[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: issue with ftp-proxy and IP aliases
- To: misc_(_at_)_openbsd_(_dot_)_org
- Subject: Re: issue with ftp-proxy and IP aliases
- From: Luis Cerdas <luis_(_dot_)_cerdas_(_at_)_rawten_(_dot_)_net>
- Date: Fri, 16 May 2003 10:42:08 -0600
- Cc: "James J. Lippard" <lippard-openbsd_(_at_)_discord_(_dot_)_org>
I had a similar problem where I needed to specify which IP address
ftp-proxy should use, but received no reply from anybody on the list...
On Friday, May 16, 2003, at 10:28 AM, James J. Lippard wrote:
My home network has a firewall with two IP addresses, one is the
external address used with NAT for my internal network as a whole, the
is an external address used with binat for a particular machine.
The IP address for the binat is numerically lower (.38) than the main
address (.100, same subnet).
The /etc/hostname.if file contains .100 as the primary address and .38
I run ftp-proxy with -n on the firewall. Specifically,
127.0.0.1:8021 stream tcp nowait root
/usr/libexec/ftp-proxy ftp-proxy -n -w -r
The three key pf.conf rules are:
nat on $ext_if from $INT_NET to any -> <.100 address>
rdr on $int_if proto tcp from any to any port ftp -> 127.0.0.1 port
binat on $ext_if from <special machine ip> to any -> <.38 address>
Up until OpenBSD 3.3, I had no problems with this setup. Now, however,
I run into the following problem when attempting to FTP from any
on the internal network other than the binatted machine:
If a passive FTP connection is used, the data connection comes from the
numerically lower external IP address on the firewall (.38) rather than
the primary IP (.100), which means that passive FTP no longer works.
control connection still comes from .100 as expected, but there's a
mismatch between the data and control connections.
Has anyone encountered this problem before? Is there a solution that
doesn't require making the lower IP the primary address?
It appears to me that the problem is that where .38 used to be listed
as an alias and as the second IP on the interface, it is now listed
as the first IP on the interface and ifconfig doesn't identify either
IP as an "alias".
Jim Lippard lippard_(_at_)_discord_(_dot_)_org http://www.discord.org/
GPG Key ID: 0xF8D42CFE
Visit your host, monkey.org