TCLUG Archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [TCLUG:9710] ip_masq_ftp



Use passive mode.

Tom Veldhouse
veldy@visi.com

----- Original Message -----
From: Jon Schewe <jpschewe@eggplant.mtu.net>
To: <tclug-list@mn-linux.org>
Sent: Tuesday, November 02, 1999 8:02 PM
Subject: Re: [TCLUG:9710] ip_masq_ftp


> On Tue, 2 Nov 1999, Amy Tebbe wrote:
>
> > Have an ipchains firewall doing masquerading.  ws_ftp on a windows
client gets
> > 500 Illegal Port error when connecting to an ftp site.  ftp on the
firewall
> > itself works fine.  ncftp works when passive is off.  when passive is
on,
> > i see deny packets on the firewall that look like:
>
> I have this problem when ftping to certain sites.  It happens when the
> site does a back check to where you're coming from.  If you're firewall is
> dropping inetd requests, which you firewall probably is, then the ftp
> server won't let you connect.  The same thing happens to me at work.  I
> have yet to find a way to get around this except to ftp from a machine
> outside the firewall or possible ftp from teh firewall machine itself.
>
> --
> Jon Schewe
> http://eggplant.mtu.net/~jpschewe
> schewe@tcfreenet.org
>
>
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: tclug-list-unsubscribe@mn-linux.org
> For additional commands, e-mail: tclug-list-help@mn-linux.org
>