TIP: Click on subject to list as thread! ANSI
echo: elebbs_support
to: All
from: Ioram Schechtman Sette
date: 2006-12-05 08:36:30
subject: RES: EleBBS: EleServ/FTP: PASV mode

* EleBBS Support List

Scott,

>> Doesn't the problem then show up on the server side if you're behind an
>>NAT?

> Active requires an open client and passive requires an open server.

> Intelligent NAT will be able to figure out which ports to open either
> way, so it depends on whether a static firewall is in use.

I think normally firewalls are configured to allow people connecting
outside, but blocks incoming requests. This behavior makes ftp server can't
establish connections to the client.

I think using PASV, when always the connections go from client to server, it
doesn't happen... I'm not an expert in FTP protocol, so maybe I'm mistaken.

I suggest D.J.Bernstein article about FTP security:
http://cr.yp.to/ftp/security.html 
He writes about the weakness of the too modes.
He doesn't recommend ftp at all, but I think he prefers PASV with his frase:
"I recommend against all use of PORT."

I'm trying to use ftp behind ssl.
It works fine when testing at home (without firewalls), but at work, I can't
establish data connections. I think PASV shall solve this issue.

Regards,
Ioram Sette


_______________________________________________________________


--- Internet Rex 2.29
* Origin: The gateway at The Snake (2:280/4312.101)
SEEN-BY: 633/267 270
@PATH: 280/4312 774/605 123/500 379/1 633/267

SOURCE: echomail via fidonet.ozzmosis.com

Email questions or comments to sysop@ipingthereforeiam.com
All parts of this website painstakingly hand-crafted in the U.S.A.!
IPTIA BBS/MUD/Terminal/Game Server List, © 2025 IPTIA Consulting™.