Re: Iptables FTP question

From: David (davidwnh_at_adelphia.net)
Date: 10/27/03

  • Next message: GuitarMan: "Re: Duane Arnold to star in "Chimpie in the mist""
    Date: Mon, 27 Oct 2003 22:50:43 GMT
    
    

    You would only need RELATED set in your rule for port 21 if you were
    allowing it to deal with related ICMP traffic for the control
    connection. And since you put -p tcp in your rule it will not deal with
    any related ICMP anyhow. As far as the ftp module specifically, the
    related statement applies to the initial syn packet for your secondary
    connections which will only be analyzed in the filters you use for the
    secondary connections. And once that syn packet is replied to, the
    secondary connection then becomes an established connection.

    >
    >>Erratum
    >>
    >>line
    >>
    >>>Thats why -sport 21 isnt good, it must ESTABLISHED only
    >>
    >>should be RELATED
    >>
    >
    > I still think it should be
    > $IPTABLES -A FORWARD -i $EXTIF -o $INTIF -p TCP --sport 21 \
    > -m state --state RELATED,ESTABLISHED -j ACCEPT
    >
    > ESTABLISHED I need for the ftp control traffic on port 21
    > RELATED I need for the ftp data traffic either to/from port 20 or a high
    > port number this should cover active and passive ftp.
    >
    > Bye,
    > Peter
    >


  • Next message: GuitarMan: "Re: Duane Arnold to star in "Chimpie in the mist""

    Relevant Pages

    • RE: Telnet/ftp problems SBS2000
      ... Please make sure your client computers are configured as both Firewall ... will find two options "Enable folder view for FTP sites" and "Use Passive ... that the control connection has been successfully established, ... (other than port 21) ...
      (microsoft.public.windows.server.sbs)
    • Re: IPSwitch, Inc. WS_FTP Server
      ... > bounce attack as well as PASV connection hijacking. ... > The FTP bounce vulnerability allows a remote attacker to cause the ... > anonymously along with any internal addresses that the FTP server has ... That means it's got to handle a PORT ...
      (Bugtraq)
    • RE: FTP Window of opportunity?
      ... target on the line when in reality it was just a firewall lying to them. ... The connection connects and then immediately ... Subject: FTP Window of opportunity? ... the FTP port shows up. ...
      (Pen-Test)
    • Re: Iptables FTP question
      ... think all other related would be from specific modules,the FTP and IRC ... Keep in mind that connection ... source port of 20 if it is for port mode data connections(for a standard ... I would also break down your rules into chains instead of appending such ...
      (comp.security.firewalls)
    • Re: Passive means what during FTP?
      ... :227 Entering Passive Mode ... :ftp: connect: No route to host ... The FTP data transfer uses a connection that is separate from the ... address and port number to connect to for the data transfer. ...
      (comp.os.linux.setup)