OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: Passive mode ftp
From: mouss (usebsdfree.fr)
Date: Mon Aug 21 2000 - 09:23:39 CDT


At 16:35 15/08/00 +0200, Graham Wheeler wrote:

>[Please note, Mike, I'm not suggesting that active FTP is better in the
>latter case - although it might be, depending on the situation - just
>that there are situations in which firewalls are deployed in which the
>only allowed traffic is incoming].

which may be stated as follows:
- passive mode is better when the FW protects clients.
- active mode is better when the FW protects servers.

but designing a new protocol would be better than both modes. ftp is simply
over-engeneered...

-
[To unsubscribe, send mail to majordomolists.gnac.net with
"unsubscribe firewalls" in the body of the message.]