Great Circle Associates Firewalls
(March 1993)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Packet filtering and FTP
From: smb @ research . att . com
Date: Tue, 16 Mar 93 18:25:32 EST
To: "David I. Dalva" <dave @ TIS . COM>
Cc: firewalls @ GreatCircle . COM

	 Summary: Cisco "established" keyword breaks FTP-DATA.

	 I am having FTP trouble when I configure my Cisco to only
	 permit established TCP connections above port 1024.  When a
	 new (random) port is created for FTP-DATA (e.g., as the result
	 of a "dir"), the Cisco prohibits the connection since it
	 doesn't meet the "established" criteria.

	 Does anybody know what the port range is for randomly
	 allocated ports, or another way to get around this problem?

There is no such range.  Or rather, even though UNIX systems tend
to allocate random ports somewhere above 1024, there's no ban on
servers in that range -- witness X11.

I know of no way to do what you want in a safe fashion.  I wish I did.


Indexed By Date Previous: Re: Packet filtering and FTP
From: Brent Chapman <brent @ GreatCircle . COM>
Next: Re: Packet filtering and FTP
From: bdboyle @ maverick1 . erenj . com (Bryan D. Boyle)
Indexed By Thread Previous: Re: Packet filtering and FTP
From: Brent Chapman <brent @ GreatCircle . COM>
Next: Re: Packet filtering and FTP
From: "David I. Dalva" <dave @ TIS . COM>

Google
 
Search Internet Search www.greatcircle.com