Title: FTP through FW-1 with NAT
To where are you allowing your ident rule?  Apparently this
ftp site requires ident for identification and logging purposes,
but you must have an ident server running to answer queries.
 
Hal

Hal Dorsman
Data Network Engineer
Blackfoot Telephone Cooperative
Missoula, Montana, USA
[EMAIL PROTECTED]
(406) 541-5106

-----Original Message-----
From: Larry Wu [mailto:[EMAIL PROTECTED]]
Sent: Wednesday, June 28, 2000 8:43 AM
To: [EMAIL PROTECTED]
Subject: [FW1] FTP through FW-1 with NAT


I am currently using FW-1 with NAT for all out going internet traffic. I'm having problems accessing the FTP server on our ISP. From the log I see my initial ftp connection passing through but the return message is dropped. The service that the returned message is 'ident', a predefined service for port 113.  I then create a rule to allow this 'Ident' service to pass thru. The log shows it is accepted but I still cannot access the FTP site. I have no problems accessing other FTP sites. But most sites I do download from allow anonymous sessions. Has anyone encountered this type of problem? Any help will be much appreciated.

Larry

Reply via email to