Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 17 Mar 2006 11:41:20 +0100
From:      Erik Norgaard <norgaard@locolomo.org>
To:        freebsd-questions@freebsd.org
Subject:   configuring fetch to passive mode
Message-ID:  <441A9250.10103@locolomo.org>

next in thread | raw e-mail | index | archive | help
Hi:

This ought to be a configuration tunable, but I can't find any 
documentaion on it: How to I force fetch to use passive mode?

When I try "make fetch" of some port I get:

   => Attempting to fetch from \
       ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/distfiles/.
   fetch: \ ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/distfiles/file: \
       Operation not permitted

It fails quickly, no sign of things timing out.

In my firewall (pf), I have

block in  quick on $ext_if all
pass  out quick on $ext_if proto tcp  all flags S/SA keep state
pass  out quick on $ext_if proto udp  all keep state
pass  out quick on $ext_if proto icmp all keep state

which basically block ftp active, but should allow ftp passive. If I 
flush the rules fetch works fine, so it must be an issue of fetch trying 
active mode.

Setting FTP_PASSIVE_MODE=YES as environment variable or in make.conf 
doesn't change a thing.

Thanks, Erik

-- 
Ph: +34.666334818                                  web: www.locolomo.org
S/MIME Certificate: www.daemonsecurity.com/ca/8D03551FFCE04F06.crt
Subject ID:  9E:AA:18:E6:94:7A:91:44:0A:E4:DD:87:73:7F:4E:82:E7:08:9C:72
Fingerprint: 5B:D5:1E:3E:47:E7:EC:1C:4C:C8:3A:19:CC:AE:14:F5:DF:18:0F:B9



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?441A9250.10103>