Am Dienstag, den 28.03.2006, 14:09 +0200 schrieb Michael Schmidt:


> So what I want to setup is pf and the ftp-daemon in that way that the
> ftp-daemon offers only a very small range of passive ports (or perhaps
> only one single passive port?) and that pf opens only the same small
> range of ports (or the same single port).

Well, I needed the exact same thing and did it with pure-ftpd[1] via the
command-line option "-p 50000:50400" and an pf.conf entry like "pass in
on $if tcp from any to $if port 50000:50400". Maybe this is an option
for you too.


David Elze                     Tel:    (+49)(0)441 - 36116410
[EMAIL PROTECTED]              Fax:    (+49)(0)441 - 36116419       PGP/GPG:              5F83FEA2
bytemine  -  Entwicklungsmanufaktur fuer innovative Loesungen

[demime 1.01d removed an attachment of type application/pgp-signature which had 
a name of signature.asc]

Reply via email to