[thelist] FTP, IP Filtering, and Firewalls

Joshua Olson joshua at waetech.com
Fri May 28 08:20:45 CDT 2004


List,

I'm configuration FTP on a server and I want to maximally lock down the
ports.  I opened the normal ports for FTP, 20 and 21, and found that this
works very well so long as the client is not behind a firewall and was
therefore able to use Active Mode FTP transfer.  But, if they are behind a
firewall, am I correct in assuming that they MUST be able to use Passive
Mode, which means that the server needs to have some ports open in the upper
range?  If so, is there an easy way to configure the open ports using the IP
Filtering OTHER than enumerate each possible port one at a time?

Thanks in advance.

<tip type="thelist" author="Joshua Olson">
When you want to start a new thread do not simply respond to an existing
message.  Instead, start a brand new message and send it to
thelist at lists.evolt.org.

If you respond to a message, then some mail clients--which may be set up to
display threads as nested trees--may inadvertently put your new thread in
with the thread you hijacked instead of starting a new tree.  They can do
this even if you change the title because some mail clients can track
threads using the mail headers for Message ID, In-Reply-To, and
References--all of which are generally hidden from the user.
</tip>

<><><><><><><><><><>
Joshua Olson
Web Application Engineer
WAE Tech Inc.
http://www.waetech.com/service_areas/
706.210.0168




More information about the thelist mailing list