From bounce-fwtk-users-303@listserv.nai.com Mon May  6 08:14 EDT 2002
Received: from sentry.gw.tislabs.com (firewall-user@sentry.gw.tislabs.com [192.94.214.100])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id IAA05422
	Mon, 6 May 2002 08:14:56 -0400 (EDT)
Received: by sentry.gw.tislabs.com; id IAA29707; Mon, 6 May 2002 08:33:42 -0400 (EDT)
Received: from listserv.nai.com(161.69.213.6) by sentry.gw.tislabs.com via smap (V5.5)
	id xma029692; Mon, 6 May 02 08:33:01 -0400
Subject: [fwtk-users] proxying to an ftp server using a non standard port
To: "fwtk-users" <fwtk-users@listserv.nai.com>
X-Mailer: Lotus Notes Release 5.0.4a  July 24, 2000
Message-ID: <LISTMANAGER-303-564-2002.05.06-07.17.44--fwtk-archive#lists.tislabs.com@listserv.nai.com>
From: czeritis@agl.com.au
Date: Fri, 3 May 2002 18:38:38 +1000
X-MIMETrack: Serialize by Router on GLAMT001/AGLExternal(Release 5.0.6a |January 17, 2001) at
 05/03/2002 06:41:56 PM
MIME-Version: 1.0
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain; charset="us-ascii"
Content-Length: 1704
Status: RO

I am trying to use ftp-gw as a reverse proxy within my dmz so that external
clients can ftp to the proxy and their requests can be relayed to an
internal ftp server.
The issue is that the internal ftp server is using a non standard port for
the control channel (i.e. not 21)

Ideally i would like to have ftp-gw listening on port 21 and then when a
request comes in to be able to connect to an internal server that is
listening to another port.

I have so far tried two approaches -

first is running the default setup when a client connects to the proxy and
then specifies a user as <username>@<hostname>. (This doesn't pose too many
security holes as there is a firewall between the proxy and the internal
network so there is not way of connecting to another server other than the
intended one). Anyway it seems that there is no way in specifying a
specific port this way.

second approach was to install the "plug capability" patch written by Kevin
P. Fleming that allows a reverse proxy type configuration. This works great
as a reverse proxy! but it seems it still doesn't allow a port definition
either.

Is there any way to achieve my desired result?

thanks in advance



**********************************************************************
This  email  is  intended  solely  for the use of the addressee
and may contain information that is confidential or privileged.
If you receive this email in error please notify the sender and
delete the email immediately.
**********************************************************************


---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Mon May  6 08:17 EDT 2002
Received: from sentry.gw.tislabs.com (firewall-user@sentry.gw.tislabs.com [192.94.214.100])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id IAA05426
	Mon, 6 May 2002 08:17:56 -0400 (EDT)
Received: by sentry.gw.tislabs.com; id IAA29742; Mon, 6 May 2002 08:36:42 -0400 (EDT)
Received: from listserv.nai.com(161.69.213.6) by sentry.gw.tislabs.com via smap (V5.5)
	id xma029731; Mon, 6 May 02 08:36:38 -0400
Subject: [fwtk-users] proxying to an ftp server using a non standard port
To: "fwtk-users" <fwtk-users@listserv.nai.com>
X-Mailer: Lotus Notes Release 5.0.4a  July 24, 2000
Message-ID: <LISTMANAGER-303-566-2002.05.06-07.18.44--fwtk-archive#lists.tislabs.com@listserv.nai.com>
From: czeritis@agl.com.au
Date: Mon, 6 May 2002 10:08:24 +1000
X-MIMETrack: Serialize by Router on GLAMT001/AGLExternal(Release 5.0.6a |January 17, 2001) at
 05/06/2002 10:11:46 AM
MIME-Version: 1.0
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain; charset="us-ascii"
Content-Length: 1711
Status: RO

Hi,

I am trying to use ftp-gw as a reverse proxy within my dmz so that external
clients can ftp to the proxy and their requests can be relayed to an
internal ftp server.
The issue is that the internal ftp server is using a non standard port for
the control channel (i.e. not 21)

Ideally i would like to have ftp-gw listening on port 21 and then when a
request comes in to be able to connect to an internal server that is
listening to another port.

I have so far tried two approaches -

first is running the default setup when a client connects to the proxy and
then specifies a user as <username>@<hostname>. (This doesn't pose too many
security holes as there is a firewall between the proxy and the internal
network so there is not way of connecting to another server other than the
intended one). Anyway it seems that there is no way in specifying a
specific port this way.

second approach was to install the "plug capability" patch written by Kevin
P. Fleming that allows a reverse proxy type configuration. This works great
as a reverse proxy! but it seems it still doesn't allow a port definition
either.

Is there any way to achieve my desired result?

thanks in advance





**********************************************************************
This  email  is  intended  solely  for the use of the addressee
and may contain information that is confidential or privileged.
If you receive this email in error please notify the sender and
delete the email immediately.
**********************************************************************


---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Mon May  6 08:21 EDT 2002
Received: from sentry.gw.tislabs.com (firewall-user@sentry.gw.tislabs.com [192.94.214.100])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id IAA05430
	Mon, 6 May 2002 08:21:04 -0400 (EDT)
Received: by sentry.gw.tislabs.com; id IAA00060; Mon, 6 May 2002 08:39:51 -0400 (EDT)
Received: from listserv.nai.com(161.69.213.6) by sentry.gw.tislabs.com via smap (V5.5)
	id xma000048; Mon, 6 May 02 08:39:44 -0400
X-Originating-IP: [202.56.242.111]
From: "Sonal Merchant" <sonalmerchant@hotmail.com>
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] Setting up FTP server & ftp-gw on same machine
Date: Sun, 05 May 2002 13:06:28 +0530
Mime-Version: 1.0
Message-ID: <LISTMANAGER-303-565-2002.05.06-07.17.45--fwtk-archive#lists.tislabs.com@listserv.nai.com>
X-OriginalArrivalTime: 05 May 2002 07:36:29.0012 (UTC) FILETIME=[91BD1140:01C1F407]
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain; format=flowed
Content-Length: 570
Status: RO

I want to set up a Ftp server on the same machine running ftp-gw. According 
to the manual pages, I should compile the ftp daemon in 
/fwtk/tools/server/ftpd directory with PROXY_PASSTHROUGH option. Can anyone 
give me the guidelines for the compilation?







