[prev in list] [next in list] [prev in thread] [next in thread] 

List:       netfilter
Subject:    Re: FTP connection tracking doesn't work with nftables
From:       Tomek L <tl-netfilter () gazeta ! pl>
Date:       2015-05-18 5:58:54
Message-ID: CANfWn6Vtio5yQb8h1aEyj1dsO8+Z9o4vUERoHSV6447RA5OmmA () mail ! gmail ! com
[Download RAW message or body]

I would say it is better to have high ports open on demand (after AUTH
TLS) than have them open all the time. NFTables are now useless to me,
as their FTP/TLS passive mode is not supported neither by helper or by
"recent" extension.

2015-05-17 22:59 GMT+02:00 Pascal Hambourg <pascal@plouf.fr.eu.org>:
> Tomek L a écrit :
>> I agree on source port issue, but I don't think that in case of TLS
>> there is nothing that can be done with FTP helper. Still we can assume
>> that just after TLS AUTH negotiation, client will connect on high port
>> with new connection to server. Now we are in situation, where if TLS
>> is used, high ports on server side must be open all the time.
>
> IMO, it is not much better to open all passive ports to any host which
> has established a connection to port 21 regardless of whether a
> PASV/EPSV command was acknowledged by the server.
--
To unsubscribe from this list: send the line "unsubscribe netfilter" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic