Re: Passive and Active ftp mode

Marius Tomaschewski <[email protected]> Tue, 13 Aug 2002 11:29:02 +0200
Newsgroups gmane.linux.suse.proxy-suite
Organization SuSE Labs, Product Developement
Message-ID <[email protected]>
On Mon, Aug 12, 2002 at 03:26:48PM -0400, Ruiyuan Jiang wrote:
> Yes, Marius

Hi!

> The client is in the corporate internal network and proxy server is in the
> DMZ zone. In this case, I don't use NAT between ftp client and proxy server.

OK.

> I guess from proxy server to ftp server connection may do NAT which on ftp
> server side it shows proxy server IP address incoming, right, Marius?

As I see on your previous mails, your proxy machine has an official IP,
so you may use NAT or not. This depends on configuration.
But the server side seems to work...

> What is netcat? I don't see it on my Solaris and HP-UX boxes.

This is a generic TCP/UDP tool, you can listen with:

http://www.atstake.com/research/tools/index.html#network_utilities

There are more tools like netcat, i.e. sock. You can use them
i.e. to bind on a port and test if you can connect it from the
other host...

> Is it snope on Solaris or nettl on HP-UX?

I don't know them.

> Does proxy server need to initiate connection to ftp client also?

No. It was for testing only. I wanted to see if a firewall
filter blocks it or there is NAT used...

> My setup is that ftp client initiate connection to ftp proxy server
> and ftp proxy serve can't initiate connection to ftp client which
> is blocked by firewall.
  ^^^^^^^^^^^^^^^^^^^^^^
> I just made it worked followed your suggestion. Thanks.

OK.
The filter rules on your firewall are fixed and it works now?

Kind regards,
 Marius Tomaschewski <[email protected]>
--
 SuSE Linux AG, NÃŒrnberg - SuSE Labs, Product Developement
 PGP public key available:   http://www.suse.de/~mt/mt.pgp
 Fprint:  EA 1F 92 75 1A F9 82 07  A1 28 DE 7A 32 E8 97 18

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]