_________________________________________________________________
Join the world’s largest e-mail service with MSN Hotmail. 
http://www.hotmail.com


---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Mon May  6 17:42 EDT 2002
Received: from sentry.gw.tislabs.com (firewall-user@sentry.gw.tislabs.com [192.94.214.100])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id RAA07219
	Mon, 6 May 2002 17:42:55 -0400 (EDT)
Received: by sentry.gw.tislabs.com; id SAA12919; Mon, 6 May 2002 18:01:42 -0400 (EDT)
Received: from listserv.nai.com(161.69.213.6) by sentry.gw.tislabs.com via smap (V5.5)
	id xma012914; Mon, 6 May 02 18:01:23 -0400
Message-Id: <LISTMANAGER-303-567-2002.05.06-16.46.14--fwtk-archive#lists.tislabs.com@listserv.nai.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 5.1
Date: Mon, 06 May 2002 17:47:21 -0400
To: "fwtk-users" <fwtk-users@listserv.nai.com>
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: [fwtk-users] Re: proxying to an ftp server using a non
  standard port
In-Reply-To: <LISTMANAGER-602-566-2002.05.06-07.18.44--rmurphy#itm-inst.
 com@listserv.nai.com>
Mime-Version: 1.0
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 1064
Status: RO

At 10:08 AM 5/6/02 +1000, czeritis@agl.com.au wrote:
>Hi,
>
>I am trying to use ftp-gw as a reverse proxy within my dmz so that external
>clients can ftp to the proxy and their requests can be relayed to an
>internal ftp server.
>The issue is that the internal ftp server is using a non standard port for
>the control channel (i.e. not 21)
>
>Ideally i would like to have ftp-gw listening on port 21 and then when a
>request comes in to be able to connect to an internal server that is
>listening to another port.

OK, the easiest way to do this is to modify the ftp-gw source at function 
cmd_user.
It defaults the port to 21 (short port = FTPPORT); change that from FTPPORT 
to whatever port you need.

You can't use plug-gw for ftp since FTP has two connections; plug-gw has no 
knowledge of the data channel and won't set up a listener for the data 
traffic - ftp-gw knows to do that.
         -Rick


---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Thu May  9 14:53 EDT 2002
Received: from sentry.gw.tislabs.com (firewall-user@sentry.gw.tislabs.com [192.94.214.100])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id OAA19327
	Thu, 9 May 2002 14:53:11 -0400 (EDT)
Received: by sentry.gw.tislabs.com; id PAA07902; Thu, 9 May 2002 15:12:04 -0400 (EDT)
Received: from listserv.nai.com(161.69.213.6) by sentry.gw.tislabs.com via smap (V5.5)
	id xma007894; Thu, 9 May 02 15:11:26 -0400
Message-ID: <LISTMANAGER-303-570-2002.05.09-13.55.43--fwtk-archive#lists.tislabs.com@listserv.nai.com>
From: Fritsch Jonathan D CONT PSNS <fritschj@PSNS.navy.mil>
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] Ports
Date: Thu, 9 May 2002 12:02:50 -0700 
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2653.19)
X-N-Score: scored -400
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 336
Status: RO

How can I open and close port on fwtk.  For example port 1863 inbound or
outbound only.


Jonathan D Fritsch
SRA Int. - PSNS IT Configuration Mgmt.
Code 1233.24 (360) 476-0019


---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Thu May  9 19:15 EDT 2002
Received: from sentry.gw.tislabs.com (firewall-user@sentry.gw.tislabs.com [192.94.214.100])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id TAA19870
	Thu, 9 May 2002 19:15:50 -0400 (EDT)
Received: by sentry.gw.tislabs.com; id TAA14124; Thu, 9 May 2002 19:34:41 -0400 (EDT)
Received: from listserv.nai.com(161.69.213.6) by sentry.gw.tislabs.com via smap (V5.5)
	id xma014118; Thu, 9 May 02 19:33:57 -0400
Message-Id: <LISTMANAGER-303-571-2002.05.09-18.18.40--fwtk-archive#lists.tislabs.com@listserv.nai.com>
X-Mailer: exmh version 2.5 07/13/2001 with nmh-1.0.4
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] Outgoing pop-gw allowing choice of mail server.
Mime-Version: 1.0
Date: Fri, 10 May 2002 09:27:51 +1000
From: Ian Mortimer <ian@physics.uq.edu.au>
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain; charset=us-ascii
Content-Length: 1136
Status: RO

A network behind an fwtk firewall has been using the pop-gw written by 
Eberhard Mattes to collect mail from an external mail server.  Some of the 
group now need to collect their mail from a different mail server but the 
pop-gw has no provision for that and doesn't support the user@host syntax.

pop3-gw from the fwtk site does support the user@host syntax but it tries to 
use apop by default and then falls back to pop if apop fails and it doesn't 
allow you to set a default server if none is specified.

I've hacked the pop3-gw code to use a default server and it seems to
be working ok but I was  wondering if there's another pop-gw which:

   uses pop3 (or can be configured to use pop3)
   allows you to configure a default server
   also accepts the user@host syntax to override the default server

Thanks
-- 
Ian
     ian@physics.uq.edu.au    Ian Mortimer
     Tel: +61 7 3365 3436     Department of Physics
     Fax: +61 7 3365 1242     University of Queensland



---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Thu May  9 20:04 EDT 2002
Received: from sentry.gw.tislabs.com (firewall-user@sentry.gw.tislabs.com [192.94.214.100])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id UAA19905
	Thu, 9 May 2002 20:04:04 -0400 (EDT)
Received: by sentry.gw.tislabs.com; id UAA15106; Thu, 9 May 2002 20:22:55 -0400 (EDT)
Received: from listserv.nai.com(161.69.213.6) by sentry.gw.tislabs.com via smap (V5.5)
	id xma015093; Thu, 9 May 02 20:22:00 -0400
Date: Thu, 9 May 2002 20:15:44 -0400 (EDT)
From: Ted Keller <keller@bfg.com>
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] Re: Ports
In-Reply-To: <LISTMANAGER-13-570-2002.05.09-13.55.43--keller#bfg.com@listserv.nai.com>
Message-ID: <LISTMANAGER-303-572-2002.05.09-19.06.38--fwtk-archive#lists.tislabs.com@listserv.nai.com>
MIME-Version: 1.0
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 911
Status: RO

Jonathan,

First remember - these must be tcp ports.

You can use plug-gw to proxy ports inbound or outbound.  The steps
involved include...
1. define the ports in /etc/services
2. activate plug-gw through /etc/inetd.conf (or equivalent)
3. define the rules in netperm-table.

