Re: Linksys Router and PASV FTP

From: Jim Nugent (nuge_at_execpc.invalid)
Date: 02/09/04


Date: Mon, 09 Feb 2004 02:30:45 GMT


"Richard" <richard@nospam.no> wrote in message
news:oAwVb.251$72.179820032@news.telia.no...
> Your router really can't be blamed, it does just that, route traffic, it
> does'nt care what you let through it...
> Some firewalls on the other hand does'nt handle FTP well, unless PASV mode
> is used.

In the normal FTP protocol the remote host sends back a port number and
says, listen on this port for the data. That doesn't work so well with most
firewalls, so that's exactly what PASV (passive) mode is for. All
connections are handled from the client end. It's been around since the days
of the SOCKS proxy, and most FTP clients support it.

I suppose an FTP client could use UPNP to set up the router to open the
appropriate port, but it's easier to use PASV because it's already there.

-- 
Jim (for e-mail replace invalid with net)
"Remember, an amateur built the Ark; professionals built the Titanic."


Relevant Pages

  • MSN starting Remote Assistance problems.
    ... and my dad has got XP home. ... Ensuring my router allows port forwarding for 3389. ... I've even turned off the firewalls on both computers. ...
    (microsoft.public.windowsxp.messenger)
  • Re: Router recommendation needed
    ... with one Lan port and one Wan port. ... Just because a router has a firewall and/or ... SOHO router - I can easily find wireless routers, firewalls, switches, ... They make a rock-solid appliance, reliable as hell, and I ...
    (microsoft.public.windows.server.sbs)
  • Re: Port 8080
    ... It's common for firewalls to leave ... >will act as a proxy for you on this port, which can be a good thing. ... going through a proxy server but he isn't. ... the router it should still show as closed. ...
    (comp.security.firewalls)
  • Re: Syslog to a different port
    ... Anthony Fischer schrieb: ... instances of firewalls being able to send to a specific port, I haven't seen anyone doing it on a router. ...
    (comp.dcom.sys.cisco)
  • Re: [Full-disclosure] Extending JavaScript Portscanning to Include Banner Grabbing
    ... A common implementation flaw in FTP clients allows FTP servers ... to cause clients to connect to other hosts. ... "port banning" restrictions). ... I took a look at this technique this morning, ...
    (Full-Disclosure)