Beaudet, David P. <mailto -Beaudet
NGA.GOV> wrote on January 17, 2007
09:26 AM:
> Here's what's going on:
>
> There are two modes of data transfer for FTP: Active
and Passive.
>
> ...
> Passive mode involves the server opening two ports --
the control port
> is fixed and the same as in active mode, but the data
port is a random
> unprivileged port > 1024. Therefore, IPTABLES must
be configured
> accordingly. The only working configuration I
discovered was opening
> up all ports above 1024.
Can your firewall open up ports between your host and your
client only?
It that works, you may still run into the problem that the
Windows ftp
client doesn't do Passive, if you're working from a Windows
client.
Regards
gh
|