Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
VSFTP running behind a firewall
View unanswered posts
View posts from last 24 hours

Goto page Previous  1, 2  
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
asterix404
Apprentice
Apprentice


Joined: 05 Nov 2004
Posts: 213

PostPosted: Sat Dec 11, 2004 12:01 am    Post subject: Reply with quote

umm... well... in my vsftp.conf there is an option for forcing data transfers over port 20. Also isn't this the default ftp data transfer port?
Back to top
View user's profile Send private message
pharaoh
Apprentice
Apprentice


Joined: 20 Nov 2003
Posts: 211
Location: Pennsylvania

PostPosted: Sat Dec 11, 2004 12:03 am    Post subject: Reply with quote

Hey, did you also forward all those passive ports through the routers?

EDIT: Ok I notice in your very first post you said you did forward them...
_________________
RYZEN 5 3600 Matisse (Zen 2) 6-Core 3.6 GHz Socket AM4 65W
ASRock B550M PRO4
Crucial Ballistix 3200 MHz DDR4 DRAM 16GB
EVGA GeForce GTX 1060 6GB
Back to top
View user's profile Send private message
asterix404
Apprentice
Apprentice


Joined: 05 Nov 2004
Posts: 213

PostPosted: Sat Dec 11, 2004 12:35 am    Post subject: Reply with quote

how do you do that, and actuilly this stuff is really helpful with people going through similar porblems... cuz there is almost no documention describng non working vsftpd stuff, but rally how do you configure those ports to be passive?
Back to top
View user's profile Send private message
pharaoh
Apprentice
Apprentice


Joined: 20 Nov 2003
Posts: 211
Location: Pennsylvania

PostPosted: Sat Dec 11, 2004 12:39 am    Post subject: Reply with quote

You have them set in your vsftpd.conf already so it seems ok. Just to check, you're forwarding the TCP ports not the UDP ones with the router right?
_________________
RYZEN 5 3600 Matisse (Zen 2) 6-Core 3.6 GHz Socket AM4 65W
ASRock B550M PRO4
Crucial Ballistix 3200 MHz DDR4 DRAM 16GB
EVGA GeForce GTX 1060 6GB
Back to top
View user's profile Send private message
seank
l33t
l33t


Joined: 08 Jul 2004
Posts: 686

PostPosted: Sat Dec 11, 2004 12:58 am    Post subject: Reply with quote

asterix404 wrote:
umm... well... in my vsftp.conf there is an option for forcing data transfers over port 20. Also isn't this the default ftp data transfer port?
No
Back to top
View user's profile Send private message
asterix404
Apprentice
Apprentice


Joined: 05 Nov 2004
Posts: 213

PostPosted: Sat Dec 11, 2004 2:03 am    Post subject: Reply with quote

yes I am only forwarding the TCP cuz that the thing can call for... what is UDP... it has been a while since i had to use that information... as for the port listenings... is there a reason to not use port 20?

Okay so here we go, i have prots 61000-62000 open on all of my routers. I have 19-22 open as well... I get a socket error... what is that what does this mean?
Back to top
View user's profile Send private message
pharaoh
Apprentice
Apprentice


Joined: 20 Nov 2003
Posts: 211
Location: Pennsylvania

PostPosted: Sat Dec 11, 2004 3:29 am    Post subject: Reply with quote

I'm curious if you really do need that ftp_conntrack_ip module just for this port 20 passive business. I don't like genkernel because it takes away your control, but try doing an lsmod and see what's loaded up. Sean is right though, if you're not using a firewall you shouldn't need it...however I needed it even with the firewall open on the correct ports. Who knows!
_________________
RYZEN 5 3600 Matisse (Zen 2) 6-Core 3.6 GHz Socket AM4 65W
ASRock B550M PRO4
Crucial Ballistix 3200 MHz DDR4 DRAM 16GB
EVGA GeForce GTX 1060 6GB
Back to top
View user's profile Send private message
asterix404
Apprentice
Apprentice


Joined: 05 Nov 2004
Posts: 213

PostPosted: Sat Dec 11, 2004 3:37 am    Post subject: Reply with quote

okay so the lsmod has

Quote:
Module Size Used by
uhci_hcd 27664 0
ehci_hcd 24324 0
tulip 35360 0
cmpci 35636 0
mpu401 24420 1 cmpci
sound 70444 1 mpu401
ohci_hcd 14596 0
snd_pcm_oss 55848 0
snd_mixer_oss 18816 3 snd_pcm_oss
snd_seq_oss 32640 0
snd_seq_midi_event 6144 1 snd_seq_oss
snd_seq 52368 4 snd_seq_oss,snd_seq_midi_event
snd_cmipci 22820 2
snd_pcm 89352 2 snd_pcm_oss,snd_cmipci
snd_page_alloc 8072 1 snd_pcm
snd_opl3_lib 9472 1 snd_cmipci
snd_timer 21636 3 snd_seq,snd_pcm,snd_opl3_lib
snd_hwdep 7556 1 snd_opl3_lib
gameport 3712 1 snd_cmipci
snd_mpu401_uart 6272 1 snd_cmipci
snd_rawmidi 20644 1 snd_mpu401_uart
snd_seq_device 6920 4 snd_seq_oss,snd_seq,snd_opl3_lib,snd_rawmidi
snd 51588 13 snd_pcm_oss,snd_mixer_oss,snd_seq_oss,snd_seq_midi_event,snd_seq,snd_cmipci,snd_pcm,snd_opl3_lib,snd_timer,snd_hwdep,snd_mpu401_uart,snd_rawmidi,snd_seq_device
usbcore 96868 5 uhci_hcd,ehci_hcd,ohci_hcd
nvidia 4810100 14