Let me know if you need sample rules for what you are doing.

ted keller


On Thu, 9 May 2002, Fritsch Jonathan D CONT PSNS wrote:

> How can I open and close port on fwtk.  For example port 1863 inbound or
> outbound only.
>
>
> Jonathan D Fritsch
> SRA Int. - PSNS IT Configuration Mgmt.
> Code 1233.24 (360) 476-0019
>
>
> ---
> You are currently subscribed to fwtk-users as: keller@bfg.com
> To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com
>


---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Fri May 10 14:17 EDT 2002
Received: from sentry.gw.tislabs.com (firewall-user@sentry.gw.tislabs.com [192.94.214.100])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id OAA21379
	Fri, 10 May 2002 14:17:05 -0400 (EDT)
Received: by sentry.gw.tislabs.com; id OAA00992; Fri, 10 May 2002 14:29:01 -0400 (EDT)
Received: from listserv.nai.com(161.69.213.6) by sentry.gw.tislabs.com via smap (V5.5)
	id xma026861; Fri, 10 May 02 10:31:49 -0400
Message-ID: <LISTMANAGER-303-573-2002.05.10-09.23.07--fwtk-archive#lists.tislabs.com@listserv.nai.com>
From: Fritsch Jonathan D CONT PSNS <fritschj@PSNS.navy.mil>
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Cc: "'fwtk-users'" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] RE: Outgoing pop-gw allowing choice of mail server.
Date: Fri, 10 May 2002 07:31:47 -0700
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2653.19)
X-N-Score: scored -400
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 1891
Status: RO

  Ian Mortimer,

I've added the following information in the files you say are required for
opening a port on fwtk.

/etc/services
msnet		1863/tcp	#Microsoft .NET

/etc/inetd.conf
msnet		stream	tcp	nowait	root	/usr/local/etc/plug-gw
plug-gw	msnet

As far a what to put in the netperm-table, I'm unsure what to ender.  I've
read what I could find online, but I get conflicting information.

- Jonathan

-----Original Message-----
From: Ian Mortimer [mailto:ian@physics.uq.edu.au]
Sent: Thursday, May 09, 2002 4:28 PM
To: fwtk-users
Subject: [fwtk-users] Outgoing pop-gw allowing choice of mail server.


A network behind an fwtk firewall has been using the pop-gw written by 
Eberhard Mattes to collect mail from an external mail server.  Some of the 
group now need to collect their mail from a different mail server but the 
pop-gw has no provision for that and doesn't support the user@host syntax.

pop3-gw from the fwtk site does support the user@host syntax but it tries to

use apop by default and then falls back to pop if apop fails and it doesn't 
allow you to set a default server if none is specified.

I've hacked the pop3-gw code to use a default server and it seems to
be working ok but I was  wondering if there's another pop-gw which:

   uses pop3 (or can be configured to use pop3)
   allows you to configure a default server
   also accepts the user@host syntax to override the default server

Thanks
-- 
Ian
     ian@physics.uq.edu.au    Ian Mortimer
     Tel: +61 7 3365 3436     Department of Physics
     Fax: +61 7 3365 1242     University of Queensland



---
You are currently subscribed to fwtk-users as: fritschj@PSNS.navy.mil
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com


---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Mon May 13 12:40 EDT 2002
Received: from sentry.gw.tislabs.com (firewall-user@sentry.gw.tislabs.com [192.94.214.100])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id MAA28054
	Mon, 13 May 2002 12:40:20 -0400 (EDT)
Received: by sentry.gw.tislabs.com; id MAA03225; Mon, 13 May 2002 12:52:21 -0400 (EDT)
Received: from listserv.nai.com(161.69.213.6) by sentry.gw.tislabs.com via smap (V5.5)
	id xma003213; Mon, 13 May 02 12:51:51 -0400
Message-ID: <LISTMANAGER-303-577-2002.05.13-11.43.02--fwtk-archive#lists.tislabs.com@listserv.nai.com>
From: "Barreira, Fernando [IT]" <fernando.barreira@citigroup.com>
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] problem with STAT on ftp
Date: Mon, 13 May 2002 10:52:36 -0400
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2650.21)
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain
Content-Length: 3384
Status: RO

i have a windows ftp program that is ued as follows..

It is a program called REALWATCH and is used to poll a server for specific
types of files and download them when they appear in the directory.

 It is a custom application by the company that provides the service and
uses the library CSFTP32.OCX from Catalyst.com in their SocketTools package.

This library appears to want to do the STAT every time a file is retrieved
as a 'feature'.  My guess is that they can then call a function like,
 'filesize=get("server","filename");' in their code and know how large the
file is going to be so they can put up a percent complete message.

This isn't a feature that it appears they can disable.  They have
rewritten the application a number of times to try to avoid it, but the
underlying
library won't remove the requirement for STAT.

========================here is the problem===============================

 Ok, here is the problem.  Command line "get" works file 
FTP makes two connections to the proxy server.  One over port 21, which
is the control connection.  And another (the data channel) that is
negotiated depending on if it is passive or active mode.

Over the control connection, commands get sent to tell the remote ftp
server what it is you want to do.

These are commands like:

RETR
LIST
SYST
PWD
CWD
PASV
TYPE
USER
PASS
DIR
...and the one that is killing us...STAT.

You can NOT send these commands using an FTP client.  They are lower
level protocol commands.  The only way to manually send them is with a RAW
(cooked) TCP connection to port 21 to manually manipulate the control
channel.  That is why I was using the telnet program to get more
specific debug data.

When you do a GET on a file using your FTP program, the ftp program
translates this into a series of commands.  In a simple FTP client, it
may just send the RETR command to retrieve the file.  In a more complex FTP
program, it may set the binary/ascii TYPE and STAT the file to find out
how large it is so it can put up a progress meter, see the rights, etc.

When you are doing your GET, you are doing just that - only sending a
RETR command to get the file.  You are absolutely right, this works just
fine.

HOWEVER, not all FTP clients do this.  Some of them, and in this case
some FTP processes embedded in proprietary applications that use FTP as
their
transport, send the additional commands, like STAT.

What is happening is that when the client issues the STAT command, the
proxy, or the downstream firewall, is killing the control channel.  This
should NOT happen.  What should happen is either a message is sent back
that says that the command is not supported, or the response should be
returned to the user.

