EPSV/EPRT support

From: Henrik Nordström <henrik_at_henriknordstrom.net>
Date: Wed, 15 Sep 2010 15:28:04 +0200

tis 2010-09-14 klockan 01:23 +0000 skrev Amos Jeffries:

> * Squid should be starting with EPSV not EPRT anyway. Check that your
> ftp_pasv directive is set to "on" (default), or remove it from the config
> altogether.

Shouldn't we start with PASV if it's a IPv4 connection?

There is no big need for EPSV/EPRT in IPv4, and many NATs and Firewalls
have issues tracking the E* requests/responses.

Sure, they are designed to actually be easier for NATs and Firewalls,
and they are, but things do fail if the directives are not understood.

The old PASV/PORT commands are well known for ages, and supported by
virtually every device out there.

This problem is seen on both client and server sides, for both EPSV and
EPRT.

Yes, it's somewhat depressing to still frequently see these issues when
the EPSV and EPRT directives have been official standards track changes
to the FTP protocol for over a decade (1998), but that's the reality of
Internet.

Regards
Henrik
Received on Wed Sep 15 2010 - 13:28:08 MDT

This archive was generated by hypermail 2.2.0 : Wed Sep 15 2010 - 12:00:06 MDT