> FTP is a completely different protocol to HTTP.  It uses a TCP control
> channel on port 21, and an incoming UDP data channel for data.
>
> In passive mode, this is slightly different.
>
> However, people who have used passive and UDP FTP know that UDP is faster
> and that's why ip_masq_ftp was created.

It's been a while since I read the FTP RFC but if I do remember correctly:

1. FTP uses TCP only (FSP uses UDP)
2. As mention before it uses one port for data (20)  and one port for
control (21). When you download a file, your local PC binds and listens to a
random port and then sends the port to the server. Server then connects from
the data port and sends you the file. This will not work when masquerading
because when your PCs binds to a local port the port is not exposed to the
internet. ip_masq_ftp knows about ftp connections and when it sees a local
port being sent it sets up a port that is exposed to the internet on the
gateway, rewrites the packet so that the ftp server sends the data to it and
redirects traffic from the gateway port to your local port. Thus FTP works
again.

The answer is still load ip_masq_ftp, albeit for somewhat different reason.
;-)

Dave.

---
David Zverina
Alt Key Pty. Ltd.
http://www.altkey.com
PO Box 3121, Parramatta, 2124, Australia

--
SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
To unsubscribe send email to [EMAIL PROTECTED] with
unsubscribe in the text

Reply via email to