On 30-Apr-99 Barton, James wrote:
> I have an internal Masq ftp server that users from the internet need to
> access. They can log in, but they can't get a listing of files. I get the
> error "Can't build data connection".
That's not a very straight-forward thing to get working. As you may or may
not know, a single ftp client actually involves two TCP connections. One
that is known as the control connection which is where all of the interactive
commands are issued, and then there is a data connection which is strangely
enough issued in reverse; that is from the server to the client. To
facilitate this data connection the PORT command is used to tell the peer
onto which IP and Port to attempt a data connection. Since this information
conflicts with the masqueraded IP and Port, the connection attempt will fail.
> According to the IPMASQ-HOWTO-1.71 section 6.8 it may not be possible.
> "NOTE: At this time, it is beleived that this modified IP_MASQ_FTP module
> for port forwarded FTP connections will NOT work for the 2.2.x kernels.
The purpose of the ip_masq_ftp module is to snoop on the control connection
and rewrite the PORT command. This is only active during outgoing
connections; i.e. masqueraded clients. It wouldn't be active during your
situation because it is specifically monitoring connections going out to a
destination port of 21.
So to answer your original question about how to redirect incoming ftp
services. Hmm, good question. How does everyone else do it. Maybe they
don't. I'm sure there has to be a package somewhere to do it. If there
isn't I guess someone will have to write it :/
I've been looking at the redir package and ironically it appears to have PASV
support but no normal mode ftp support. Not quite sure why. Anyhow you can
take a look at that package, here is it's freshmeat entry:
http://www.freshmeat.net/appindex/1999/03/14/921462694.html
/* Chris Faherty <[EMAIL PROTECTED]>, finger for PGP */
_______________________________________________
Masq maillist - [EMAIL PROTECTED]
http://tiffany.indyramp.com/mailman/listinfo/masq
Admin requests can be handled by web (above) or [EMAIL PROTECTED]