From owner-freebsd-pf@FreeBSD.ORG Fri Oct 22 06:29:24 2004 Return-Path: Delivered-To: freebsd-pf@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 9BE1616A4CE for ; Fri, 22 Oct 2004 06:29:24 +0000 (GMT) Received: from ns.kt-is.co.kr (ns.kt-is.co.kr [211.218.149.125]) by mx1.FreeBSD.org (Postfix) with ESMTP id 2085F43D46 for ; Fri, 22 Oct 2004 06:29:24 +0000 (GMT) (envelope-from yongari@kt-is.co.kr) Received: from michelle.kt-is.co.kr (ns2.kt-is.co.kr [220.76.118.193]) (authenticated bits=128) by ns.kt-is.co.kr (8.12.10/8.12.10) with ESMTP id i9M6T3Ah003497 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=FAIL); Fri, 22 Oct 2004 15:29:03 +0900 (KST) Received: from michelle.kt-is.co.kr (localhost.kt-is.co.kr [127.0.0.1]) by michelle.kt-is.co.kr (8.12.10/8.12.10) with ESMTP id i9M6SkvJ030726 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Fri, 22 Oct 2004 15:28:46 +0900 (KST) (envelope-from yongari@kt-is.co.kr) Received: (from yongari@localhost) by michelle.kt-is.co.kr (8.12.10/8.12.10/Submit) id i9M6SkUd030725; Fri, 22 Oct 2004 15:28:46 +0900 (KST) (envelope-from yongari@kt-is.co.kr) Date: Fri, 22 Oct 2004 15:28:46 +0900 From: Pyun YongHyeon To: Claudiu Dragalina-Paraipan Message-ID: <20041022062846.GB30651@kt-is.co.kr> References: <20041022061152.GA30651@kt-is.co.kr> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20041022061152.GA30651@kt-is.co.kr> User-Agent: Mutt/1.4.1i X-Filter-Version: 1.11a (ns.kt-is.co.kr) cc: freebsd-pf@freebsd.org Subject: Re: FTP Server behind NAT X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list Reply-To: yongari@kt-is.co.kr List-Id: Technical discussion and general questions about packet filter (pf) List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 22 Oct 2004 06:29:24 -0000 On Fri, Oct 22, 2004 at 03:11:52PM +0900, To Claudiu Dragalina-Paraipan wrote: > On Thu, Oct 21, 2004 at 09:05:29PM +0300, Claudiu Dragalina-Paraipan wrote: > > Hello again, > > > > in the meanwhile I found a solution: > > ftp can be aware of the fact that it must use another IP for passive > > mode connections. > > vsftpd option that does this is "pasv_address" and pureftpd is > > "ForcePassiveIP". Probably most decent ftp servers have such an > > option. > > The firewall still has the redirect the same ports to the internal ftp > > server for this to work. > > > > I guess you need "-a" option of ftp-proxy(8). > Ooops. Please ignore this. Need more coffee. -- Regards, Pyun YongHyeon http://www.kr.freebsd.org/~yongari | yongari@freebsd.org