It is currently Sun, 26 May 2013 08:54:19 GMT



 
Author Message
 Active FTP under iptables to ftp.netscape.com
I am running iptables with SNAT under Redhat 7.1 with 2.4.3 smp kernel.

I have successfully installed ip_conntrack, ip_conntrack_ftp and
ip_nat_ftp. I can connect from internal machines to active FTP sites.

I know it's working because I used a protocol analyzer and saw the
connections back to my local machines from source port 20. I connected
specifically to ftp.cs.utah.edu and ftp.microsoft.com both using 2-port
active ftp.

The weirdest thing it that active ftp doesn't work from
ftp.netscape.com. For some reason the conntrack module just doesn't
realize that it should track it if it's there. My guess is that it's
something with the particular server Netscape is running.

I know that ftp.netscape.com supports active ftp because I can connect
with active ftp from my server machine to it with the firewall down.

Does anyone know why this happens? Would someone else please try
connecting to ftp.netscape.com and confirm my findings?

-John

On a side note, does anyone know of a nice way to view the output of
tcpdump in Linux? Something that splits it up into frame, ip, tcp and
application and shows the fields in a more human-readable way?



 Sat, 20 Mar 2004 04:16:26 GMT   
 Active FTP under iptables to ftp.netscape.com

I'm seeing the same behavior. I ran ethereal on my linux firewall and
discovered that for some reason the ftp-data session back to my firewall is
being opened from another IP address than that of the outbound...
ftp.netscape.com IP address. Obviously, this type of nonsense will fail.

Try ethereal. www.ethereal.com

Steve Cowles



 Sat, 20 Mar 2004 09:37:28 GMT   
 
   [ 2 post ] 

Similar Threads

1. problem with active ftp and iptables

2. Active FTP/IPTables

3. FTP active mode and iptables

4. netscape 4.73, ftp.netscape.com is empty dir

5. FTP Undefined error 0 during install over active ftp

6. pf and ftp-proxy rules for active ftp connections

7. Redhat 6.1 mirror ftp://ftp.linuxnirvana.com

8. Does ftp.freebsd.com support passive FTP?

9. AHS directory on ftp.sco.com, Re: SCO FTP Sites

10. Linuxppc.com ftp site & Mac FTP programs


 
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group.
Designed by ST Software