<?xml version="1.0" encoding="UTF-8"?><rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
> <channel><title>Comments on: BSD FTP-Proxy: PF Firewall Allow Outgoing Active / Passive FTP Connections</title> <atom:link href="http://www.cyberciti.biz/faq/freebsd-opebsd-pf-firewall-ftp-configuration/feed/" rel="self" type="application/rss+xml" /><link>http://www.cyberciti.biz/faq/freebsd-opebsd-pf-firewall-ftp-configuration/</link> <description>Every answer asks a more beautiful question.</description> <lastBuildDate>Fri, 10 Feb 2012 19:55:56 +0000</lastBuildDate> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <item><title>By: Hasse</title><link>http://www.cyberciti.biz/faq/freebsd-opebsd-pf-firewall-ftp-configuration/#comment-66489</link> <dc:creator>Hasse</dc:creator> <pubDate>Sat, 07 Jan 2012 19:07:36 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/faq/?p=1284#comment-66489</guid> <description>Thanks
As usual, it&#039;s a pleasure following your tutorials. They simply works.</description> <content:encoded><![CDATA[<p>Thanks<br
/> As usual, it&#8217;s a pleasure following your tutorials. They simply works.</p> ]]></content:encoded> </item> <item><title>By: Ben Francom</title><link>http://www.cyberciti.biz/faq/freebsd-opebsd-pf-firewall-ftp-configuration/#comment-51115</link> <dc:creator>Ben Francom</dc:creator> <pubDate>Thu, 25 Nov 2010 12:29:24 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/faq/?p=1284#comment-51115</guid> <description>Thanks for the great article, and explanation.  The comments are also very informative.  It helped me recently with an instance of PF, FreeBSD  and FTP.</description> <content:encoded><![CDATA[<p>Thanks for the great article, and explanation.  The comments are also very informative.  It helped me recently with an instance of PF, FreeBSD  and FTP.</p> ]]></content:encoded> </item> <item><title>By: stiv</title><link>http://www.cyberciti.biz/faq/freebsd-opebsd-pf-firewall-ftp-configuration/#comment-46640</link> <dc:creator>stiv</dc:creator> <pubDate>Wed, 31 Mar 2010 10:09:06 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/faq/?p=1284#comment-46640</guid> <description>Thank you for good article.
But if I use  the rule
# keep stats of outging connections
pass out keep state
I don&#039;t need any other rules such as
# Allow outgoing via ssh, smtp, domain, www, https, whois etc
pass out on $ext_if proto tcp to any port $tcp_services
pass out on $ext_if proto udp to any port $udp_services</description> <content:encoded><![CDATA[<p>Thank you for good article.<br
/> But if I use  the rule<br
/> # keep stats of outging connections<br
/> pass out keep state<br
/> I don&#8217;t need any other rules such as<br
/> # Allow outgoing via ssh, smtp, domain, www, https, whois etc<br
/> pass out on $ext_if proto tcp to any port $tcp_services<br
/> pass out on $ext_if proto udp to any port $udp_services</p> ]]></content:encoded> </item> <item><title>By: Vivek Gite</title><link>http://www.cyberciti.biz/faq/freebsd-opebsd-pf-firewall-ftp-configuration/#comment-44515</link> <dc:creator>Vivek Gite</dc:creator> <pubDate>Mon, 09 Nov 2009 05:43:47 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/faq/?p=1284#comment-44515</guid> <description>@ Colin
Thanks for the heads up!</description> <content:encoded><![CDATA[<p>@ Colin</p><p>Thanks for the heads up!</p> ]]></content:encoded> </item> <item><title>By: Colin</title><link>http://www.cyberciti.biz/faq/freebsd-opebsd-pf-firewall-ftp-configuration/#comment-44504</link> <dc:creator>Colin</dc:creator> <pubDate>Sun, 08 Nov 2009 20:26:30 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/faq/?p=1284#comment-44504</guid> <description>Hi Vivek,
I think there is an error here:
# pfctl -nf /etc/rc.conf
# pfctl -f /etc/rc.conf
Should be this:
# pfctl -nf /etc/pf.conf
# pfctl -f /etc/pf.conf
In any case, thanks for a useful page and a very useful site. I keep coming back.
-Colin</description> <content:encoded><![CDATA[<p>Hi Vivek,</p><p>I think there is an error here:</p><p># pfctl -nf /etc/rc.conf<br
/> # pfctl -f /etc/rc.conf</p><p>Should be this:<br
/> # pfctl -nf /etc/pf.conf<br
/> # pfctl -f /etc/pf.conf</p><p>In any case, thanks for a useful page and a very useful site. I keep coming back.</p><p>-Colin</p> ]]></content:encoded> </item> <item><title>By: SIFE</title><link>http://www.cyberciti.biz/faq/freebsd-opebsd-pf-firewall-ftp-configuration/#comment-43870</link> <dc:creator>SIFE</dc:creator> <pubDate>Mon, 28 Sep 2009 12:54:25 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/faq/?p=1284#comment-43870</guid> <description>Salamo Alikom
@Vivek Gite
this rules you had sets it fix my problem , thx.</description> <content:encoded><![CDATA[<p>Salamo Alikom<br
/> @Vivek Gite<br
/> this rules you had sets it fix my problem , thx.</p> ]]></content:encoded> </item> <item><title>By: John</title><link>http://www.cyberciti.biz/faq/freebsd-opebsd-pf-firewall-ftp-configuration/#comment-43019</link> <dc:creator>John</dc:creator> <pubDate>Tue, 11 Aug 2009 10:26:42 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/faq/?p=1284#comment-43019</guid> <description>@Vivek
Thanks, that would make sense. Unfortunately it also means that my block out rule is essentially rendered useless. A few people here use personal laptops with the BBC iPlayer installed which can eat bandwidth. By only allowing out required traffic, it makes life a lot easier.
