[Fwd: Re: [LARTC] DNAT rule for vsftp (PASSIVE FTP)]

2007-10-05 Thread Mohan Sundaram
Grant Taylor wrote: I'll have to double check some things to make sure that you don't need to do any thing special other than just allow the initial connection and rely on the FTP connection tracking helper to handle all other connections. I've never run an FTP server behind a NAT, but I've n

[Fwd: Re: [LARTC] DNAT rule for vsftp (PASSIVE FTP)]

2007-10-05 Thread Mohan Sundaram
Original Message Subject: Re: [LARTC] DNAT rule for vsftp (PASSIVE FTP) Date: Fri, 05 Oct 2007 12:17:42 +0530 From: Mohan Sundaram <[EMAIL PROTECTED]> Reply-To: [EMAIL PROTECTED] To: Indunil Jayasooriya <[EMAIL PROTECTED]> References: <[EMAIL PROTECTED]> I

Re: [LARTC] DNAT rule for vsftp (PASSIVE FTP)

2007-10-05 Thread Grant Taylor
On 10/05/07 02:16, Indunil Jayasooriya wrote: What is FTP helper module? As I understand it, the Connection Tracking FTP helper module is essentially a small module / algorithm that you load in to the Connecting Tracking structure (via the below modules) to watch what ftp commands you send o

Re: [LARTC] DNAT rule for vsftp (PASSIVE FTP)

2007-10-05 Thread Indunil Jayasooriya
On 10/5/07, Grant Taylor <[EMAIL PROTECTED]> wrote: > > On 10/5/2007 12:51 AM, Indunil Jayasooriya wrote: > > I want to run vsftp behind a firewall.(i.e DMZ zone) . It is runnig as > > passive ftp. > > Ok... > > > Then, How can I write DNAT rules. > > You don't want to write rules for each possible

Re: [LARTC] DNAT rule for vsftp (PASSIVE FTP)

2007-10-04 Thread Grant Taylor
On 10/5/2007 12:51 AM, Indunil Jayasooriya wrote: I want to run vsftp behind a firewall.(i.e DMZ zone) . It is runnig as passive ftp. Ok... Then, How can I write DNAT rules. You don't want to write rules for each possible combination. YOUR comments. Use the FTP helper module as it is me