Re: securing an FTP service

From: Davide (ak_71_at_libero.it)
Date: 11/24/04

  • Next message: Shawn Wall: "DOS Attack?"
    Date: 24 Nov 2004 15:15:22 -0000
    To: security-basics@securityfocus.com
    
    
    ('binary' encoding is not supported, stored as-is) In-Reply-To: <41A043F900025D3B@vsmtp2alice.tin.it (added by postmaster@aliceposta.it)>

    thanks pingywon and alessandro for your hints.
    yes, the lan is natted. FTP service on the firewall
    is redirected to the Server. I understand the fact that
    since at branch office IP is dynamic i cannot
    reject (at the firewall level) ftp requests
    that do not come from IP others than branch office's.

    But I think I failed to explain the prospected solution:
    the ftp-server is placed in the DMZ
    (internet)---(router)---(firewall)---(ftp-server)---(internal firewall AKA "holed fiewall")---(LAN)---(computer hosting the ftproot)

    i.e. the ftproot sits in another computer inside the LAN. this would expose to the DMZ the NETBIOS sharing
    needed to the ftp-server to access the ftproot:
    on the internal firewall, netbios ports should be
    redirected to the computer hosting the ftproot.
    On the computer hosting the ftproot, we configure:
    .a folder, containig the documents, read-only;
    .another folder used to host the files the remote
    user finally needs to give (put) to the colleagues
    with read/write/delete access.
    . users in the central office access the ftproot
    as any normal shared resource in the LAN.

    Does this setup give any sense?

    thanks
    davide

    >On Tuesday 23 November 2004 00:11, Davide wrote:
    >>
    >>
    (internet)---(router)---(firewall)---(LAN)---(server)
    >>
    >the LAN is NATted? If so, you'll need to set Port Address
    >Translation on the firewall/nat.
    >
    [...]
    >takers?).
    >
    >Cheers
    >
    >--
    >Alessandro Bottonelli, CISSP & BS7799 Lead Auditor
    >AXIS-NET Privacy & InfoSec Consulting
    >http://www.axis-net.it
    >


  • Next message: Shawn Wall: "DOS Attack?"

    Relevant Pages

    • sp1 for 2003 stopped incomingl ftp connections ?
      ... I installed SP1 for 2003 web edition and external users now cant connect to ... Internally its ok (i.e from LAN on diagram below). ... traffic on 21 and forwarding to ftp service. ... Firewall ...
      (microsoft.public.inetserver.iis.ftp)
    • Re: How save is a Windows PC on a Linux network.
      ... firewall between the dialup and the internal lan. ... Being of sound mind and body, I never surf with the Windows machine and ... Assuming you trust your firewall, and you know what's running on the ... I have to have it on the lan to access the Linux servers but sometimes it ...
      (comp.os.linux.misc)
    • Re: OWA
      ... 'Thats good news at least about the firewall. ... Tried them both earlier and same error message - 403. ... get ths same error message in and outside of the LAN? ...
      (microsoft.public.backoffice.smallbiz2000)
    • Re: How to stealth against ping/echo requests?
      ... I just started using the Online-Armor firewall. ... Some ports are even open. ... Are you behind a router? ... Every time it founds a new LAN, it asks if you want to trust it ...
      (comp.security.firewalls)
    • Re: [SLE] Firewall zones
      ... Looking at the firewall configuration in Yast, ... My network card is assigned its IP address by the router using DHCP. ... It connects to the LAN and to the router; the router in turn talks to the ... All the systems on the LAN are supposed to have the same firewall protection, ...
      (SuSE)

    Loading