Re: ftp-proxy and active passive
Togan Muftuoglu <[email protected]> Wed, 24 Mar 2004 16:32:55 +0100
| Newsgroups | gmane.linux.suse.proxy-suite |
|---|---|
| Message-ID | <[email protected]> |
* Dirk Roloff; <[email protected]> on 24 Mar, 2004 wrote: > >right you have to open the ports for outgoing. >in active mode you had to open the > 1023 for incomming. belive me - you dont want this. >So your firewall will pass all incomming connections. This is a big hole in your security. > You can define the port range for both active and passive connections so you only allow these ranges for your ftp services # # The following entries select a port range for client DTP # ports in passive mode, i.e. when the client sends a PASV. # If no port range is given, no bind is performed, in which # case the proxy lets the machine select an ephemeral port. # # PassiveMinDataPort 41000 # PassiveMaxDataPort 41999 Maybe this could help -- Togan Muftuoglu | Unofficial SuSE FAQ Maintainer | Please reply to the list; http://susefaq.sf.net | Please don't put me in TO/CC. Nisi defectum, haud refiecendum --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]