This is what this incident is about - getting the proxy server to behave
in the appropriate manner and either denying the STAT command or sending
the response, but NOT destroying the control channel.  The destruction of
the control channel breaks the whole FTP process and causes the program to
stop functioning.

Everything that is being done in this transfer is fully RFC compliant
for a FTP transfer.  Nothing out of the ordinary is being done.  The issue
is
just that the STAT command destroys the connection.



---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Mon May 13 14:52 EDT 2002
Received: from sentry.gw.tislabs.com (firewall-user@sentry.gw.tislabs.com [192.94.214.100])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id OAA28544
	Mon, 13 May 2002 14:52:18 -0400 (EDT)
Received: by sentry.gw.tislabs.com; id PAA06703; Mon, 13 May 2002 15:04:19 -0400 (EDT)
Received: from listserv.nai.com(161.69.213.6) by sentry.gw.tislabs.com via smap (V5.5)
	id xma006643; Mon, 13 May 02 15:04:07 -0400
Date: Mon, 13 May 2002 15:04:28 -0400 (EDT)
From: Ted Keller <keller@bfg.com>
To: "fwtk-users" <fwtk-users@listserv.nai.com>
cc: fwtk-users <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] Re: problem with STAT on ftp
In-Reply-To: <LISTMANAGER-13-577-2002.05.13-11.43.02--keller#bfg.com@listserv.nai.com>
Message-ID: <LISTMANAGER-303-578-2002.05.13-13.55.21--fwtk-archive#lists.tislabs.com@listserv.nai.com>
MIME-Version: 1.0
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 3893
Status: RO

Fernando,

If you do this against a non-windows server  - does it work?  stat seems
to be supported through ftp-gw - at least to wu-ftpd daemons.

ted keller


On Mon, 13 May 2002, Barreira, Fernando [IT] wrote:

> i have a windows ftp program that is ued as follows..
>
> It is a program called REALWATCH and is used to poll a server for specific
> types of files and download them when they appear in the directory.
>
>  It is a custom application by the company that provides the service and
> uses the library CSFTP32.OCX from Catalyst.com in their SocketTools package.
>
> This library appears to want to do the STAT every time a file is retrieved
> as a 'feature'.  My guess is that they can then call a function like,
>  'filesize=get("server","filename");' in their code and know how large the
> file is going to be so they can put up a percent complete message.
>
> This isn't a feature that it appears they can disable.  They have
> rewritten the application a number of times to try to avoid it, but the
> underlying
> library won't remove the requirement for STAT.
>
> ========================here is the problem===============================
>
>  Ok, here is the problem.  Command line "get" works file
> FTP makes two connections to the proxy server.  One over port 21, which
> is the control connection.  And another (the data channel) that is
> negotiated depending on if it is passive or active mode.
>
> Over the control connection, commands get sent to tell the remote ftp
> server what it is you want to do.
>
> These are commands like:
>
> RETR
> LIST
> SYST
> PWD
> CWD
> PASV
> TYPE
> USER
> PASS
> DIR
> ...and the one that is killing us...STAT.
>
> You can NOT send these commands using an FTP client.  They are lower
> level protocol commands.  The only way to manually send them is with a RAW
> (cooked) TCP connection to port 21 to manually manipulate the control
> channel.  That is why I was using the telnet program to get more
> specific debug data.
>
> When you do a GET on a file using your FTP program, the ftp program
> translates this into a series of commands.  In a simple FTP client, it
> may just send the RETR command to retrieve the file.  In a more complex FTP
> program, it may set the binary/ascii TYPE and STAT the file to find out
> how large it is so it can put up a progress meter, see the rights, etc.
>
> When you are doing your GET, you are doing just that - only sending a
> RETR command to get the file.  You are absolutely right, this works just
> fine.
>
> HOWEVER, not all FTP clients do this.  Some of them, and in this case
> some FTP processes embedded in proprietary applications that use FTP as
> their
> transport, send the additional commands, like STAT.
>
> What is happening is that when the client issues the STAT command, the
> proxy, or the downstream firewall, is killing the control channel.  This
> should NOT happen.  What should happen is either a message is sent back
> that says that the command is not supported, or the response should be
> returned to the user.
>
> This is what this incident is about - getting the proxy server to behave
> in the appropriate manner and either denying the STAT command or sending
> the response, but NOT destroying the control channel.  The destruction of
> the control channel breaks the whole FTP process and causes the program to
> stop functioning.
>
> Everything that is being done in this transfer is fully RFC compliant
> for a FTP transfer.  Nothing out of the ordinary is being done.  The issue
> is
> just that the STAT command destroys the connection.
>
>
>
> ---
> You are currently subscribed to fwtk-users as: keller@bfg.com
> To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com
>


---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Mon May 13 15:55 EDT 2002
Received: from sentry.gw.tislabs.com (firewall-user@sentry.gw.tislabs.com [192.94.214.100])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id PAA28655
	Mon, 13 May 2002 15:55:56 -0400 (EDT)
Received: by sentry.gw.tislabs.com; id QAA08575; Mon, 13 May 2002 16:07:57 -0400 (EDT)
Received: from listserv.nai.com(161.69.213.6) by sentry.gw.tislabs.com via smap (V5.5)
	id xma008563; Mon, 13 May 02 16:07:12 -0400
To: "fwtk-users" <fwtk-users@listserv.nai.com>
CC: fwtk-users@listserv.nai.com
Message-Id: <LISTMANAGER-303-583-2002.05.13-14.58.38--fwtk-archive#lists.tislabs.com@listserv.nai.com>
Date: Mon, 13 May 2002 15:47:16 -0500
From: "Michael R. Eckhoff" <FOOBAR@sbcglobal.net>
Subject: [fwtk-users] Re: problem with STAT on ftp
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text
Content-Length: 2376
Status: RO


Ted,

I have been working with Fernando on this so I'm going 
to go ahead and reply.  I don't think he knows I'm 
also on this list.

I see this problem with all FTP destinations.

