Re: [Proftpd-user] iptables and passive ftp over TLS
Kai Schaetzl <[email protected]>
| Newsgroups | gmane.network.proftpd.user |
|---|---|
| Message-ID | <[email protected]> |
Matus UHLAR - fantomas wrote on Mon, 27 Aug 2018 13:15:13 +0200: > I doubt this did not happen. You are probably right, but I couldn't remember. That's why I wrote "I think." :-) > the client may issue CCC command prior to sending transfer command, which > removes the encryption, so the conntrack can see which port it's going to be > opened. Interesting. I have found that SmartFTP supports this. Filezilla has several requests for it that have been rejected because of security concerns (data not encrypted). > other possibility is to simple allow those connections exactly as you did > above. Ok, good. Thanks for your explanations! > > You can reduce nubmer of passive ports - I doubt you need 2001 ports, unless > you have very busy FTP server. You are probably right. So, approximately, this would rather be the number of average user number at a time multiplied with the concurrent connection limit (per user/ip) plus some safeguard allowance? Kai -- Get your web at Conactive Internet Services: http://www.conactive.com ------------------------------------------------------------------------------ Check out the vibrant tech community on one of the world's most engaging tech sites, Slashdot.org! http://sdm.link/slashdot _______________________________________________ ProFTPD Users List <[email protected]> Unsubscribe problems? http://www.proftpd.org/list-unsub.html