Bluehost.com Web Hosting $6.95

Re: FTP proxy not working in Solaris 9

This is a discussion on Re: FTP proxy not working in Solaris 9 within the IPFilter forums, part of the System Security and Security Related category; Hans Werner Strube wrote: > Since there has been no reply to my four mails from August 16-19, here &...


Go Back   Usenet Forums > System Security and Security Related > IPFilter

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 09-21-2005
Hans Werner Strube
 
Posts: n/a
Default Re: FTP proxy not working in Solaris 9

Hans Werner Strube wrote:
> Since there has been no reply to my four mails from August 16-19, here
> a summary again.
> I always liked IPF because of its well-functioning FTP proxy and had
> 3.4.x (finally, 3.4.35) running for years on a Solaris 7_x86 PC with
> two interfaces (routing). This was replaced by a Solaris 9 SunFire V210
> (64 bit only), with IPF 3.4.35 compiled on it and the same configuration
> as on the PC. Then with FTP proxy rules in ipnat.conf, IPF did not pass any
> FTP-related packets (not even those of the control connection) to the other
> interface, as verified by snoop. But they were not logged as blocked by
> any rule, and ipnat -l shows correct mapping. This happens only for
> connections *through* the firewall, whereas the FTP proxy works for
> connections from the firewall machine itself to the outer net. Also,
> no-proxy NAT works correctly through the firewall.
> For more details, see my former mails.
> Any ideas? Experimenting is difficult for me, since this is a busy
> firewall of an institute.


NEWS: I tried the same with the rcmd and raudio proxies - same behaviour:
With proxy NAT rule, not even the control connection was visible on the
outer interface for connections _through_ the firewall, but it was visible
for connections _from_ the firewall itself.

Thus, this bug is not FTP specific but seems to concern all builtin proxies!
(Version 3.4.35; 4.1.x not tested.)

In the failing case, ipnat -lv shows "drop 0/N", N nonzero. Seems to indicate
that appr_check in ip_proxy.c (called from ip_natout in ip_nat.c) fails?
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT +1. The time now is 01:45 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0