Subject: Re: NAT query
To: None <>
From: der Mouse <mouse@Rodents.Montreal.QC.CA>
List: tech-userlevel
Date: 02/26/2002 06:05:56
> I have a NAT box between our FTP server and the Internet universe.
> [...problem...]

"Don't do that, then."  FTP, especially in PORT-using (non-PASV) mode,
is one of the protocols broken most severely by NAT, to the point that
a lot of NAT implementations have special-case kludges to rewrite the
control data stream on the fly to make it "work" in at least a minimal
sense.  To my mind, this "fixes" FTP-through-NAT in much the same way
that MSS clamping "fixes" a path MTU discovery black hole: it doesn't
actually fix the problem, just keeps it dormant for the moment.