Any chance I can keep my cake and eat it :-)</description> <content:encoded><![CDATA[<p>@Vivek<br
/> Thanks, that would make sense. Unfortunately it also means that my block out rule is essentially rendered useless. A few people here use personal laptops with the BBC iPlayer installed which can eat bandwidth. By only allowing out required traffic, it makes life a lot easier.<br
/> Any chance I can keep my cake and eat it :-)</p> ]]></content:encoded> </item> <item><title>By: Vivek Gite</title><link>http://www.cyberciti.biz/faq/freebsd-opebsd-pf-firewall-ftp-configuration/#comment-43018</link> <dc:creator>Vivek Gite</dc:creator> <pubDate>Tue, 11 Aug 2009 10:11:00 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/faq/?p=1284#comment-43018</guid> <description>@John,
Try:
&lt;pre&gt;pass out on $ext_if inet proto tcp from any to any port ftp
pass out on $ext_if inet proto tcp from any to any port &gt;1023&lt;/pre&gt;</description> <content:encoded><![CDATA[<p>@John,</p><p>Try:</p><pre>pass out on $ext_if inet proto tcp from any to any port ftp
pass out on $ext_if inet proto tcp from any to any port >1023</pre>]]></content:encoded> </item> <item><title>By: John</title><link>http://www.cyberciti.biz/faq/freebsd-opebsd-pf-firewall-ftp-configuration/#comment-43017</link> <dc:creator>John</dc:creator> <pubDate>Tue, 11 Aug 2009 09:57:26 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/faq/?p=1284#comment-43017</guid> <description>I&#039;ve got ftp-proxy working on my firewall for all the clients behind it. However I can&#039;t ftp (using Active or Passive) from the actual firewall itself, which is making installing/upgrading ports tedious.
For example:
#pkg_add -r ftp://ftp.freebsd.org/pub/FreeBSD/ports/i386/packages-7.2-release/Latest/ifstated.tbz
Error: FTP Unable to get ftp://ftp.freebsd.org/pub/FreeBSD/ports/i386/packages-7.2-release/Latest/ifstated.tbz: Operation not permitted
pkg_add: unable to fetch &#039;ftp://ftp.freebsd.org/pub/FreeBSD/ports/i386/packages-7.2-release/Latest/ifstated.tbz&#039; by URL
I&#039;m guessing that this is because no redirection is being done as the request is being sent straight out the default route interface (I verified this by pausing the pkg_add command, and executing netstat -f inet &#124; grep ftp).
Any suggestions as to how I can get around this. Surely this is something that others have encountered.</description> <content:encoded><![CDATA[<p>I&#8217;ve got ftp-proxy working on my firewall for all the clients behind it. However I can&#8217;t ftp (using Active or Passive) from the actual firewall itself, which is making installing/upgrading ports tedious.</p><p>For example:<br
/> #pkg_add -r <a
href="ftp://ftp.freebsd.org/pub/FreeBSD/ports/i386/packages-7.2-release/Latest/ifstated.tbz" rel="nofollow">ftp://ftp.freebsd.org/pub/FreeBSD/ports/i386/packages-7.2-release/Latest/ifstated.tbz</a><br
/> Error: FTP Unable to get <a
href="ftp://ftp.freebsd.org/pub/FreeBSD/ports/i386/packages-7.2-release/Latest/ifstated.tbz" rel="nofollow">ftp://ftp.freebsd.org/pub/FreeBSD/ports/i386/packages-7.2-release/Latest/ifstated.tbz</a>: Operation not permitted<br
/> pkg_add: unable to fetch &#8216;<a
href="ftp://ftp.freebsd.org/pub/FreeBSD/ports/i386/packages-7.2-release/Latest/ifstated.tbz" rel="nofollow">ftp://ftp.freebsd.org/pub/FreeBSD/ports/i386/packages-7.2-release/Latest/ifstated.tbz</a>&#8216; by URL</p><p>I&#8217;m guessing that this is because no redirection is being done as the request is being sent straight out the default route interface (I verified this by pausing the pkg_add command, and executing netstat -f inet | grep ftp).<br
/> Any suggestions as to how I can get around this. Surely this is something that others have encountered.</p> ]]></content:encoded> </item> <item><title>By: John Dakos</title><link>http://www.cyberciti.biz/faq/freebsd-opebsd-pf-firewall-ftp-configuration/#comment-42590</link> <dc:creator>John Dakos</dc:creator> <pubDate>Fri, 17 Jul 2009 13:06:38 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/faq/?p=1284#comment-42590</guid> <description>Good Job  Man :)  This Tutorial  Help Me To Understand  Ftp-Proxy and RDR. Thanks</description> <content:encoded><![CDATA[<p>Good Job  Man :)  This Tutorial  Help Me To Understand  Ftp-Proxy and RDR. Thanks</p> ]]></content:encoded> </item> </channel> </rss>
