Subject: Re: IPFILTER 3.4.9 and FTP
To: dkwok <dkwok@iware.com.au>
From: Berndt Josef Wulf <wulf@dingo.ping.net.au>
List: port-i386
Date: 05/14/2001 06:31:18
dkwok wrote
[ Charset ISO-8859-1 unsupported, converting... ]
> I have just installed NetBSD 1.5.1 with ipfilter 3.4.9 stocked verison. This is the first time I put netbsd as my gateway. I have been using Linuxrouter for 2 years, so I used ipchains ip masquarade.
> 
> After installing the nebbsd router I can feel a significant improvment in speed on connecting to the internet. This is also backup up the improvment in traceroute time. However, I have problem doing ftp. ftp using unix box is fine. But windoz ftp client has problem. Although I have configured it in passive mode. I use ftp explorer. It says "error connecting to: ftp.netbsd.org"
> 
> I have checked mail list people seem to say ipfilter 3.4.8 & 3.4.9 are both broken.
> 
> Any pointer on this one?

In /etc/ftp.conf set

portrange       all     1024    5000

which assigns a port range between 1024 and 5000. Using the following
entry in /etc/ipf.conf will pass these packets in passive mode

pass in log quick on ppp0 proto tcp from any to any port 1023 >< 5001

You may want to choose a different port range which suits best your
system

Hope this helps

cheerio Berndt
-- 
Name    : Berndt Josef Wulf            | +++ With BSD on Packet Radio +++
E-Mail  : wulf@ping.net.au             |    tfkiss, tnt, dpbox, wampes
ICQ     : 18196098                     |  VK5ABN, Nairne, South Australia 
URL     : http://www.ping.net.au/~wulf | MBOX : vk5abn@vk5abn.#lmr.#sa.au.oc
Sysinfo : DEC AXPpci33+, NetBSD-1.5    | BBS  : vk5abn.#lmr.#sa.aus.oc