From owner-freebsd-questions@FreeBSD.ORG Thu Jan 15 04:34:20 2004 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 8B9A216A4CE for ; Thu, 15 Jan 2004 04:34:20 -0800 (PST) Received: from gw.pelleg.org (gw.pelleg.org [205.201.13.235]) by mx1.FreeBSD.org (Postfix) with ESMTP id 40AC543D49 for ; Thu, 15 Jan 2004 04:34:19 -0800 (PST) (envelope-from daniel+bsd@pelleg.org) Received: from lank.here (lank.wburn [192.168.3.41]) (using TLSv1 with cipher EDH-RSA-DES-CBC3-SHA (168/168 bits)) (Client CN "gw.pelleg.org", Issuer "Dan Pelleg" (verified OK)) by gw.pelleg.org (Postfix) with ESMTP id A735C5A53; Thu, 15 Jan 2004 07:34:17 -0500 (EST) Received: by lank.here (Postfix, from userid 7675) id 03C0E120; Thu, 15 Jan 2004 07:34:12 -0500 (EST) To: Hiren References: <1074159047.2398.3.camel@fbtab.h3p.co.za> From: Dan Pelleg Date: Thu, 15 Jan 2004 07:34:12 -0500 In-Reply-To: <1074159047.2398.3.camel@fbtab.h3p.co.za> (Hiren's message of "Thu, 15 Jan 2004 11:30:47 +0200") Message-ID: User-Agent: Gnus/5.1002 (Gnus v5.10.2) XEmacs/21.1 (Cuyahoga Valley, berkeley-unix) MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii cc: FreeBSD-Questions Subject: Re: running ftpd in a jail X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 15 Jan 2004 12:34:20 -0000 Hiren writes: > greetings > > i am setting up a ftp server. > since i prefer setting all services within jails, i thought i would > setup ftpd within a jail. > i was basically NATing the required ports to the jails. > i realized that ftpd in passive mode was almost impossible to NAT since > it uses a wide range of ports. > i then resorted to NATing ports 20 and 21 and using active mode for my > server. > i wanted to know which mode is more secure and how would i go about > setting up ftpd within a jail in passive mode. > > i would appreciate advice and comments > You can use the punch_fw keyword to natd(8) for that. -- Dan Pelleg