[geeks] RANT (ftp)

der Mouse mouse at Rodents.Montreal.QC.CA
Tue Oct 24 16:07:51 CDT 2006


>> Any case where someone finds making FTP to work through a firewall
>> to be a black art is, I believe, one where that person does not
>> really understand FTP, the firwall, or both.
> Or they're using the wrong firewall.

But if the person is using the wrong filerwall but thoroughly
understands it, there's no black art; it just doesn't work.

> SonicWALLs, Cisco firewall solutions (IOS routers with the firewall
> feature set, PIXes, ASA5500s) and many more offer application-layer
> inspection of FTP streams.

> End result is FTP Just Works.

...until you run it on an unusual port, or TLS-secure the control
connection, or something.  This doesn't fix the problem; it just papers
over the worst of the symptoms.

/~\ The ASCII				der Mouse
\ / Ribbon Campaign
 X  Against HTML	       mouse at rodents.montreal.qc.ca
/ \ Email!	     7D C8 61 52 5D E7 2D 39  4E F1 31 3E E8 B3 27 4B



More information about the geeks mailing list