Re: active ftp through firewall

From: Barry Margolin (barmar_at_alum.mit.edu)
Date: 05/20/04


Date: Thu, 20 May 2004 12:09:25 -0400

In article <1085036311.748582@ente.ipberlin.com>,
 jpd <read_the_sig@do.not.spam.it> wrote:

> ["Followup-To:" header set to comp.security.unix.]
> On 2004-05-20, Barry Margolin <barmar@alum.mit.edu> wrote:
> > Firewalls are supposed to watch the traffic on the FTP command channel,
> > and notice when a PORT command goes through so that they can open up
> > that port for an inbound connection from the FTP server.
>
> And why do you suppose them to do so?

Because it's important to support a heavily-used Internet application
protocol.

> A simple port blocking firewall
> does no such thing.

That makes them poor firewalls.

There are many who don't even like to use the term "firewall" when
referring to simple, stateless port filters like this. I'm not so
pedantic, but this is the type of difference that can be important.

-- 
Barry Margolin, barmar@alum.mit.edu
Arlington, MA
*** PLEASE post questions in newsgroups, not directly to me ***


Relevant Pages

  • Re: active ftp through firewall
    ... > Firewalls are supposed to watch the traffic on the FTP command channel, ... > that port for an inbound connection from the FTP server. ... Some firewalls (``application level'' I have in my ...
    (comp.security.misc)
  • Re: active ftp through firewall
    ... > Firewalls are supposed to watch the traffic on the FTP command channel, ... > that port for an inbound connection from the FTP server. ... Some firewalls (``application level'' I have in my ...
    (comp.security.unix)
  • Re: PLINK and/or PuTTY -- Logon to Linux with no Privileges
    ... There are firewalls that can detect this sort of thing, ... We've tried just regular VNC, with no luck, then tried it on port 80, ... were easily broken out of because, well, they're shell scripts! ...
    (comp.security.ssh)
  • Re: How to Stealth POP3 Port 110 using NIS2000?
    ... > What do you want to protect by 'stealth-ports'? ... > stealthed port protects your privacy, 'cause I really don't get it. ... I can't answer that as I am no expert on firewalls. ...
    (comp.security.firewalls)
  • Re: How to Stealth POP3 Port 110 using NIS2000?
    ... >> how a stealthed port protects your privacy, 'cause I really don't get it. ... > I can't answer that as I am no expert on firewalls. ... The only thing you risk when not stealthing port 110 is for people to find ...
    (comp.security.firewalls)