Here is a copy of the control stream to the NT Server:
220 
USER user@destination.host
331-(----GATEWAY CONNECTED TO destination.host----)
331-(220 destination Microsoft FTP Service (Version 
5.0).)
331 Password required for user.
PASS secretpassword
230-This is a private FTP site.
230-All Access Is monitored and logged.
230-
230-
230-Please Disconnect
230 User user logged in.
SYST
215 Windows_NT version 5.0
PWD
257 "/" is current directory.
TYPE I
200 Type set to I.
CWD /12345/foo
250 CWD command successful.
PWD
257 "/12345/foo" is current directory.
PWD
257 "/12345/foo" is current directory.
TYPE A
200 Type set to A.
PORT 10,11,12,30,9,215
200 PORT command successful.
LIST
150 Opening ASCII mode data connection for /bin/ls.
226 Transfer complete.
TYPE I
200 Type set to I.
STAT /12345/foo/test.txt
530 Peer has closed connection
PORT 10,11,12,30,9,216
QUIT

...notice the 530 immediately after the STAT.  The 
PORT command following the STAT is getting ready for 
the RETR.  It then figures out that the channel is 
dead and issues a QUIT.

Here is one to ftp.cdrom.com:

220 
USER ftp@ftp.cdrom.com
331-(----GATEWAY CONNECTED TO ftp.cdrom.com----)
331-(220 wcarchive.cdrom.com FTP server (Version DG-
4.1.75 1020766287) ready.)
331 Guest login ok, send your email address as 
password.
PASS foobar@sbcglobal.net
230-Welcome to ftp.cdrom.com, a service of Digital 
River, Inc.
230 Guest login ok, access restrictions apply.
SYST
215 UNIX Type: L8 Version: BSD-199506
PWD
257 "/" is current directory.
TYPE I
200 Type set to I.
PWD
257 "/" is current directory.
PORT 10,11,12,30,9,216
200 PORT command successful.
STAT .
530 Peer has closed connection

Notice, again, the as soon as the STAT is issued, the 
connection closes.  This is immediate, there is no 
delay between the stat being issued and the 530 being 
returned.

Hope this helps.

Mike

> Fernando,

> If you do this against a non-windows server  - does 
> it work?  stat seems
> to be supported through ftp-gw - at least to wu-ftpd 
> daemons.

> ted keller



---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Mon May 13 17:46 EDT 2002
Received: from sentry.gw.tislabs.com (firewall-user@sentry.gw.tislabs.com [192.94.214.100])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id RAA28861
	Mon, 13 May 2002 17:46:37 -0400 (EDT)
Received: by sentry.gw.tislabs.com; id RAA11192; Mon, 13 May 2002 17:58:37 -0400 (EDT)
Received: from listserv.nai.com(161.69.213.6) by sentry.gw.tislabs.com via smap (V5.5)
	id xma011181; Mon, 13 May 02 17:57:53 -0400
Date: Mon, 13 May 2002 17:58:11 -0400 (EDT)
From: Ted Keller <keller@bfg.com>
To: "fwtk-users" <fwtk-users@listserv.nai.com>
cc: fwtk-users@listserv.nai.com
Subject: [fwtk-users] Re: problem with STAT on ftp
In-Reply-To: <AA-95B4997094656138C432C1FBB4BC7FA4-ZZ@www2.prodigy.net>
Message-ID: <LISTMANAGER-303-584-2002.05.13-16.49.19--fwtk-archive#lists.tislabs.com@listserv.nai.com>
MIME-Version: 1.0
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 2828
Status: RO

Michael,

Just in case I'm crazy (as many people have implied) would you try this
with ftp.bfg.com.  This is a wu-ftpd server.  When I try there - things
seem to work fine - or I am seeing something different than you.

ted keller


On Mon, 13 May 2002, Michael R. Eckhoff wrote:

>
> Ted,
>
> I have been working with Fernando on this so I'm going
> to go ahead and reply.  I don't think he knows I'm
> also on this list.
>
> I see this problem with all FTP destinations.
>
> Here is a copy of the control stream to the NT Server:
> 220
> USER user@destination.host
> 331-(----GATEWAY CONNECTED TO destination.host----)
> 331-(220 destination Microsoft FTP Service (Version
> 5.0).)
> 331 Password required for user.
> PASS secretpassword
> 230-This is a private FTP site.
> 230-All Access Is monitored and logged.
> 230-
> 230-
> 230-Please Disconnect
> 230 User user logged in.
> SYST
> 215 Windows_NT version 5.0
> PWD
> 257 "/" is current directory.
> TYPE I
> 200 Type set to I.
> CWD /12345/foo
> 250 CWD command successful.
> PWD
> 257 "/12345/foo" is current directory.
> PWD
> 257 "/12345/foo" is current directory.
> TYPE A
> 200 Type set to A.
> PORT 10,11,12,30,9,215
> 200 PORT command successful.
> LIST
> 150 Opening ASCII mode data connection for /bin/ls.
> 226 Transfer complete.
> TYPE I
> 200 Type set to I.
> STAT /12345/foo/test.txt
> 530 Peer has closed connection
> PORT 10,11,12,30,9,216
> QUIT
>
> ...notice the 530 immediately after the STAT.  The
> PORT command following the STAT is getting ready for
> the RETR.  It then figures out that the channel is
> dead and issues a QUIT.
>
> Here is one to ftp.cdrom.com:
>
> 220
> USER ftp@ftp.cdrom.com
> 331-(----GATEWAY CONNECTED TO ftp.cdrom.com----)
> 331-(220 wcarchive.cdrom.com FTP server (Version DG-
> 4.1.75 1020766287) ready.)
> 331 Guest login ok, send your email address as
> password.
> PASS foobar@sbcglobal.net
> 230-Welcome to ftp.cdrom.com, a service of Digital
> River, Inc.
> 230 Guest login ok, access restrictions apply.
> SYST
> 215 UNIX Type: L8 Version: BSD-199506
> PWD
> 257 "/" is current directory.
> TYPE I
> 200 Type set to I.
> PWD
> 257 "/" is current directory.
> PORT 10,11,12,30,9,216
> 200 PORT command successful.
> STAT .
> 530 Peer has closed connection
>
> Notice, again, the as soon as the STAT is issued, the
> connection closes.  This is immediate, there is no
> delay between the stat being issued and the 530 being
> returned.
>
> Hope this helps.
>
> Mike
>
> > Fernando,
>
> > If you do this against a non-windows server  - does
> > it work?  stat seems
> > to be supported through ftp-gw - at least to wu-ftpd
> > daemons.
>
> > ted keller
>
>
>


