Linux Netfilter discussions
 help / color / mirror / Atom feed
* Re: iptables ip_conntrack_ftp + proftpd TLS: PORT command not understood
@ 2008-05-26 19:24 Filippo Zeus
  2008-05-26 19:39 ` whiplash
  0 siblings, 1 reply; 15+ messages in thread
From: Filippo Zeus @ 2008-05-26 19:24 UTC (permalink / raw)
  To: netfilter

That's true ... proftpd has been configured to encrypt auth+data
so the PORT command is sent in cleartext way.

I you read
question Using mod_tls, FTP sessions through my firewall now no longer 
work. What's going on?
at http://www.castaglia.org/proftpd/doc/contrib/ProFTPD-mini-HOWTO-TLS.html

proftpd developers suggest to do this to fix this problem...
but it do not work.

please help

> There's no bug, indeed.
> Conntrack helper simply *can't* see the PORT command, since the packet 
> payload
> is encrypted.
>

^ permalink raw reply	[flat|nested] 15+ messages in thread
[parent not found: <483B04A8.9000405@gmail.com>]

end of thread, other threads:[~2008-05-27  7:49 UTC | newest]

Thread overview: 15+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2008-05-26 19:24 iptables ip_conntrack_ftp + proftpd TLS: PORT command not understood Filippo Zeus
2008-05-26 19:39 ` whiplash
2008-05-26 20:00   ` Filippo Zeus
2008-05-26 20:41     ` Patrick McHardy
2008-05-27  1:14       ` Filippo Zeus
2008-05-27  7:39         ` Patrick McHardy
2008-05-27  7:46           ` Jan Engelhardt
2008-05-27  7:49         ` whiplash
2008-05-26 22:05     ` Jan Engelhardt
2008-05-26 22:32       ` Jan Engelhardt
2008-05-26 22:32       ` whiplash
2008-05-27  1:30         ` Filippo Zeus
     [not found] <483B04A8.9000405@gmail.com>
2008-05-26 18:51 ` Filippo Zeus
2008-05-26 19:07   ` whiplash
2008-05-26 19:28   ` Jan Engelhardt

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox