From mboxrd@z Thu Jan 1 00:00:00 1970 From: "wickedsun" Subject: Re: Is iptables kickin' that much? Date: Fri, 6 Sep 2002 22:12:16 -0400 (Eastern Daylight Time) Sender: netfilter-admin@lists.netfilter.org Message-ID: <3D796080.000001.00644@athlon1000> References: <3D793DE4.2060504@fugmann.dhs.org> Mime-Version: 1.0 Content-Type: Multipart/Alternative; boundary="------------Boundary-00=_G4Q1QL80000000000000" Return-path: Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: To: afu@fugmann.dhs.org Cc: netfilter --------------Boundary-00=_G4Q1QL80000000000000 Content-Type: Text/Plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable DC++ is a Direct Connect client. You can use either Passive or Active mod= e. It's just like FTP. In passive you get the search responces from the serv= er where as Active, the users send you the responces directly thru port 1412= =2E I used to have to map the ports, but after flushing my forwards and adding your rules to my IPtables, it worked.=0D =0D Look on sourceforge for DC++.=0D =0D -------Original Message-------=0D =0D From: Anders Fugmann=0D Date: Friday, September 06, 2002 7:52:52 PM=0D To: wickedsun=0D Cc: netfilter=0D Subject: Re: Is iptables kickin' that much?=0D =0D wickedsun wrote:=0D > thing to say, it works. =0D Great.=0D =0D > Now the question is, will this work with any=0D > protocol? (ftp, irc, etc). =0D as of today, only ftp and IRC is implemented in the vanilla tree. POM =0D may have connection tracking for other protocols.=0D =0D A protocol that requests something and then receives an answer is =0D handled by basic connection tracking (Which is why you dont need =0D connection tracking modules for e.g. http and pop, since no new =0D connection are established). It is the RELATED packets that are hard to =0D find.=0D =0D >The thing is scary me a bit. I read in your email=0D > that you have to load up a FTP module (which I have compiled in the kernel)=0D > and it seems to me that it works with other protocol as well. (I was ab= le to=0D > enable Active in DC++ without having to forward manually each ports lik= e I=0D > used to do).=0D Active DC++???? Never heard of it.=0D =0D > =0D > This was of a huge help for the iptables newbies (including me) and tha= nks =0D No problem.=0D =0D Regards=0D Anders Fugmann=0D =0D --=0D Author of FIAIF=0D FIAIF Is An Intelligent Firewall=0D http://fiaif.fugmann.dhs.org=0D =0D =0D =0D =2E=20 --------------Boundary-00=_G4Q1QL80000000000000 Content-Type: Text/HTML; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable
DC++ is a Direct Connect client. You can use either Passive or = Active mode. It's just like FTP. In passive you get the search&= nbsp;responces from the server where as Active, the users send you the re= sponces directly thru port 1412. I used to have to map the ports, bu= t after flushing my forwards and adding your rules to my IPtables, it wor= ked.
 
Look on sourceforge for DC++.
 
-------Original Message-------
 
Date: Friday, Sept= ember 06, 2002 7:52:52 PM
Subject: Re: Is ip= tables kickin' that much?
 
wickedsun wrote:
> thing to say, it works.
Gre= at.

> Now the question is, will this work with any
> prot= ocol? (ftp, irc, etc).
as of today, only ftp and IRC is implemented i= n the vanilla tree. POM
may have connection tracking for other protoc= ols.

A protocol that requests something and then receives an answe= r is
handled by basic connection tracking (Which is why you dont need=
connection tracking modules for e.g. http and pop, since no new
= connection are established). It is the RELATED packets that are hard to <= BR>find.

>The thing is scary me a bit. I read in your email
= > that you have to load up a FTP module (which I have compiled in the = kernel)
> and it seems to me that it works with other protocol as w= ell. (I was able to
> enable Active in DC++ without having to forwa= rd manually each ports like I
> used to do).
Active DC++???? Nev= er heard of it.

>
> This was of a huge help for the ipta= bles newbies (including me) and thanks.
No problem.

Regards
= Anders Fugmann

--
Author of FIAIF
FIAIF Is An Intelligent Fi= rewall
http://fiaif.fugmann.d= hs.org



.
--------------Boundary-00=_G4Q1QL80000000000000--