Great Circle Associates Firewalls
(December 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: ftp & PASV
From: dreschs @ mpd . tandem . com (Sten Drescher)
Organization: Tandem Computers
Date: 08 Dec 1995 11:14:38 -0600
To: <firewalls @ GreatCircle . COM>
In-reply-to: root's message of Fri, 8 Dec 1995 00:04:24 -0500 (EST)
References: <Pine . LNX . 3 . 91 . 951208000127 . 212A-100000 @ deimos>

root <deimos!root @
 uunet .
 uu .
 net> said:

r> The PASV is *not* required if the ftp client is properly socksified.
r> I had to fidget with both the one included with SSLeay (which worked,
r> but I had to pick a port (instead of using 0 to let the system pick
r> it), and make sure SHORTENED_RBIND was off since it was so in our
r> server.

	So the ftp client that comes with socks isn't properly
socksified?  If you meant that you don't have to MANUALLY issue the PASV
I'll agree, but otherwise I'd like to know how you get incoming tcp
connections through your filewall.

-- 
#include <disclaimer.h>				/* Sten Drescher */
To get my PGP public key, send me email with your public key and
	Subject: PGP key exchange
Key fingerprint =  90 5F 1D FD A6 7C 84 5E  A9 D3 90 16 B2 44 C4 F3


References:
Indexed By Date Previous: Re: Orange Book Irrelevant (was: A1 Systems?)
From: "KM" <goertzek @ gateway . wangfed . com>
Next: Re: Mathematical Proof of RSA Encryption
From: Leonard Miyata <leonard @ geminisecure . com>
Indexed By Thread Previous: Re: ftp & PASV
From: root <root @ deimos>
Next: NT Security and NTFS (fwd)
From: spencerj @ dg-rtp . dg . com (Jon Spencer)

Google
 
Search Internet Search www.greatcircle.com