sent: Wednesday, May 26, 2004 8:34 AM Subject: proxy and ftp Hello everyone. =20 I have most of my firewall rules configured, however, I am not sure = what I should do for rules for my ftp and proxy servers. I have a = diagram below giving a picture of how my setup is configured. If = someone (or many-ones ) would not mind giving me some ideas for forward = chain rules for my ftp and proxy servers, I would really appreciate it = ... I am kind of stumped as to how to not open my firewall up to the = world ..... Thank you very much Peter ----------------------------- eth0 a.a.a.1/29 external firewall eth1 b.b.b.1/26 ---------------------------- - - proxy server b.b.b.3 - ftpserver b.b.b.4 - - ----------------------------- eth1 b.b.b.2/26 internal firewall eth0 c.c.c.1/21 ---------------------------- ------=_NextPart_000_0E1E_01C44302.3F934C30 Content-Type: text/html; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable
I should have also mentioned, that my = concern with=20 ftp is mostly weather to configure the rules with passive or active mode = ... I=20 realize the active mode is "better" for me as a server admin ... however = could=20 cause many problems on the client side ....
 
Peter
----- Original Message -----
From:=20 Peter=20 Marshall
To: netfilter@lists.netfilter.o= rg=20
Sent: Wednesday, May 26, 2004 = 8:34=20 AM
Subject: proxy and ftp

Hello everyone. 
 
I have most of my firewall rules = configured,=20 however, I am not sure what I should do for rules for my ftp and proxy = servers.  I have a diagram below giving a picture of how my setup = is=20 configured.  If someone (or many-ones ) would not mind giving me = some=20 ideas for forward chain rules for my ftp and proxy servers, I would = really=20 appreciate it ... I am kind of stumped as to how to not open my = firewall up to=20 the world .....
 
Thank you very much
Peter
 
 
-----------------------------
eth0 a.a.a.1/29
external firewall
eth1 b.b.b.1/26
----------------------------
-
- proxy server b.b.b.3
- ftpserver b.b.b.4
-
-
-----------------------------
eth1 b.b.b.2/26
internal firewall
eth0 c.c.c.1/21
----------------------------
 
 
 
------=_NextPart_000_0E1E_01C44302.3F934C30--