On 8 Apr 99, at 9:45, Fuzzy Fox wrote about
    "[Masq]  Re: Ip Masq and Port Forwar":

| Ryan S. Bringel <[EMAIL PROTECTED]> wrote:
| >
| > I currently use a Windowz FTP deamon that i am very happy with 
| > and would like to continue to use, the problem is that box is now 
| > behind the linux firewall. The FTP uses a non-standard port (99) 
| > also... Please see below.
| 
| You will run into problems with this, because FTP uses multiple
| connections for data transfers.  In fact, I guarantee that, after you
| get this working, that's what your next question is gonig to be....
| 
| There is an experimentail version of the ip_masq_ftp module which
| supposedly helps out when running a masqueraded ftp server; the default
| one only assists ftp *client* connections, not server.  But I cannot
| recall where you get the experimental ip_masq_ftp....

If the external client is using PORT (not PASV) mode, your masqed FTP 
server will *mostly* just work.  The only problem will be on long 
file transfers, because the masqeuerade entry for the control 
connection will time out and be deleted while the long transfer is 
going on on the data port.

To support PASV mode (which is what most web browsers seem to use) 
and long file transfers, you need both a kernel patch and an updated 
version of the ip_masq_ftp module.  For 2.0.36 kernels, these are 
both available via David Ranch's excellent IP_MASQ HowTo.

These patches will not work as-is with 2.2.x kernels.  But stay 
tuned.  The kernel patch required in 2.2.x is even more trivial than 
in 2.0.3x, and one brave soul has already ported my ip_ftp_masq mods 
into the 2.2.x version and is trying it out.

|...

- Fred Viles <mailto:[EMAIL PROTECTED]>




_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
http://tiffany.indyramp.com/mailman/listinfo/masq
Admin requests can be handled by web (above) or [EMAIL PROTECTED]

Reply via email to