/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */



Carl H. Sayres <[EMAIL PROTECTED]> wrote:
>
> Whenever I click on an ftp://...  URL from within any web browser on
> any client platform, the browser simply waits and eventually times
> out.  HTTP URLs work fine.  To my surprise, the FTP program works
> great when used from the command line.

This is one of the more confusing problem reports I see on this list. 
The reason is that the FTP mode that is having problem, which is the
"passive" mode, is the one that should work flawlessly without any
firewall rules; only the masquerade rule is required (of course).

The reason:

    In "port mode" ftp, the client connects to the server on port 21,
    and sends commands on that channel.  Whenever a data transfer is
    desired, the client sends a PORT command to the server, containing
    its local IP address and a randomly-chosen port number for the
    server to connect to the client.  In a masquerade setup, this fails
    for two reasons:  The client sends its local IP address, which is an
    unreachable network as far as the server is concerned (usually
    192.168.*.*).  And, even if the client did get the IP address right,
    the masquerade server wouldn't know that the incoming connection was
    supposed to be forwarded back to the client, because it's a random
    port number.

    This is exactly the problem that the ip_masq_ftp module solves.  It
    watches for outgoing PORT commands, and modifies them in mid-stream,
    substituting a new IP address and port, and also sets up an entry in
    the masq table that will forward that new connection back to the
    originating client.

Sounds great.  BUT... WEB BROWSERS DO NOT USE "PORT MODE".

    In "port mode" ftp, the client also connects to the server on port
    21, sending commands on that channel.  Whenever a data transfer is
    desired, the client sends a PASV command to the server, and the
    server replies with a randomly-chosen port number for the client to
    connect to it.  The client simply makes another outbound connection
    to the server, to the port specified by the server.

    In a masquerade setup, this type of connection (an outgoing TCP
    connection) should work perfectly without any need for modules, or
    fixup addresses, or whatever.  So a problem report such as you gave
    is rather confusing.

So, my conclusion...  There is something wrong with your firewall setup
(not your masquerade setup...  though they use the same command
(ipmasqadm/ipchains) to set up, they are different things.

A passive-mode ftp session requires the ability of the client to be able
to send an out-bound TCP connection to any random port that the server
might ask it to connect to.  The ip_masq_ftp module will not affect
anything in this regard, because the masq table entry will be created
when the connection is attempted.  I can only conclude that the
masquerade is working fine, but that you have some sort of firewall rule
in place that is preventing the connection from succeeding.

Your firewall logs may help you find the problem.

-- 
   [EMAIL PROTECTED] (Fuzzy Fox)      || "Nothing takes the taste out of peanut
sometimes known as David DeSimone  ||  butter quite like unrequited love."
  http://www.dallas.net/~fox/      ||                       -- Charlie Brown


_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/

Reply via email to