Re: [squid-users] FTP and PASV Unsafe Messages?

From: Marc Elsen <marc.elsen@dont-contact.us>
Date: Thu, 19 Sep 2002 16:22:09 +0200

Alex Short wrote:
>
> I'm running SQUID 2.5 PRE13 and when trying to download .exe's from the
> following url http://209.167.114.38/support/Downloads/index.html (i
> selected Tecra->8200 Series then any filename) and tried to download an
> executable ftp://ftp.toshiba.ca/models/t8200/T820BMWD.exe I get:
>
> The requested URL could not be retrieved
>
> --------------------------------------------------------------------------------
>
> An FTP protocol error occurred while trying to retrieve the URL:
> ftp://ftp.toshiba.ca/models/t8200/T820BMWD.exe
>
> Squid sent the following FTP command:
>
> RETR T820BMWD.exe
>
> and then received this reply
> PORT command successful.
>
> In my cache logs i get :
>
> 2002/09/19 08:25:54| Unsafe PASV reply from 209.167.114.38: Entering
> Passive Mode (10,117,1,1,49,142)
>
> Any idea how/what/where to fix this error?
>
> Thanks
> Alex

 From the 2.5 rel notes :

Squid now sanity checks FTP data connections to ensure the connection is
from the requested server. Can be disabled
if needed by turning off the ftp_sanitycheck option.

OR, passive mode ftp may be incompatible with your fw. sec. policy
setup.
There is another TAG in squid.conf related to this issue :

ftp_passive , which is defaulted to on.

You may want to experiment with both parameters in your case...

M.

-- 
 'Time is a consequence of Matter thus
 General Relativity is a direct consequence of QM
 (M.E. Mar 2002)
Received on Thu Sep 19 2002 - 08:22:12 MDT

This archive was generated by hypermail pre-2.1.9 : Tue Dec 09 2003 - 17:10:21 MST