---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Mon May 13 18:14 EDT 2002
Received: from sentry.gw.tislabs.com (firewall-user@sentry.gw.tislabs.com [192.94.214.100])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id SAA28882
	Mon, 13 May 2002 18:14:40 -0400 (EDT)
Received: by sentry.gw.tislabs.com; id SAA11534; Mon, 13 May 2002 18:26:42 -0400 (EDT)
Received: from listserv.nai.com(161.69.213.6) by sentry.gw.tislabs.com via smap (V5.5)
	id xma011527; Mon, 13 May 02 18:25:44 -0400
Message-Id: <LISTMANAGER-303-585-2002.05.13-17.16.25--fwtk-archive#lists.tislabs.com@listserv.nai.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 5.1
Date: Mon, 13 May 2002 18:25:31 -0400
To: "fwtk-users" <fwtk-users@listserv.nai.com>
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: [fwtk-users] Re: problem with STAT on ftp
In-Reply-To: <LISTMANAGER-602-577-2002.05.13-11.43.02--rmurphy#itm-inst.
 com@listserv.nai.com>
Mime-Version: 1.0
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 1207
Status: RO

At 10:52 AM 5/13/02 -0400, Barreira, Fernando [IT] wrote:
>Everything that is being done in this transfer is fully RFC compliant
>for a FTP transfer.  Nothing out of the ordinary is being done.  The issue
>is just that the STAT command destroys the connection.

Have a look at how ftp-gw handles STAT commands - look at the "ops[]" 
structure in the ftp-gw source:

         "stat",         OP_CONN,        /* overload */  cmd_abor,

A "stat" command is only valid if connected, and when recognized, it calls 
'cmd_abor' to abort your connection.
Changing this to
         "stat",         OP_CONN,        0,
would allow your application to send the "STAT" command.
Interestingly enough, this alias of STAT to ABOR has been in ftp-gw for 
quite a while. I'll bet that the Gauntlet ftp-gw has the same code.

I think this was coded this way because ftp-gw wasn't prepared to handle 
the STAT command while a data transfer is in progress. If so, coding a 
function to reject the STAT under those conditions would have made more sense.
         -Rick


---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Wed May 15 14:19 EDT 2002
Received: from sentry.gw.tislabs.com (firewall-user@sentry.gw.tislabs.com [192.94.214.100])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id OAA05009
	Wed, 15 May 2002 14:19:38 -0400 (EDT)
Received: by sentry.gw.tislabs.com; id OAA05084; Wed, 15 May 2002 14:31:40 -0400 (EDT)
Received: from listserv.nai.com(161.69.213.6) by sentry.gw.tislabs.com via smap (V5.5)
	id xma005059; Wed, 15 May 02 14:31:10 -0400
Message-ID: <LISTMANAGER-303-591-2002.05.15-13.22.16--fwtk-archive#lists.tislabs.com@listserv.nai.com>
From: "DiGeronimo,Sergio" <Sergio.DiGeronimo@sbs.siemens.ca>
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] Undefined Symbol - connection_ id
Date: Wed, 15 May 2002 12:32:00 -0400
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2650.21)
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 907
Status: RO

Hello, I would appreciate your help...
I am trying to install the ftp-proxy components of the FWTK version 2.1 on
Solaris 2.8 SPARC system

I am encountering the following error when running 'make';

gcc -g -o ftp-igw ftp-igw.o ftp-misc.o bindport.o ../libfwall.a ../libauth.a
-lresolv -lsocket -lnsl
Undefined                       first referenced
 symbol                             in file
connection_id                       ftp-igw.o
ld: fatal: Symbol referencing errors. No output written to ftp-igw
collect2: ld returned 1 exit status
*** Error code 1
make: Fatal error: Command failed for target `ftp-igw'

Appreciate your help - thanks in advance!


Regards,

Sergio Di Geronimo
Network Analyst 
Siemens Business Services Canada Inc.





---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Wed May 15 21:11 EDT 2002
Received: from sentry.gw.tislabs.com (firewall-user@sentry.gw.tislabs.com [192.94.214.100])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id VAA05983
	Wed, 15 May 2002 21:11:02 -0400 (EDT)
Received: by sentry.gw.tislabs.com; id VAA14299; Wed, 15 May 2002 21:23:06 -0400 (EDT)
Received: from listserv.nai.com(161.69.213.6) by sentry.gw.tislabs.com via smap (V5.5)
	id xma014275; Wed, 15 May 02 21:22:25 -0400
Message-Id: <LISTMANAGER-303-595-2002.05.15-20.13.24--fwtk-archive#lists.tislabs.com@listserv.nai.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 5.1
Date: Wed, 15 May 2002 21:13:43 -0400
To: "fwtk-users" <fwtk-users@listserv.nai.com>
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: [fwtk-users] Re: Undefined Symbol - connection_ id
In-Reply-To: <LISTMANAGER-602-591-2002.05.15-13.22.16--rmurphy#itm-inst.
 com@listserv.nai.com>
Mime-Version: 1.0
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 1073
Status: RO

At 12:32 PM 5/15/02 -0400, DiGeronimo,Sergio wrote:
>Hello, I would appreciate your help...
>I am trying to install the ftp-proxy components of the FWTK version 2.1 on
>Solaris 2.8 SPARC system
>
>I am encountering the following error when running 'make';
>
>gcc -g -o ftp-igw ftp-igw.o ftp-misc.o bindport.o ../libfwall.a ../libauth.a
>-lresolv -lsocket -lnsl
>Undefined                       first referenced
>  symbol                             in file
>connection_id                       ftp-igw.o
>ld: fatal: Symbol referencing errors. No output written to ftp-igw
>collect2: ld returned 1 exit status
>*** Error code 1
>make: Fatal error: Command failed for target `ftp-igw'
>
>Appreciate your help - thanks in advance!

I can't find anything in my FWTK 2.1 distribution matching ftp-igw.* or 
bindport.*
What are you building? What directory off the fwtk distribution is this 
ftp-igw in?
         -Rick


---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Thu May 16 20:26 EDT 2002
Received: from sentry.gw.tislabs.com (firewall-user@sentry.gw.tislabs.com [192.94.214.100])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id UAA08934
	Thu, 16 May 2002 20:26:29 -0400 (EDT)
Received: by sentry.gw.tislabs.com; id UAA12628; Thu, 16 May 2002 20:38:35 -0400 (EDT)
Received: from listserv.nai.com(161.69.213.6) by sentry.gw.tislabs.com via smap (V5.5)
	id xma012606; Thu, 16 May 02 20:38:01 -0400
Message-Id: <LISTMANAGER-303-608-2002.05.16-19.29.21--fwtk-archive#lists.tislabs.com@listserv.nai.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 5.1
Date: Thu, 16 May 2002 20:31:43 -0400
To: "fwtk-users" <fwtk-users@listserv.nai.com>
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: [fwtk-users] RE: Undefined Symbol - connection_ id
In-Reply-To: <E0EF20FAE0A300478B099DA0FA841BD184D6DF@MISS913B.SBS.SIEMEN
 S.CA>
Mime-Version: 1.0
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 631
Status: RO

