Skip site navigation (1)Skip section navigation (2)
Date:      30 Jan 2005 10:45:50 -0500
From:      Lowell Gilbert <freebsd-questions-local@be-well.ilk.org>
To:        "Gerard Meijer" <gmeijer@palmweb.nl>
Cc:        freebsd-questions@freebsd.org
Subject:   Re: ipfw statefull ruleset problem
Message-ID:  <44is5egbtd.fsf@be-well.ilk.org>
In-Reply-To: <082901c50621$290f8ea0$9600000a@guus>
References:  <082901c50621$290f8ea0$9600000a@guus>

next in thread | previous in thread | raw e-mail | index | archive | help
"Gerard Meijer" <gmeijer@palmweb.nl> writes:

> But I learned that that is not the right way to do this in a
> statefull ruleset, because the dynamic rules don't have any use in
> this way. So what is the right way to solve this?

Don't do FTP?  Use an FTP proxy that knows how to work around the
firewall?  FTP was designed for an Internet with end-to-end
connectivity, which you're breaking by putting in a packet filter in
the first place...



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?44is5egbtd.fsf>