Re: Security setting to prevent passive ftp?

From: Matthew Saltzman (mjs_at_ces.clemson.edu)
Date: 07/23/05

  • Next message: Gary kaplan: "Installing FC-4, problem with video"
    Date: Sat, 23 Jul 2005 10:12:52 -0400 (EDT)
    To: For users of Fedora Core releases <fedora-list@redhat.com>
    
    

    On Sat, 23 Jul 2005, Alexander Dalloz wrote:

    > Am Sa, den 23.07.2005 schrieb Jonathan August um 15:38:
    >
    >> For my users that use passive ftp, when they connect to ncftpd on my
    >> server, the connection takes a long time and eventually for them as
    >> dialup users, it times out. If I try to ftp to the machine behind my
    >> firewall and specify to use passive, as soon as I try anything that
    >> sends data (ls, put, get), the connection gets dropped. I turned off
    >> SELinux, but this didn't help. Any ideas?
    >
    >> -Jon
    >
    > modprobe ip_conntrack_ftp

    And to make it permanent, add to /etc/sysconfig/iptables-config.

    >
    > Alexander
    >
    >
    >

    -- 
     		Matthew Saltzman
    Clemson University Math Sciences
    mjs AT clemson DOT edu
    http://www.math.clemson.edu/~mjs
    -- 
    fedora-list mailing list
    fedora-list@redhat.com
    To unsubscribe: http://www.redhat.com/mailman/listinfo/fedora-list
    

  • Next message: Gary kaplan: "Installing FC-4, problem with video"

    Relevant Pages

    • Passive FTP
      ... His passive ftp work on non-standart port ... Here log of connection. ... 234 AUTH TLS successful ... Data Socket Error: Connection refused ...
      (microsoft.public.isa)
    • Re: vsftpd slow because of iptables firewall
      ... On Sat, 2004-08-07 at 17:58, Alexander Dalloz wrote: ... > fully close paths for network packets. ... So at all running netfilter code means CPU work and if ... For instance if a connection was properly established, ...
      (Fedora)
    • Re: instant messaging
      ... On Fri, 2004-04-23 at 13:52, Alexander Dalloz wrote: ... many standard firewall rules. ... I know that a proxy connection may help. ...
      (Fedora)
    • Re: Error when FTPing
      ... >firewall s/w hence why we upgraded. ... >connection they can't connect they get connection failure. ... well can they get *any* kind of passive FTP connection working to ... Internet Explorer? ...
      (microsoft.public.inetserver.iis.ftp)
    • RE: NAT firewalls possibly insecure by nature?
      ... That's not my understanding of passive ftp. ... there are mechanisms to send information back along that connection. ... case in point is passive ftp, which opens a connection, and then requests ... NAT firewalls possibly insecure by nature? ...
      (Focus-Microsoft)