|
OpenBSD General Other questions regarding OpenBSD which do not fit in any of the categories below. |
|
Thread Tools | Display Modes |
|
|||
OpenBSD 6.0: ftp configuration
Hi all.
New here and looking for some help. Just finished my first day of a practicum/internship, and currently the instructor and I are stuck on getting ftp to transmit/receive. I am looking for in depth/detailed information on configuring pf/rules to allow for incoming and outgoing ftp traffic, and also how to correctly configure ftp-proxy. More in depth information on the use of anchors would also be of help, as the information contained in the official OpenBSD faq, leaves much to be desired and has almost no troubleshooting value. |
|
|||
check out "The Book of pf" 2nd edition by Peter Hansteen
No starch press ISBN-10: I59327-274-X ISBN-13: 978-I-59327-274-6 |
|
||||
Quote:
Quote:
|
|
|||
The following is my setup on an OpenBSD firewall running on an Alix system. It allows clients on my home network to ftp to servers on the Internet
If you are trying to protect a ftp server with a firewall configuration you need a somewhat different approach Ftp uses 2 TCP communciation channels:
On my OpenBSD 5.8 firewall. I configured ftp-proxy(8) in /etc/rc.conf.local Code:
ftpproxy_flags="-T FTP_DATA" To allow this traffic in the firewall rule set: Code:
# --- ftp-proxy tags the ftp data connection packets. See /etc/rc.conf.local # pass out quick on egress inet tagged FTP_DATA The proxy itself listens on the the loopback 127.0.0.1 interface port 8021. The ftp command channel is diverted in pf.conf with: Code:
# ---- internal network interface anchor "ftp-proxy/*" pass in quick on internal inet proto tcp to port ftp divert-to 127.0.0.1 port 8021 Code:
pass out quick on egress inet proto tcp from any to any port = 21
__________________
You don't need to be a genius to debug a pf.conf firewall ruleset, you just need the guts to run tcpdump |
|
|
Similar Threads | ||||
Thread | Thread Starter | Forum | Replies | Last Post |
OpenBSD as Mail server, can you check my configuration? | wjuq | OpenBSD General | 4 | 12th February 2014 01:36 PM |
OpenBSD Gnome Configuration Problem | threaderslash | OpenBSD Packages and Ports | 7 | 29th August 2011 10:22 AM |
WindowMaker 0.92.0p7 (OpenBSD 4.4/i386 Packages) configuration issue. | xixobrax | OpenBSD General | 1 | 3rd May 2009 04:04 PM |
k3b, configuration. | maxrussell | FreeBSD Ports and Packages | 4 | 3rd March 2009 04:23 AM |
Working Configuration for Openbsd 4.0 - Postfix - SASL - TLS | roundkat | Guides | 0 | 4th May 2008 05:38 PM |