PF border firewall and internal active FTP and external PASV ftp

From: Andrew (ardiiATnoSPAMyahooDOTTcom)
Date: 06/29/04

  • Next message: Robert S. Sciuk: "Re: OpenBSD 3.5 on HP PA-RISC"
    Date: Tue, 29 Jun 2004 15:06:10 +1000
    
    

    Hi all

    I am currently configuring a new OpenBSD 3.5 box to act as a new
    border firewall. Basically, the network configuration is like this
    (forgive the terrible ascii art)

    INTERNET
    <--->
    router (valid public IP address)
    <-->
    OpenBSD firewall (valid public IP address)
    <-->
    external switch where www, mail, ftp plug into (all with valid public
    IP addresses)

    Now, I have read a tonne of pages on how to configure PF to handle ftp
    connections when masquerading but can't find any on how to configure
    it to handle ftp connections in this situation. Basically, I am using
    this line at the moment in the /etc/pf.conf file:

    pass quick proto tcp from any to $ftpservers port $ftpports keep state

    Now, that works where a client connecting to the FTP server from the
    internet uses an ACTIVE connection but fails to get a data connection
    when using a passive connection. Is there a way to configure this so
    both active and passive FTP connections work? Can I just use pf rules
    (I don't want to just randomly allow connections from port X and up to
    a server) Alternatively, do I need to configure the ftp-proxy.

    Any help would be great!

    Thanks

    Andrew


  • Next message: Robert S. Sciuk: "Re: OpenBSD 3.5 on HP PA-RISC"

    Relevant Pages

    • IPSec tools. Tips asked for selecting some toolsets
      ... I have written FTP and HTTP functionality to my apps for years, ... Now I should be able to open and handle IPSec VPN tunnels for secure ... I'll list here some keywords about those IPSec banking connections, ... *immediately* is a secure FTP connection over SSL lines. ...
      (borland.public.delphi.thirdpartytools.general)
    • Re: Linux kernel on FreeBSD
      ... Is there something I'm missing with the firewalls ... Netfilter seems to have better nat proxy support for protocols like ftp ... If you setting incomming ftp connections to an ftp server ...
      (freebsd-questions)
    • Re: As my customer says it is an odd problem - is it DST, DNS or what? (long)
      ... Some places will refuse email if they can not resolve the machine's ... to change to the Bellsouth DNS servers on their windows system ... using Windows ftp. ... connections if they can not resolve the name/IP combination from ...
      (comp.unix.sco.misc)
    • RE: FTP Window of opportunity?
      ... does it seemingly accept the connections and drop them once the response ... Subject: FTP Window of opportunity? ... blocked by the firewall. ... the FTP port shows up. ...
      (Pen-Test)
    • Re: vsftp unable to access
      ... I have tried opening up port 20 and 21 on my router and still no luck. ... from the remote site can you do an nmap to make sure the port is ... # loosens things up a bit, to make the ftp daemon more usable. ... # Make sure PORT transfer connections originate from port 20. ...
      (Ubuntu)