Re: [Proftpd-user] iptables and passive ftp over TLS

Kai Schaetzl <[email protected]>
Newsgroups gmane.network.proftpd.user
Message-ID <[email protected]>
Matus UHLAR - fantomas wrote on Mon, 27 Aug 2018 13:15:13 +0200:

> I doubt this did not happen.

You are probably right, but I couldn't remember. 
That's why I wrote "I think." :-)

> the client may issue CCC command prior to sending transfer command, which
> removes the encryption, so the conntrack can see which port it's going to be
> opened.

Interesting. I have found that SmartFTP supports this. Filezilla has several 
requests for it that have been rejected because of security concerns (data not 
encrypted).

> other possibility is to simple allow those connections exactly as you did
> above.

Ok, good. Thanks for your explanations!

> 
> You can reduce nubmer of passive ports - I doubt you need 2001 ports, unless
> you have very busy FTP server.

You are probably right. So, approximately, this would rather be the number of 
average user number at a time multiplied with the concurrent connection limit 
(per user/ip) plus some safeguard allowance?

Kai

-- 
Get your web at Conactive Internet Services: http://www.conactive.com




------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot
_______________________________________________
ProFTPD Users List   <[email protected]>
Unsubscribe problems?
http://www.proftpd.org/list-unsub.html
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.