I'm having a problem ftping; mainly, if the data port the client and server are using to connect is already registered to a service on the firewall, it fails. phoneboy.com has a solution for 4.0, which is to turn off the service checking. I've gotten this to work in the past on a 4.0 box, but I can't seem to get ti working on my 4.1 box. Anyone have any suggestions?
ex log entry:
non-passive mode:
action service source destination prot rule s_port
"reject" "2095" "[server]" "[client]" "tcp" "0" "ftp"
reason: tried to open tcp service port, port: MPEG"
passive-mode:
action service source destination prot rule s_port
"reject" "ftp" "[client]" "[server]" "tcp" "0" "1561"
reason: tried to open tcp service port, port: pptp-tcp"
In the reason, it says "tried to open tcp service port" and then the service it wants to see there instead of ftp-data. Any idea how to tell it not to check what the port's supposed to be, or if this is even the best option???
Thanks,
moi
[sig][/sig]
ex log entry:
non-passive mode:
action service source destination prot rule s_port
"reject" "2095" "[server]" "[client]" "tcp" "0" "ftp"
reason: tried to open tcp service port, port: MPEG"
passive-mode:
action service source destination prot rule s_port
"reject" "ftp" "[client]" "[server]" "tcp" "0" "1561"
reason: tried to open tcp service port, port: pptp-tcp"
In the reason, it says "tried to open tcp service port" and then the service it wants to see there instead of ftp-data. Any idea how to tell it not to check what the port's supposed to be, or if this is even the best option???
Thanks,
moi
[sig][/sig]