Re: ftp passive ports and their state

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



gabrix <gabrix@xxxxxxxxxxxxx> [2006-09-28 00:12]:
> I have a debian sarge kernel 2.6 stable and proftpd as ftpd ... .My
> ftpd is open to internet users and i accept passive ftping.I have
> inserted a PassivePorts 60000 65534 directive in proftpd.conf for
> passive connections which it's still a hole of 5534 ports in my
> firewall.Could i accept connections to this ports  in a state
> ESTABLISHED,RELATED in my iptables script ?

If you haven't already, you might want to check out the ip_conntrack_ftp and ip_nat_ftp modules.  I believe they do some sort of magic with passive FTP.

Shane

-- 
Shane Hickey <shane@xxxxxxxxxxxxxxxxxxx>: Network/System Consultant
GPG KeyID: 777CBF3F
Key fingerprint: 254F B2AC 9939 C715 278C  DA95 4109 9F69 777C BF3F


[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux