From: William Chen (kwchen@netvigator.com)
Date: Thu Feb 26 2004 - 21:14:01 GMT-3
Dear all,
In all the examples of passive FTP in the book of Ptractical Studies Vol.
2. It states that to match the passive FTP traffic by ACL to a server, the
ACL should be:
1. permit ip tcp any host x.x.x.x ftp
2. permit ip tcp any host x.x.x.x gt 1023 established
I wonder why established is used in the statement 2, since in passive
FTP, the data channel should be initiated by the client to server at a port
greater than 1023.
Best Regards,
William Chen
This archive was generated by hypermail 2.1.4 : Fri Mar 05 2004 - 07:13:57 GMT-3