[geeks] DHCP silliness

Kurt Mosiejczuk geeks at sunhelp.org
Mon Nov 26 09:28:27 CST 2001


On Sat, 24 Nov 2001, Peter L. Wargo wrote:

> (All of basenji.com sits behind one NAT address, and incoming ports are
> routed to the system running the appropriate service.  All internal
> systems ('bout 9 of them) use one box for DNS.)

How do you handle people trying to do passive FTP?  You then don't have
a known port to forward for the data connection...

I mainly ask because I've run into this before multiple times... once I
solved it by making the FTP server a hardened box and throwing it to the
wolves outside the firewall. =)

--Kurt




More information about the geeks mailing list