Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game. |
Notices |
Welcome to LinuxQuestions.org, a friendly and active Linux Community.
You are currently viewing LQ as a guest. By joining our community you will have the ability to post topics, receive our newsletter, use the advanced search, subscribe to threads and access many other special features. Registration is quick, simple and absolutely free. Join our community today!
Note that registered members see fewer ads, and ContentLink is completely disabled once you log in.
Are you new to LinuxQuestions.org? Visit the following links:
Site Howto |
Site FAQ |
Sitemap |
Register Now
If you have any problems with the registration process or your account login, please contact us. If you need to reset your password, click here.
Having a problem logging in? Please visit this page to clear all LQ-related cookies.
Get a virtual cloud desktop with the Linux distro that you want in less than five minutes with Shells! With over 10 pre-installed distros to choose from, the worry-free installation life is here! Whether you are a digital nomad or just looking for flexibility, Shells can put your Linux machine on the device that you want to use.
Exclusive for LQ members, get up to 45% off per month. Click here for more info.
|
 |
08-25-2005, 08:29 PM
|
#1
|
Member
Registered: Oct 2003
Location: Ohio , USA
Distribution: up to Suse 15.1
Posts: 73
Rep:
|
ftp server issue
Hi,
if you read other posts, I lost my NAT this year to a raccon.
I since was able to get SuseFirewall back so that my internal can go out and to the DMZ.
I have a web server in the DMZ and it doubles as an ftp server for internal ( for Suse installs ).
Web works fine from internal and external.
I can browse fine from the DMZ.
I can ftp ( smartftp from a windows box ) and update my web site from internal.
I cannot , however get my ftp install to work. I ran iptraf to monitor. I can ping the machine from the DMZ to the internal and I can ping the ftp server from the internal. ( testing reasons )
I had noticed that my smartftp was taking a bit longer to connect but did not have the time to investigate before.
What I see is this, on iptraf on the web/ftp server, I see the machine attempt to connect and I see a high ( 30K + ) port set up. The installation times out however. ( if I use a false name / password or such I get dropped right away, so I believe they make connection )
I tried smartftp while I was watching iptraf, it tries a high port as well and waits, it then drops PASV and tries a lower port, say 1200 or so. It then connects and I am fine. ( explains my delay somewhat )
The installation must not make an attempt to go to a lower port.
What do I need to look for?
hmmm, never thought to try and internal link to the web to see what kind of port I get there.
Thoughts please?
Thx
Mike
|
|
|
08-25-2005, 11:26 PM
|
#2
|
Member
Registered: Jan 2003
Distribution: many win/nix/mac
Posts: 259
Rep:
|
I'm a little lost, thats easy to do.
What ftp server are you using? What client? And maybe a little clearer topography of your network.
It may be just a matter of setting up your firewall to allow traffic on some high ports so the clients can make passive connections. Your ftp server may need to set up a little different.
Thanks
dan
|
|
|
08-31-2005, 09:40 AM
|
#3
|
Member
Registered: Oct 2003
Location: Ohio , USA
Distribution: up to Suse 15.1
Posts: 73
Original Poster
Rep:
|
I use the Suse / Yast to set up the ftp server. I believe it is vsftp.
What of the topology would you like to know?
eth0 is external,
eth1 is internal,
eth2 is DMZ.
The ftp server is in the DMZ ( I want to later be able to use it external as well and it is on my web server ).
I update the web site from internal, connecting with smartftp on a windows machine. Itg connects but is slow about it because it drops to a lower port before a real connection is established.
The other ftp conection is with the Suse installation option to install via ftp. I have no idea what they use. I do see the request on the ftp server ( via iptraf ) but whereas the smartftp drops to a lower port and goes on, the install does not.
If I use an incorrect name or file path, I am dropped right away from the ftp server so I know they are communicating. They just are not able to connect at the high port and the install program doen not drop to a low port to try.
I do not want toi fix the install program, I want to know why they cannot connect on the high port.
Thanks
Mike
|
|
|
09-10-2005, 01:09 AM
|
#4
|
Member
Registered: Oct 2003
Location: Ohio , USA
Distribution: up to Suse 15.1
Posts: 73
Original Poster
Rep:
|
Is there a simple method for testing port connections both directions ? ( from and to the DMZ from and to the internal ) I must have something set wrong in the NAT firewall because it did work at one time.
I am still a noob at this
mike
|
|
|
09-15-2005, 11:25 PM
|
#5
|
Member
Registered: Oct 2003
Location: Ohio , USA
Distribution: up to Suse 15.1
Posts: 73
Original Poster
Rep:
|
Also,
I thought 1024 was the high / low port line. Why is it that I can get connection in the 1400 to 1700 range but not higher?
I need to know what more you need to know about the set up. I think the ftp deamon is vsftp. From a Suse 9.0 installation.
Thanks Mike
|
|
|
All times are GMT -5. The time now is 09:39 AM.
|
LinuxQuestions.org is looking for people interested in writing
Editorials, Articles, Reviews, and more. If you'd like to contribute
content, let us know.
|
Latest Threads
LQ News
|
|