On 29 Apr 99, at 21:51, Chris Faherty wrote about
"RE: [Masq] Cant build data connect":
| On 30-Apr-99 Barton, James wrote:
|
| > I have an internal Masq ftp server that users from the internet need to
| > access. They can log in, but they can't get a listing of files. I get the
| > error "Can't build data connection".
|...
| > According to the IPMASQ-HOWTO-1.71 section 6.8 it may not be possible.
| > "NOTE: At this time, it is beleived that this modified IP_MASQ_FTP module
| > for port forwarded FTP connections will NOT work for the 2.2.x kernels.
|
| The purpose of the ip_masq_ftp module is to snoop on the control connection
| and rewrite the PORT command. This is only active during outgoing
| connections; i.e. masqueraded clients. It wouldn't be active during your
| situation because it is specifically monitoring connections going out to a
| destination port of 21.
The part of the IPMASQ-HOWTO James was refering to provides a kernel
patch and updated ip_masq_ftp module, which makes FTP support
completely orthogonal (doesn't matter whether it's the server or
client that's masqed). It appears to work fine, but is applicable
only to the 2.0.3x kernels.
To answer James' question, yes. Someone has taken a whack at porting
these changes to the 2.2.x kernel. The kernel patch required is even
smaller (although a bigger one might be desirable), the bigger task
was merging the ip_masq_ftp.c re-write.
Dave Meythaler <[EMAIL PROTECTED]> did the work, and reported
success with his initial testing. He sent me a copy of his
ip_masq_ftp.c module, but I haven't had a chance to check it out yet.
Dave and I CC'ed David Ranch on all the emails related to this, but I
don't know if DR has taken it any further. There is an obvious
desire to get this added to the official kernel.
|...
- Fred Viles <mailto:[EMAIL PROTECTED]>
_______________________________________________
Masq maillist - [EMAIL PROTECTED]
http://tiffany.indyramp.com/mailman/listinfo/masq
Admin requests can be handled by web (above) or [EMAIL PROTECTED]