Re: Why does passive FTP work behind router/firewall?

From: Don Kelloway (dkelloway_at_commodon.com)
Date: 02/27/04


Date: Fri, 27 Feb 2004 07:14:23 GMT


"Don Kelloway" <dkelloway@commodon.com> wrote in message
news:A5C%b.22445$W74.16140@newsread1.news.atl.earthlink.net...
>
> To offer an even better explanation. Please let me refer you to the
> following article I wrote about six years ago. I think it may be of
> some assistance in understanding the intricacies with PASV FTP and
> firewalls. The article is entitled "The difference between PASV FTP
and
> Normal FTP" and is available from:
>
> http://war.jgaa.com/ftp/?cmd=show_page&ID=ftp_pasv
>
>

Note the article refers to a time when PASV FTP would fail with NAT
enabled firewalls. Since that time most if not all Firewalls offering
NAT have become 'protocol aware' and are smart enough to rewrite the
contents of the packets as they are being passed through the connection.

--
Best regards,
Don Kelloway
Commodon Communications
Visit http://www.commodon.com to learn about the "Threats to Your
Security on the Internet".