Damn. I was hoping it was a solution to the passive mode problem. I'm tempted to just write a packet sniffer that listens for all passive requests and responses and creates a dynamic allow rule for the port and IP. I don't really need it since I run a couple of PIX 515's, but someone else could surely use it.
--Blaine At 02:18 PM 10/14/2002, you wrote: >No. I thought you were asking how to use IPSEC policies to do port filtering. > >Jim > > >----- Original Message ----- >From: "Blaine Fleming" <[EMAIL PROTECTED]> >To: <[EMAIL PROTECTED]> >Sent: Monday, October 14, 2002 2:07 PM >Subject: [isp-security] Re: Port Filtering for FTP Server > > > > What I don't see in this is how to allow passive mode ftp. The policy set > > listed below will allow active mode transfers. Am I just missing it? > > > > --Blaine > > >____________ The ISP-SECURITY Discussion List ____________ >To Join: mailto:[EMAIL PROTECTED] >To Remove: mailto:[EMAIL PROTECTED] >Archives: http://isp-lists.isp-planet.com/isp-security/archives/ >To Remove: mailto:%%email.unsub%% ____________ The ISP-SECURITY Discussion List ____________ To Join: mailto:[EMAIL PROTECTED] To Remove: mailto:[EMAIL PROTECTED] Archives: http://isp-lists.isp-planet.com/isp-security/archives/ To Remove: mailto:[EMAIL PROTECTED]
