Re: active ftp through firewall

phn_at_icke-reklam.ipsec.nu
Date: 05/20/04


Date: Thu, 20 May 2004 16:54:34 +0000 (UTC)

In comp.security.misc jpd <read_the_sig@do.not.spam.it> wrote:
> ["Followup-To:" header set to comp.security.unix.]
> On 2004-05-20, Barry Margolin <barmar@alum.mit.edu> wrote:
>> Firewalls are supposed to watch the traffic on the FTP command channel,
>> and notice when a PORT command goes through so that they can open up
>> that port for an inbound connection from the FTP server.

> And why do you suppose them to do so? A simple port blocking firewall
> does no such thing. Some firewalls (``application level'' I have in my
> head, but I might be wrong) can indeed do that, but it's by no means
> standard for everything that might be called a firewall.

Firewalls comes in many flavors. From the (too)simple ones who
can't keep state and/or do ftp up to "real ones".

I think the simple d-link 604 can do ftp, and that must be defined
as "entry-level". So any "firewall" that don't do ftp seems outdated.

> --
> j p d (at) d s b (dot) t u d e l f t (dot) n l .

-- 
Peter Håkanson         
        IPSec  Sverige      ( At Gothenburg Riverside )
           Sorry about my e-mail address, but i'm trying to keep spam out,
	   remove "icke-reklam" if you feel for mailing me. Thanx.


Relevant Pages

  • Re: Linux kernel on FreeBSD
    ... Is there something I'm missing with the firewalls ... Netfilter seems to have better nat proxy support for protocols like ftp ... If you setting incomming ftp connections to an ftp server ...
    (freebsd-questions)
  • FTP [partially] explained (was Re: Cant obtain 4.11 ?)
    ... >> I am not really up on active vs. passive FTP. ... > or to have the server initiate a separate data connection. ... > latter often breaks on firewalls that don't explicitly support ftp. ... the FTP server accepts a PORT ...
    (comp.unix.bsd.freebsd.misc)
  • Re: Ive been hacked, found mldonkey running
    ... General Schvantzkoph writes: ... ]>> Does anyone know if Linksys routers are adequate firewalls? ... I had the FTP ... ]>> as the internet port. ...
    (comp.os.linux.security)
  • Re: FTP
    ... For troubleshooting purposes I am trying to connect to an FTP ... site using the windows command line. ... Assuming you don't have any firewalls on your computer except Windows Firewall, try going to the Windows Firewall control panel and make sure that on the "exceptions" tab, there are exceptions enabled for ports 20 and 21. ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: For Lance
    ... Port 21 isn't the only one that's used for FTP. ... I suggest temprarily dropping firewalls on your LAN and try FTP'ing back and forth using just your LAN computers. ... Once you get FTP working without firewalls, raise the firewalls, make firewall exceptions and troubleshoot it again. ...
    (microsoft.public.inetserver.iis.ftp)