Re: [Shorewall-users] ProFtpd Shorewall DROP net-fw TLS connection from client ftp

2017-08-09 Thread Davide Marchi
[..] To handle a protocol like FTP, Netfilter must inspect each packet of the control connection in order to be able to automatically open data connections. When the control connection is encrypted, it can't do that and hence data connections are rejected. To work around this, you will need

Re: [Shorewall-users] ProFtpd Shorewall DROP net-fw TLS connection from client ftp

2017-08-09 Thread Tom Eastep
On 08/09/2017 01:28 AM, Davide Marchi wrote: > Hi friends, > > On Debian Jessie, > I've configured ProFtpd to connect by tls (SSLv3 TLSv1 -> Letsencypt > certificate) on port but with Shorewall up, it DROP the connection: > > > Aug 8 18:50:10 server kernel: [16438563.572121] >

[Shorewall-users] ProFtpd Shorewall DROP net-fw TLS connection from client ftp

2017-08-09 Thread Davide Marchi
Hi friends, On Debian Jessie, I've configured ProFtpd to connect by tls (SSLv3 TLSv1 -> Letsencypt certificate) on port but with Shorewall up, it DROP the connection: Aug 8 18:50:10 server kernel: [16438563.572121] Shorewall:net-fw:DROP:IN=eth0 OUT=