Re: [opensuse] proftp passive mode, on which port?



On 06/21/2007 02:59 AM, Fajar Priyanto wrote:
On Thursday 21 June 2007 15:30, Hans Linux wrote:

i always have bad experience with my proftp server. i have it running
but i can't transfr any data. Everytime it always stuck at "Entering
passive mode" for a long time and then timeout. But if I disable the
firewall, it works well. So which port of firewall should i open? I do
some googling and find out port 30000-30050 or 60000-65535, but it
didn't work.


Hello Hans,
It's not your proftp's fault.
In passive mode, the ftp client will connect to the ftp server on tcp 21, then
for data transfer it will open random high ports. In order to do this your
kernel must have ip_conntrack_ftp module loaded, so that it can 'track' the
connection for ftp.

I believe you can set it in your firewall to load the needed module.
HTH,

Congratulations on the only correct answer so far :-)

As for loading ip_conntrack_ftp, that is done in the SuSEfirewall2
script, so the OP must be using some other firewall.

--
Hypocrisy is the homage vice pays to virtue. -- François de La Rochefoucauld

--
To unsubscribe, e-mail: opensuse+unsubscribe@xxxxxxxxxxxx
For additional commands, e-mail: opensuse+help@xxxxxxxxxxxx



Relevant Pages

  • Re: FTP server behind a PF firewall (including NAT)
    ... > Thank you, but I have a working PF configuration for FTP clients, both ... > for active and passive mode. ... > this firewall) that allows both active mode and passive mode clients. ... > Active-mode transfers are the easiest (again, allow connections to all ...
    (comp.unix.bsd.freebsd.misc)
  • Re: Passive Mode issue
    ... in the windows firewall and the network firewall with the same results. ... and the ftp site is bound to a specific public IP. ... The server will timeout from all users trying passive mode. ... passive port range for IIS and opened those ports in the firewall, ...
    (microsoft.public.inetserver.iis.ftp)
  • FC3: no route to host with enabled firewall
    ... i've problem with my firewall. ... of my outgoing connections are filtered. ... ftp> ls ... 227 Entering Passive Mode ...
    (Fedora)
  • Re: outgoing firewall rules
    ... for ftp you need inbound 21 and outbound 20 (active mode) ... in passive mode, you need a lot more, google 'passiveportrange' ... > original provider's firewall allowed all outgoing traffic for the servers. ...
    (microsoft.public.inetserver.iis)
  • Re: Mac client ftp open data connection errors
    ... I've determined the Mac firewall is what's preventing this from ... working since when I turn it off or enable the FTP Server/Service on the Mac ... it is a combination of the passive mode and the firewall. ...
    (microsoft.public.windows.server.sbs)