Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | PIX and PASV ftp |
|---|---|
| Date: | Tue, 19 Jul 2005 12:34:31 -0700 |
I'm having some difficulty in getting the PIX to allow PASV connections through. I have a vsftpd server on a DMZ with a private IP and running IPTables with modules ip_nat_ftp and ip_conntrack_ftp loaded, though same errors occur with IPTables stopped. The vsftpd server has a pasv_address of the public IP, and pasv_enable is YES. The error from IE browser is "An error occurred opening that folder on the FTP Server. Make sure you have permission to access that folder." Ethereal on the client follows the TCP stream like this: 220 Welcome message nnnn USER xxxxx 331 Please specify the password. PASS xxxxx 230 Login successful. Have fun. SYST 215 UNIX Type: L8 FEAT 500 Unknown command. TYPE I 200 Switching to Binary mode. REST 0 350 Restart position accepted (0). PWD 257 "/home/xxxx" PASV <then a bunch of TCP Retransmission requests for PASV> The server log shows it responds to the PASV command with: <Time/date> <pid> <username> FTP command: Client "nnn.nnn.nnn.nnn", "PASV" <Time/date> <pid> <username> FTP response: Client "nnnnnn", "227 Entering Passive Mode (nnn,nnn,nnn,nnn,190,130)" But the client never gets that message. The pix logs this: "%PIX-4-406002: FTP port command different address: from <outsideIP:port> to <insideIP:port>". "%PIX-6-302014: Teardown TCP connection nnn for outside:<outsideIP:port> to dmz:<insideIP:port> duration 00:00:01 bytes 350 Deny". "PIX-6-106015: Deny TCP (no connection) from <outsideIP:port> to <insideIP:port>". Non-PASV works fine. I'm worn out Googling this. Has anyone experienced this before? Thanks, Bill Stout www.greenborder.com
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: Minimal secure iptables firewall, Security Admin |
|---|---|
| Next by Date: | Re: MAC Address connecting to Port 1, cygnuz1979 |
| Previous by Thread: | pix asdm, Andrew Shore |
| Next by Thread: | Re: PIX and PASV ftp, Charalambos Klitiropoulos |
| Indexes: | [Date] [Thread] [Top] [All Lists] |