At 08:45 AM 5/16/02 -0400, DiGeronimo,Sergio wrote:
>The ftp-igw (and ftp-ogw) is in ../fwtk/ftp-gw2/

That's not part of fwtk; a google search finds a reference on the firewalls 
mailing list - 
http://lists.gnac.net/pipermail/firewalls/1995-May/010476.html - where 
Simon J. Gerraty describes it (a split, two-part ftp-gw for use on separate 
inside and outside bastion hosts.
Unfortunately, I haven't been able to find the code, so can't suggest a fix.
         -Rick


---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Fri May 31 08:30 EDT 2002
Received: from sentry.gw.tislabs.com (firewall-user@sentry.gw.tislabs.com [192.94.214.100])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id IAA17339
	Fri, 31 May 2002 08:30:57 -0400 (EDT)
Received: by sentry.gw.tislabs.com; id IAA22078; Fri, 31 May 2002 08:43:23 -0400 (EDT)
Received: from listserv.nai.com(161.69.213.6) by sentry.gw.tislabs.com via smap (V5.5)
	id xma022074; Fri, 31 May 02 08:43:18 -0400
X-Authentication-Warning: spider.usrconsult.be: mail set sender to <mbardiaux@peaktime.be> using -f
Message-ID: <LISTMANAGER-303-638-2002.05.31-07.33.39--fwtk-archive#lists.tislabs.com@listserv.nai.com>
Date: Fri, 31 May 2002 14:43:53 +0200
From: Michel Bardiaux <mbardiaux@peaktime.be>
Organization: Peaktime Belgium S.A.
X-Mailer: Mozilla 4.73 [en] (WinNT; I)
X-Accept-Language: en,fr
MIME-Version: 1.0
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] Re: Bug in ftp-gw.c/sendsaved ?
References: <3BF529CC.DB1722DB@peaktime.be>
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: multipart/mixed;
 boundary="------------89953D263C529B834ED09598"
Content-Length: 4908
Status: RO

This is a multi-part message in MIME format.
--------------89953D263C529B834ED09598
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit

Quoting an old posting of mine is the best intro:

Michel Bardiaux wrote:
> 
> Symptoms: FTP client (any) comes from behind a Checkpoint Firewall-1,
> goes through TIS FWTK 2.1 ftp-gw (configured incoming), to *any* ftp
> server, whather loval or in the DMZ. Client sends "USER foo", receives
> "331 Password required for ..." then "421 Service not available".
> 
> We looked in the FAQs, the FWTK archives, Google, the FWTK patches
> pages, etc... and found about the port-20 problem and patch (which was
> already applied), and about the problem of \r\n in a separate packet
> from the PORT command, which supposed to be fixed in 2.1.
> 
> We then added lots of trace printouts in ftp-gw.c and it finally emerged
> that there is one place where the \r\n problem is *not* completely fixed
> because there is one case when ftp-gw tals to the client not using
> sayn() but directly calling net_send(): in sendsaved(). After patching
> sendsaved() the sessions through FW-1 worked.
> 

The thread was more or less closed by Rick Murphy:

> Subject: 
>           [fwtk-users] Re: Bug in ftp-gw.c/sendsaved ?
>      Date: 
>           Tue, 04 Dec 2001 06:30:02 -0500
>     From: 
>           Rick Murphy <rmurphy@itm-inst.com>
>  Reply-To: 
>           "fwtk-users" <fwtk-users@listserv.nai.com>
>        To: 
>           "fwtk-users" <fwtk-users@listserv.nai.com>
> 
> 
> 
> 
> At 03:37 PM 12/1/01 -0500, Ted Keller wrote:
> >So is there a bonified patch for this issue?  The updated looks pretty
> >easy - however, if you have a patch - would like to see it and post it to
> >fwtk.org.
> 
> I haven't seen a patch and I'm reluctant to just write one - I don't have 
> the ability to test any proposed fix.
>          -Rick
> 
At the time I was far too busy to create a proper patch, and there was
also a big mess between several versions of FWTK on our machines... Now
I have been able to find the source for ftp-gw.c, both pristine 2.1 and
patched for data-port. The same patch (attached) works in both cases (as
a patch, and as a fix!).

As for testing... obviously it worked for us, and I have just received a
success report from someone else:

> Subject: 
>             Re: Original 2.1 version, unpatched...
>       Date: 
>             Thu, 30 May 2002 13:21:55 -0400
>       From: 
>             "Michael C. Ibarra" <ibarra@hawk.com>
>         To: 
>             Michel Bardiaux <mbardiaux@peaktime.be>
>  References: 
>             1 , 2 , 3 , 4 , 5 , 6
> 
> Yes! This worked! I owe you a drink, but you would have to come to
> NYC to redeem :-) Just for the record, I am using a Nokia/Checkpoint
> firewall. My Proxy server running ftp-gw is a Solaris 2.8 build and
> is on one DMZ of the Nokia, and my target ftp server is on a third
> DMZ, my client of course is on a separate DMZ as well. 
> 
> Best regards, and MANY thanks,
> 
> -mike

Will someone put the patch on fwtk.org, and/or merge it with the jumbo
patch?

Greetings,
-- 
Michel Bardiaux
Peaktime Belgium S.A.  Bd. du Souverain, 191  B-1160 Bruxelles
Tel : +32 2 790.29.41
--------------89953D263C529B834ED09598
Content-Type: text/plain; charset=us-ascii;
 name="ftp-gw.pat"
Content-Transfer-Encoding: 7bit
Content-Disposition: inline;
 filename="ftp-gw.pat"

--- ftp-gw.c	Thu May 30 17:46:01 2002
+++ our-ftp-gw.c	Thu May 30 17:46:23 2002
@@ -1687,6 +1687,10 @@
 
