From owner-freebsd-questions@FreeBSD.ORG Tue May 11 08:13:19 2004 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id CB62016A4CE for ; Tue, 11 May 2004 08:13:19 -0700 (PDT) Received: from mail02.infosat.net (mailout06.infosat.net [66.18.69.6]) by mx1.FreeBSD.org (Postfix) with ESMTP id 57F2B43D3F for ; Tue, 11 May 2004 08:13:17 -0700 (PDT) (envelope-from blygar1@webmail.co.za) Received: from [66.18.70.48] (HELO mail01.infosat.net) by mail02.infosat.net (CommuniGate Pro SMTP 4.1.8) with ESMTP id 70247128 for freebsd-questions@freebsd.org; Tue, 11 May 2004 17:13:14 +0200 Received: from [196.31.69.30] (account blygar1@webmail.co.za) by mail01.infosat.net (CommuniGate Pro WebUser 4.1.8) with HTTP id 309316714 for freebsd-questions@freebsd.org; Tue, 11 May 2004 17:13:14 +0200 From: "Gareth Bailey" To: freebsd-questions@freebsd.org X-Mailer: CommuniGate Pro WebUser Interface v.4.1.8 Date: Tue, 11 May 2004 17:13:14 +0200 Message-ID: MIME-Version: 1.0 Content-Type: text/plain; charset="ISO-8859-1" Content-Transfer-Encoding: 8bit Subject: FTP problem with IPFW X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 11 May 2004 15:13:19 -0000 I have recently setup IPFW on my FreeBSD 5.2 Release server. I am running natd to provide inet to 5 LAN users. It also runs mail, apache web server amongst others. All seems to be working fine, except for FTP. The first two lines of my firewall file are: add 1000 allow tcp from any to any via ed0 out keep-state add 1100 allow udp from any to any via ed0 out keep-state ... then later in the file: add 3600 allow tcp from any to me dst-port 21 in via ed0 setup keep-state I thought this would be sufficient to establish and maintain FTP connections. I read through the mailing lists and it seems that FTP is tricky with IPFW and natd. Is there a simple solution to this problem? Can i just add some other rule to my firewall? I read something about natd punching through IPFW, is this the answer? Any information will be mouch appreciated. Thanks, Gareth (IPFW newbie) _____________________________________________________________________ For super low premiums ,click here http://www.dialdirect.co.za/quote