Re: [opensuse] proftp passive mode, on which port?



On Thursday 21 June 2007 15:30, Hans Linux wrote:
i always have bad experience with my proftp server. i have it running
but i can't transfr any data. Everytime it always stuck at "Entering
passive mode" for a long time and then timeout. But if I disable the
firewall, it works well. So which port of firewall should i open? I do
some googling and find out port 30000-30050 or 60000-65535, but it
didn't work.

Hello Hans,
It's not your proftp's fault.
In passive mode, the ftp client will connect to the ftp server on tcp 21, then
for data transfer it will open random high ports. In order to do this your
kernel must have ip_conntrack_ftp module loaded, so that it can 'track' the
connection for ftp.

I believe you can set it in your firewall to load the needed module.
HTH,
--
Fajar Priyanto | Reg'd Linux User #327841 | Linux tutorial
http://linux2.arinet.org
3:58pm up 8:50, 2.6.18.2-34-default GNU/Linux
Let's use OpenOffice. http://www.openoffice.org

Attachment: pgpNlRUguMmSz.pgp
Description: PGP signature



Relevant Pages

  • Re: Passive means what during FTP?
    ... :227 Entering Passive Mode ... :ftp: connect: No route to host ... The FTP data transfer uses a connection that is separate from the ... address and port number to connect to for the data transfer. ...
    (comp.os.linux.setup)
  • Re: vsftpd working but not with Internet Explorer
    ... My guess is that IE is using passive mode by default. ... In passive mode Firewalls in front of the ftp server (or on the ftp ... In passive mode the server actually finds a free port (by default from ...
    (alt.os.linux)
  • Re: VSFTP in passive mode
    ... When I FTP into the site I get connected but when I ... If I exit passive mode by entering "pass" the directory comes across. ... with them having to accept incoming connections ... originating from port 20 of the FTP server they're connecting to. ...
    (alt.os.linux.redhat)
  • Re: FTP Gurus Help!!
    ... > I'm using G6 FTP server to hosts my FTP site. ... your ftp serverin active mode - using M$ ftp client - ... PORT command). ... Passive mode ftp behaves more conventionally, ...
    (comp.security.firewalls)
  • Re: Iptables FTP question
    ... for secondary connections. ... Some ftp servers don't allow passive mode because it is less safe from ... algs that allow port mode for client machines. ...
    (comp.security.firewalls)