 
 /* flush saved lines prefixing them with 'code' */
+/*
+This routine as in the 'pristine' 2.1 is not working if connection is made from a FireWall1 because, CR/NL are send in a separate packet...
+This fix was done in fwtk2.1 in the sayn() routine but it seems that the author forgot this one...
+*/
 sendsaved(fd,code)
 int	fd;
 int	code;
@@ -1695,6 +1699,10 @@
 	int	x;
 
 	for(x = 0; x < saveresps; x++) {
+		char*	buf;
+		char*	p;
+		l = strlen(saveresp[x]);
+		p = buf = malloc(5+l+32 /* wide margin... */);
 		if(code != -1) {
 			char	xuf[5];
 			xuf[0] = (code / 100) + '0';
@@ -1702,16 +1710,13 @@
 			xuf[2] = (code % 10) + '0';
 			xuf[3] = '-';
 			xuf[4] = '(';
-			if(net_send(fd,xuf,5,0) != 5)
-				return(-1);
+			memcpy(p, xuf, 5);
+			p+=5;
 		}
-		l = strlen(saveresp[x]);
-		if(net_send(fd,saveresp[x],l,0) != l)
-			return(-1);
-		if(code != -1 && write(fd,")",1) != 1)
-			return(-1);
-		if(net_send(fd,"\r\n",2,0) != 2)
-			return(-1);
+		p+=sprintf(p, "%s)", saveresp[x]);
+		if(sayn(fd, buf, strlen(buf)))
+			return -1;
+		free(buf);
 	}
 	flushsaved();
 	return(0);



--------------89953D263C529B834ED09598
Content-Type: text/plain; charset="us-ascii"
Content-description: footer

---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

--------------89953D263C529B834ED09598--


From bounce-fwtk-users-303@listserv.nai.com Fri May 31 14:09 EDT 2002
Received: from sentry.gw.tislabs.com (firewall-user@sentry.gw.tislabs.com [192.94.214.100])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id OAA18038
	Fri, 31 May 2002 14:09:53 -0400 (EDT)
Received: by sentry.gw.tislabs.com; id OAA00587; Fri, 31 May 2002 14:22:18 -0400 (EDT)
Received: from listserv.nai.com(161.69.213.6) by sentry.gw.tislabs.com via smap (V5.5)
	id xma000583; Fri, 31 May 02 14:22:16 -0400
Message-ID: <LISTMANAGER-303-639-2002.05.31-13.12.57--fwtk-archive#lists.tislabs.com@listserv.nai.com>
From: Fritsch Jonathan D CONT PSNS <fritschj@PSNS.navy.mil>
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] FTP
Date: Fri, 31 May 2002 11:22:05 -0700
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2653.19)
X-N-Score: scored -400
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 321
Status: RO

How do you FTP though the FWTK without using a product such as WSFTP PRO?

Jonathan D Fritsch
SRA Int. - PSNS IT Configuration Mgmt.
Code 1233.24 (360) 476-0019


---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Fri May 31 14:53 EDT 2002
Received: from sentry.gw.tislabs.com (firewall-user@sentry.gw.tislabs.com [192.94.214.100])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id OAA18100
	Fri, 31 May 2002 14:53:17 -0400 (EDT)
Received: by sentry.gw.tislabs.com; id PAA02113; Fri, 31 May 2002 15:05:43 -0400 (EDT)
Received: from listserv.nai.com(161.69.213.6) by sentry.gw.tislabs.com via smap (V5.5)
	id xma002105; Fri, 31 May 02 15:05:07 -0400
Sender: mqh@tfn.com
Message-ID: <LISTMANAGER-303-640-2002.05.31-13.55.52--fwtk-archive#lists.tislabs.com@listserv.nai.com>
Date: Fri, 31 May 2002 15:05:45 -0400
From: "Mike Q. Hiller" <mqh@tfn.com>
X-Mailer: Mozilla 4.73 [en] (X11; I; SunOS 5.6 sun4u)
X-Accept-Language: en
MIME-Version: 1.0
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] Re: FTP
Content-Transfer-Encoding: 7bit
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain; charset=us-ascii
Content-Length: 677
Status: RO

Fritsch Jonathan D CONT PSNS wrote:
> 
> How do you FTP though the FWTK without using a product such as WSFTP PRO?
> 
> Jonathan D Fritsch
> SRA Int. - PSNS IT Configuration Mgmt.
> Code 1233.24 (360) 476-0019
> 
> ---
> You are currently subscribed to fwtk-users as: mqh@tfn.com
> To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com


Use any client to ftp to the firewall machine.

for username, use user@remotehostname (ie ftp@ftp.firstcall.com)
use the accounts regualar password

you then

---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Fri May 31 15:09 EDT 2002
Received: from sentry.gw.tislabs.com (firewall-user@sentry.gw.tislabs.com [192.94.214.100])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id PAA18111
	Fri, 31 May 2002 15:09:43 -0400 (EDT)
Received: by sentry.gw.tislabs.com; id PAA02865; Fri, 31 May 2002 15:22:10 -0400 (EDT)
Received: from listserv.nai.com(161.69.213.6) by sentry.gw.tislabs.com via smap (V5.5)
	id xma002834; Fri, 31 May 02 15:21:10 -0400
Date: Fri, 31 May 2002 15:20:22 -0400
From: Joseph S D Yao <jsdy@center.osis.gov>
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] Re: FTP
Message-ID: <LISTMANAGER-303-641-2002.05.31-14.11.56--fwtk-archive#lists.tislabs.com@listserv.nai.com>
Mail-Followup-To: fwtk-users <fwtk-users@listserv.nai.com>
Mime-Version: 1.0
Content-Disposition: inline
User-Agent: Mutt/1.2.5i
In-Reply-To: <LISTMANAGER-765-639-2002.05.31-13.12.57--jsdy#center.osis.gov@listserv.nai.com>; from fritschj@PSNS.navy.mil on Fri, May 31, 2002 at 11:22:05AM -0700
X-Virus-Scanned: at The OSIS Center by AMaViS-perl11-milter (http://amavis.org/)
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain; charset=us-ascii
Content-Length: 881
Status: RO

On Fri, May 31, 2002 at 11:22:05AM -0700, Fritsch Jonathan D CONT PSNS wrote:
> How do you FTP though the FWTK without using a product such as WSFTP PRO?

No idea what that is.  With a real FTP client, you 'ftp' to the
firewall bastion host, and then give "anonymous@remote.host" followed
by your e-mail address, or "remote.name@remote.host" followed by the
requested password.

Most MS Losedoze GUI FTP hiders have a choice of how to deal with
firewalls.  Select "USER without login".

-- 
Joe Yao				jsdy@center.osis.gov - Joseph S. D. Yao
OSIS Center Systems Support					EMT-B
-----------------------------------------------------------------------
   This message is not an official statement of OSIS Center policies.

---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

