Re: dynamic ftp rule
[email protected] (Sandwich Maker) Wed, 10 Aug 2011 13:12:14 -0400 (EDT)
| Newsgroups | gmane.comp.security.firewalls.ipfilter |
|---|---|
| Message-ID | <14671_1312996455_4E42BC66_14671_12786_1_201108101712.p7AHCEZ26409@an.bradford.ma.us> |
" Date: Sat, 06 Aug 2011 01:17:15 +0100 " From: Darren Reed <[email protected]> " " On 5/08/2011 7:29 PM, Sandwich Maker wrote: " > solaris 8, ipf 3.4.35. " > " > is it possible to construct a rule which allows incoming port 20 " > [ftp-data] -only- when an outgoing port 21 [ftp] connection is active? " > anyone have an example? " " You have to use the NAT proxy. " " .e.g. " " map bge0 0/0 -> 0/32 proxy port ftp ftp/tcp big surprise - worked like a champ. thanks darren! ________________________________________________________________________ Andrew Hay the genius nature internet rambler is to see what all have seen [email protected] and think what none thought