Go Back   Wireless and Wifi Forums > News > Newsgroups > comp.security.misc
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #61 (permalink)  
Old 10-15-2005, 01:10 AM
Alun Jones
Guest
 
Posts: n/a
Default Re: Why do I need a software firewall?

<david20@alpha2.mdx.ac.uk> wrote in message
news:dio15o$lnh$1@news.mdx.ac.uk...
> In article <E4qdnbbtgcQaWdPeRVn-hg@comcast.com>, "Alun Jones"
> <alun@texis.invalid> writes:
>>"Leythos" <void@nowhere.lan> wrote in message
>>news:kEw3f.105095$lI5.40473@tornado.ohiordc.rr.c om...
>>> In article <-eGdnTC-H62FG9PeRVn-rw@comcast.com>, alun@texis.invalid
>>> says...
>>>> "Leythos" <void@nowhere.lan> wrote in message
>>>> news:MPG.1dacbea55d89a2ee98a1c1@news-server.columbus.rr.com...
>>>> > You really are a dufus - I never said that NAT didn't impact Active
>>>> > FTP,
>>>> > not once. I said that NAT doesn't break FTP, never saying anything
>>>> > about
>>>> > Active or Passive - knowing the anyone that understands the slightest
>>>> > about FTP and NAT would already know that you need to use Passive
>>>> > FTP,
>>>> > which works fine, so FTP isn't broken at all.
>>>>
>>>> Hmm...
>>>>
>>>> Depending on who's behind the NAT, that is. Passive FTP doesn't work
>>>> if
>>>> it's the server that's behind the NAT. You have to tell the NAT which
>>>> ports
>>>> to open.
>>>>
>>>> Now, some NATs work fine for passive FTP, because they scan the FTP
>>>> control
>>>> channel for PASV commands and the associated responses, and they change
>>>> the
>>>> IP address and port described therein. They should also open up the
>>>> port
>>>> mapping from the external port to the internal one. These NATs
>>>> generally
>>>> do
>>>> the same for active FTP transfers, allowing them to work, too.
>>>>
>>>> There are two usual stipulations on this, however:
>>>> 1. The FTP control traffic must be on port 21. I've heard rumours that
>>>> there are NAT routers that can be configured to look for FTP on other
>>>> ports,
>>>> but never run across such a beast.
>>>> 2. The FTP control traffic must be unencrypted.
>>>
>>> I have 9 FTP servers, some are behind a NAT from a Linksys/D-Link,
>>> others behind a FireBox II others behind a FireBox x1000. They all seem
>>> to work for us.

>>

> FTP is so widely used that I'd think that most NAT devices nowadays would
> come
> with builtin FTP Application Level Gateways to overcome these problems.


<grumble>just not paying attention</grumble>

Yes, most NATs do FTP ALGs. In fact, if your NAT doesn't have an FTP ALG,
I'd return it as defective.

However, if (1) the FTP control traffic arrives at the server on anything
other than port 21, or (2) the FTP control traffic is encrypted, the FTP ALG
in most NATs is not going to be able to make the required address and port
changes.

Alun.
~~~~



Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
HPSBGN02187 SSRT061280 rev.1 - Mercury LoadRunner, Performance Center, Monitor over Firewall, Remote Unauthenticated Arbitrary Code Execution Security Alert comp.security.misc 0 02-08-2007 09:06 PM
software thuriam software.datagrep@gmail.com alt.internet.wireless 0 08-04-2006 04:16 PM
best practices to secure home's network strutsng@gmail.com alt.internet.wireless 31 10-14-2005 10:22 AM
Need recommendations: router and software firewall. om.newsgroup@gmail.com comp.security.misc 8 10-03-2005 07:48 AM
Router firewall vs Software firewall peejay Members Lounge 12 10-26-2004 01:53 AM


All times are GMT. The time now is 03:47 AM.


Powered by vBulletin® Version 3.7.1
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45