[lug] VSFTP stopped working recently

John Hernandez jph at jph.net
Fri Nov 2 14:51:12 MDT 2012


Hey Richard, here's an idea.

Is there is NAT and/or stateful firewall (iptables?) in front of the
FTP server?   If so, there might also be a "helper" (conntrack) in
place to facilitate forwarding the passive-mode data connection back
to the server.  That helper may be not be configured to recognize
control conversations on ports other than 21.

On Fri, Nov 2, 2012 at 1:17 PM, Richard Mandel
<richard at linuxsupportguys.com> wrote:
> VSFTPD has been fixed by going back to the default FTP port 21. No matter
> what I did, it just didn't seem to run properly with any ports other than
> default 21. At best it would run with alternative an port, but PASV mode
> would not work.
>
> I gave up, and now it is fine on port 21, BUT all those guys trying to break
> in to an ftp server are back.
>
> Richard Mandel
> Linux Support Guys
>
> richard at linuxsupportguys.com
> Phone, Mobile and SMS: +1-303-499-1525
>
>
> -----Original Message-----
> From: lug-bounces at lug.boulder.co.us [mailto:lug-bounces at lug.boulder.co.us]
> On Behalf Of David L. Anselmi
> Sent: Friday, November 02, 2012 12:45 PM
> To: Boulder (Colorado) Linux Users Group -- General Mailing List
> Subject: Re: [lug] VSFTP stopped working recently
>
> Richard Mandel wrote:
>> 1) there was a second firewall active that I didn't even know was
>> there. It had no entry for the non-standard port I was trying to use
>> for FTP. I disabled this second firewall.
>
> Does that mean you've fixed the previous problem and VSFTP runs reliably
> now?  Firewalls have nothing to do with that.
>
> Dave
> _______________________________________________
> Web Page:  http://lug.boulder.co.us
> Mailing List: http://lists.lug.boulder.co.us/mailman/listinfo/lug
> Join us on IRC: irc.hackingsociety.org port=6667 channel=#hackingsociety
>
> _______________________________________________
> Web Page:  http://lug.boulder.co.us
> Mailing List: http://lists.lug.boulder.co.us/mailman/listinfo/lug
> Join us on IRC: irc.hackingsociety.org port=6667 channel=#hackingsociety



More information about the LUG mailing list