but thats the thing... I am behind a firewall... with all ports open... I also normally run genkernel and then change all of the settings cuz it can do stuff like give me pretty fonts. I thought I put FTP support in my kernel... hmm back to the drawing bord.
Back to top
View user's profile Send private message
pharaoh
Apprentice
Apprentice


Joined: 20 Nov 2003
Posts: 211
Location: Pennsylvania

PostPosted: Sat Dec 11, 2004 3:56 am    Post subject: Reply with quote

All those modules are for hardware. I don't know a thing about genkernel, and I was just asking to try that ftp_conntrack_ip modules because I have no idea what the problem is anymore :evil:
_________________
RYZEN 5 3600 Matisse (Zen 2) 6-Core 3.6 GHz Socket AM4 65W
ASRock B550M PRO4
Crucial Ballistix 3200 MHz DDR4 DRAM 16GB
EVGA GeForce GTX 1060 6GB
Back to top
View user's profile Send private message
asterix404
Apprentice
Apprentice


Joined: 05 Nov 2004
Posts: 213

PostPosted: Sat Dec 11, 2004 5:04 am    Post subject: Reply with quote

Ahh... well there is good new yet, sorry about that... actuilly the module was not installed before but now I have this:

/lib/modules/2.6.9-gentoo-r9/kernel/net/ipv4/netfilter/ip_conntrack_irc.ko
/lib/modules/2.6.9-gentoo-r9/kernel/net/ipv4/netfilter/ip_conntrack_tftp.ko
which I think I can use autoload to boot up... and prey this works... is there a way to see what packets are doing when they hit my routers? Like when I do ftp open "my ip" can I see what the packets are doing and trace them?

I know the porblem now but I have no idea how to fix it and hopefully someone out there does. I can access the ftp anywhere on my lan, the porblem is the outside... the other problem is I have a wireless router conected to the ouside world. It is a linksys, this must be the problem. Unde aplications and gaming I have this

ftp 61000 to 62000 TCP 192.168.10.100 where 10.100 is another router
ftp 19 to 22 TCP 192.168.10.100

I have nothing under port triggering i have nothing under DMZ host

I have UPnP enabled

I think I now know that is is a problem with the router and I wil have to fiddle around with my network tomm... thank you so much though, and if this does get fixed I will be sure to keep you posted... if you care enough... however you seem to
Back to top
View user's profile Send private message
pharaoh
Apprentice
Apprentice


Joined: 20 Nov 2003
Posts: 211
Location: Pennsylvania

PostPosted: Sat Dec 11, 2004 2:58 pm    Post subject: Reply with quote

Just to make sure it's one of the routers being the issue, can you just not use the routers for a short time to test it? I realize there's a security risk involved, but for how much time you've been putting into this it may just be easiest to change the net settings on the ftp server and run it directly to your internet hookup to find out if it really is one of the routers being the problem. Either way, do let us know what happens :)
_________________
RYZEN 5 3600 Matisse (Zen 2) 6-Core 3.6 GHz Socket AM4 65W
ASRock B550M PRO4
Crucial Ballistix 3200 MHz DDR4 DRAM 16GB
EVGA GeForce GTX 1060 6GB
Back to top
View user's profile Send private message
asterix404
Apprentice
Apprentice


Joined: 05 Nov 2004
Posts: 213

PostPosted: Sat Dec 11, 2004 7:28 pm    Post subject: Reply with quote

It was in fact the router... AS A HEUGE NOTE for anyone folowing this... if you loose power and it comes back up and it seems like nothing had happend... it did. If your routers still say they are doing what they are doing... they really are not. No port forwarding was occuring and I had about half services. It didn't like the reset and i had to do it about 3 times... but it finially hooked... thanks a lot pharaoh and sean_micken it works great. What else can I run from xinted now that I know this is a very powerful tool... samba? net.eth0?
Back to top
View user's profile Send private message
pharaoh
Apprentice
Apprentice


Joined: 20 Nov 2003
Posts: 211
Location: Pennsylvania

PostPosted: Mon Dec 13, 2004 3:08 am    Post subject: Reply with quote

Glad to hear it's working :D As for xinetd, I only use it to run swat and vsftpd. But if you poke around I'm sure you'll find some other services to do with it. Good luck bud!
_________________
RYZEN 5 3600 Matisse (Zen 2) 6-Core 3.6 GHz Socket AM4 65W
ASRock B550M PRO4
Crucial Ballistix 3200 MHz DDR4 DRAM 16GB
EVGA GeForce GTX 1060 6GB
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Goto page Previous  1, 2
Page 2 of 2

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum