Date: 30 Jan 2005 10:45:50 -0500 From: Lowell Gilbert <freebsd-questions-local@be-well.ilk.org> To: "Gerard Meijer" <gmeijer@palmweb.nl> Cc: freebsd-questions@freebsd.org Subject: Re: ipfw statefull ruleset problem Message-ID: <44is5egbtd.fsf@be-well.ilk.org> In-Reply-To: <082901c50621$290f8ea0$9600000a@guus> References: <082901c50621$290f8ea0$9600000a@guus>
next in thread | previous in thread | raw e-mail | index | archive | help
"Gerard Meijer" <gmeijer@palmweb.nl> writes: > But I learned that that is not the right way to do this in a > statefull ruleset, because the dynamic rules don't have any use in > this way. So what is the right way to solve this? Don't do FTP? Use an FTP proxy that knows how to work around the firewall? FTP was designed for an Internet with end-to-end connectivity, which you're breaking by putting in a packet filter in the first place...
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?44is5egbtd.fsf>