Re: ftp-proxy and active passive

Togan Muftuoglu <[email protected]> Wed, 24 Mar 2004 16:32:55 +0100
Newsgroups gmane.linux.suse.proxy-suite
Message-ID <[email protected]>
* Dirk Roloff; <[email protected]> on 24 Mar, 2004 wrote:
>
>right you have to open the ports for outgoing.
>in active mode you had to open the > 1023 for incomming. belive me - you dont want this.
>So your firewall will pass all incomming connections. This is a big hole in your security.
>

You can define the port range for both active and passive connections so
you only allow these ranges for your ftp services 

#
# The following entries select a port range for client DTP
# ports in passive mode, i.e. when the client sends a PASV.
# If no port range is given, no bind is performed, in which
# case the proxy lets the machine select an ephemeral port.
#
# PassiveMinDataPort    41000
# PassiveMaxDataPort    41999


Maybe this could help

-- 

Togan Muftuoglu			     |   	
Unofficial SuSE FAQ Maintainer	     |	Please reply to the list;
http://susefaq.sf.net		     |	Please don't put me in TO/CC.

		Nisi defectum, haud refiecendum

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]