OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: (no subject)
From: firewallsnode.genxnet.com
Date: Wed Nov 29 2000 - 07:07:55 CST


Apologies for the oddball quoting, but I seem to have deleted the original
post by mistake.

At 21:34 28/11/00 +0000, Andreas Horvath wrote:

>should i have to install a ftp proxy application or is there any other
>way to open up the fw to accept only ftp data connections?
>we're using linux kernel 2.2.14 w/ ipchains and masquerading

You need to insert (possibly even build) the ip_masq_ftp module if I
recall correctly(1). From there, you will need to allow connections to
your firewall on ports 1025-4999(2) from the ftp-data port, 20.

1) Its been awhile since I've setup a linux firewall, please take all
advice with a tablespoon of salt.
2) This are the 'standard' ports, but thats the great thing about
standards. So many to choose from.

johnny

"They called me mad, and I called them mad, and damn them, they outvoted me."
                        -- Nathaniel Lee, on being consigned to a mental
                           institution, circa 17th century.

-
[To unsubscribe, send mail to majordomolists.gnac.net with
"unsubscribe firewalls" in the body of the message.]