Re: pf and ftp-proxy active/passive problems

2010-07-03 Thread umaxx
On Thu, 3 Jun 2010 23:43:29 +0300 Teemu Rinta-aho wrote: > On Jun 3, 2010, at 11:26 PM, Teemu Rinta-aho wrote: > > I call it a day. > > Or maybe not. > > Case closed. I found out that even though I followed > the instructions and inserted the required lines > to my pf.conf as per ftp-proxy man pa

Re: pf and ftp-proxy active/passive problems

2010-06-03 Thread Teemu Rinta-aho
On Jun 3, 2010, at 11:26 PM, Teemu Rinta-aho wrote: > I call it a day. Or maybe not. Case closed. I found out that even though I followed the instructions and inserted the required lines to my pf.conf as per ftp-proxy man page, they were in a wrong place. Now when _both_ the anchor and the ftp po

Re: pf and ftp-proxy active/passive problems

2010-06-03 Thread Teemu Rinta-aho
On Jun 3, 2010, at 9:28 PM, Teemu Rinta-aho wrote: > The big problem hindering further investigation is that I cannot > print out the pf rules in the "ftp-proxy/*" anchor. What is the > correct syntax? "pfctl -a "ftp-proxy/*" -sr"? That prints nothing! OK I figured the syntax out by trial-and-erro

Re: pf and ftp-proxy active/passive problems

2010-06-03 Thread Teemu Rinta-aho
On Jun 3, 2010, at 6:42 PM, Calomel Org wrote: > We have to be careful when testing ftp. Different ftp binaries for > different OS's use different default options. For example, the ftp Yes, I did check that, even though it seems that most OSes I use have ftp from BSD (and yes of course they have s

Re: pf and ftp-proxy active/passive problems

2010-06-03 Thread Calomel Org
Teemu, We have to be careful when testing ftp. Different ftp binaries for different OS's use different default options. For example, the ftp binary on OpenBSD v4.7 uses passive ftp by default, so the the commands "ftp" and "ftp -p" are exactly the same. Some older Solaris machines use active only

Re: pf and ftp-proxy active/passive problems

2010-06-02 Thread Teemu Rinta-aho
On Jun 3, 2010, at 3:51 AM, Calomel Org wrote: > Teemu, > > Are you sure the ftp server you are connecting to supports active and > passive ftp? You may want to try your test against ftp.openbsd.org. That is a very good point. I thought so as I got both modes working from different nodes, but I a

Re: pf and ftp-proxy active/passive problems

2010-06-02 Thread Calomel Org
Teemu, Are you sure the ftp server you are connecting to supports active and passive ftp? You may want to try your test against ftp.openbsd.org. This is a linux machine behind a pf firewall (openbsd v4.7) using ftp-proxy. Both active (PORT) and passive listings seem to work. $ ftp ftp.openbsd.org

pf and ftp-proxy active/passive problems

2010-06-02 Thread Teemu Rinta-aho
Hi all, (First, sorry if you receive this e-mail multiple times, I changed my smtp server as the first one doesn't seem to get mails to this list.) my firewall (OpenBSD 4.7) is running packet filter with NAT and tcp-proxy to provide FTP for hosts in the network behind the firewall/NAT. The probl