Re: Linux Passive FTP Configuration



Fountain_spray a écrit :

2. So Linux IP filtering is effectively "AND'ed" with the network
firewall?

Obviously. How could it be otherwise ? If either filter drops a packet, that packet won't get through regarless the other filter accepted or would have accepted it.

3. I am now reading man iptables. We also have man ipchains.
Reading both. I would rather these did not exist,
it complicates the task of enabling passive FTP immensely.

iptables and ipchains being present does not mean that they are active.
iptables-save will tell if iptables is active. I do not remember about ipchains (too old).

4. How can I tell what RH kernel I have?

uname -a

5. I have not been able to get our Network Firewall Administrator to
do a sniffer trace on one server, let alone two.
I shall ask him to trace both Server A and Server B simultaneously.

I meant tnat you can do it yourself If you have root access on both servers - I guess this is required in order to setup proftpd. You do not need the firewall administrator.

6. Yes, I did restart proftpd on both Server A and Server B, and
still the PassivePort range is not used. Why?

I have no clue. Is the firewall doing NAT (address translation) ?

I defined the same PassivePort range on both servers. Bad idea?

It does not matter.
.



Relevant Pages

  • Re: UDP Port 1025 activity
    ... IP address that I tracert back to my ISP's cached DNS server (at ... is a normal problem - the remote DNS server was slower than your firewall ... outbound packet that would produce a reply. ... If the blocked packet is messenger spam, ...
    (comp.security.firewalls)
  • Re: ISA 2004 Error 14060
    ... If that script solves your problem, you'll want to reinstall ISA via Add/Remove Programs and choose "repair" when prompted. ... That seems like a problem with your DNS filter. ... After disabling the DNS filter this way, reboot your server and see if you ... > stop and restart the Firewall service. ...
    (microsoft.public.isaserver)
  • Re: Has my fedora 18 installation been hacked?
    ... I have found two php files in the tmp folder of one web site, ... Thus, I have shutdown the web server, and monitor the server for a few days, to see if these firewall complains persist. ... It would be good if you could ask your ISP for a packet capture which you could analyze off line. ...
    (Fedora)
  • Re: Limit the number of erroneous logins of root from the same IP
    ... Let's do a quick check of what happens to an IP connection attempt to ... Without a firewall in the way, the packet goes up ... server on this port and an IP ...
    (alt.os.linux.redhat)
  • How can we make a multihomed server replying on the same interface
    ... I have some linux hosts behind a masquerading firewall. ... and use YP from a multihomed Server. ... The Server answers with an UDP packet. ...
    (SunManagers)