From owner-freebsd-security@FreeBSD.ORG Mon Aug 4 06:05:57 2003 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id EC47537B404 for ; Mon, 4 Aug 2003 06:05:57 -0700 (PDT) Received: from smtp.melim.com.br (smtp.melim.com.br [200.215.110.25]) by mx1.FreeBSD.org (Postfix) with ESMTP id 1348B43FDD for ; Mon, 4 Aug 2003 06:05:57 -0700 (PDT) (envelope-from ronan@melim.com.br) Received: from fazendinha (ressacada.melim.com.br [200.180.44.4]) by smtp.melim.com.br (Postfix) with ESMTP id 4FB06FDB5; Mon, 4 Aug 2003 10:05:52 -0300 (EST) Message-ID: <014201c35a89$6a20a6d0$3aa8a8c0@melim.com.br> From: "Ronan Lucio" To: "Jan Lentfer" References: <00a001c35875$5432f730$3aa8a8c0@melim.com.br> <1059808321.3f2b6441bbaa5@www-mail.lan> Date: Mon, 4 Aug 2003 10:07:53 -0300 MIME-Version: 1.0 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: 8bit X-Priority: 3 X-MSMail-Priority: Normal X-Mailer: Microsoft Outlook Express 6.00.2800.1106 X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1106 cc: security@freebsd.org Subject: Re: FTP X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Security issues [members-only posting] List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 04 Aug 2003 13:05:58 -0000 Jan, > What ftp server are you using? If I remember right ProFTPd allows you to define > what passive ports to use, eg. 50000-50100 or something like that. Then you only > open up that ports you defined in proftpd.conf in the firewall. > Or did you mean outgoing ftp traffic? My main problem is a Internet gateway to provide Internet access for a building where the clients need to access other FTP servers from other servers. For example: We provide Internet access for a building. If the clients of these network need to access the FreeBSD FTP server and Yahoo and etc... I´m permiting ports from 1025 to 65535 to make it possible. Is it right? Thank´s, Ronan