Re: ftp-proxy for outgoing connection

2010-03-12 Thread Vadim Zhukov
On 12 March 2010 c. 10:42:57 Stuart Henderson wrote: On 2010/03/12 10:14, Vadim Zhukov wrote: On 12 March 2010 ?. 03:23:00 Stuart Henderson wrote: On 2010-03-11, Christopher Zimmermann madro...@zakweb.de wrote: Hi, my -current firewall is configured to block all in, block all

Re: ftp-proxy for outgoing connection

2010-03-12 Thread Stuart Henderson
On 2010-03-12, Vadim Zhukov persg...@gmail.com wrote: Hm-m. I think ftp-proxy itself should be fixed instead. What if target FTP server is not on egress? (yes, my workaround proposal was bad at that too)? Dropping on egress will be stupid because this will definitely allow more connections

Re: ftp-proxy for outgoing connection

2010-03-12 Thread Stuart Henderson
On 2010-03-12, Christopher Zimmermann madro...@zakweb.de wrote: On Fri, 12 Mar 2010 00:23:00 + (UTC) Stuart Henderson wrote: As I understand it, ftp-proxy could be used to create rules for inbound and outbound connections on 4.6. Now on -current the rdr keyword is missing from the

Re: ftp-proxy for outgoing connection

2010-03-12 Thread madro...@zakweb.de
B Stuart Henderson s...@spacehopper.org hat am 12. MC$rz 2010 um 11:46 geschrieben: On 2010-03-12, Christopher Zimmermann madro...@zakweb.de wrote: On Fri, 12 Mar 2010 00:23:00 + (UTC) Stuart Henderson wrote: As I understand it, ftp-proxy could be used to create rules for inbound

Re: ftp-proxy for outgoing connection

2010-03-12 Thread Stuart Henderson
On 2010-03-12, madro...@zakweb.de madro...@zakweb.de wrote: it seems to me that it is in fact not possible at the moment to use a ftp-client on a firewall until the current restrictio on rdr-to in pfctl will be removed. Is this true? you'll need add rules to allow the connections through

Re: ftp-proxy for outgoing connection

2010-03-12 Thread Vadim Zhukov
On 12 March 2010 c. 13:22:41 Stuart Henderson wrote: On 2010-03-12, Vadim Zhukov persg...@gmail.com wrote: Hm-m. I think ftp-proxy itself should be fixed instead. What if target FTP server is not on egress? (yes, my workaround proposal was bad at that too)? Dropping on egress will be stupid

ftp-proxy for outgoing connection

2010-03-11 Thread Christopher Zimmermann
Hi, my -current firewall is configured to block all in, block all out and allow only certain outbound connections. Now I want to allow outbound ftp connections. I read ftp-proxy(8) and http://openbsd.org/faq/pf/ftp.html#client. As I understand it, ftp-proxy could be used to create rules for

Re: ftp-proxy for outgoing connection

2010-03-11 Thread Noah Pugsley
Use 4.6, read this: http://www.openbsd.org/faq/current.html#20090901 or wait until 4.7 and read the new man page. Cheers, noah Christopher Zimmermann wrote: Hi, my -current firewall is configured to block all in, block all out and allow only certain outbound connections. Now I want to

Re: ftp-proxy for outgoing connection

2010-03-11 Thread Stuart Henderson
On 2010-03-11, Christopher Zimmermann madro...@zakweb.de wrote: Hi, my -current firewall is configured to block all in, block all out and allow only certain outbound connections. Now I want to allow outbound ftp connections. I read ftp-proxy(8) and

Re: ftp-proxy for outgoing connection

2010-03-11 Thread Vadim Zhukov
On 12 March 2010 c. 03:23:00 Stuart Henderson wrote: On 2010-03-11, Christopher Zimmermann madro...@zakweb.de wrote: Hi, my -current firewall is configured to block all in, block all out and allow only certain outbound connections. Now I want to allow outbound ftp connections. I

Re: ftp-proxy for outgoing connection

2010-03-11 Thread Christopher Zimmermann
On Fri, 12 Mar 2010 00:23:00 + (UTC) Stuart Henderson wrote: On 2010-03-11, Christopher Zimmermann madro...@zakweb.de wrote: Hi, my -current firewall is configured to block all in, block all out and allow only certain outbound connections. Now I want to allow outbound ftp

Re: ftp-proxy for outgoing connection

2010-03-11 Thread Stuart Henderson
On 2010/03/12 10:14, Vadim Zhukov wrote: On 12 March 2010 ?. 03:23:00 Stuart Henderson wrote: On 2010-03-11, Christopher Zimmermann madro...@zakweb.de wrote: Hi, my -current firewall is configured to block all in, block all out and allow only certain outbound connections. Now