Advertisement

09.12.2003 at 11:19AM PDT, ID: 20737298
[x]
Attachment Details

vsftp passive mode requires open ports on firewall?

Asked by mikedehaan in Linux Network Security

Tags: vsftpd, passive, mode, firewall

I'm not shy to admit that I'm new to security, but I am making my best attempt at keeping my servers safe.  I'm running vsftpd and I've read that passive mode should be used instead of active mode (or PORT mode) instead due to securtity issues.  The only problem I have with this is that in order to use passive mode, I need extra ports open on my router.

This is assuming that only forwarding used ports to the server is a good idea (ports 21, 22, 80, 110 ...).  All of the others I deny.  However, if I have to now forward around 1000 ports to my server, that might not have a service attached, in order to use passive mode?

Is this correct?  Wouldn't this be a security issue to worry about?  Would I have to put my linux machine past the router and setup a linux firewall to protect my server?  Are unused ports open to the public a security hazard?

-MStart Free Trial
 
 
[+][-]09.12.2003 at 08:30PM PDT, ID: 9350582

View this solution now by starting your 7-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

 

About this solution

Zone: Linux Network Security
Tags: vsftpd, passive, mode, firewall
Sign Up Now!
Solution Provided By: jlevie
Participating Experts: 3
Solution Grade: A
 
 
[+][-]09.15.2003 at 08:04AM PDT, ID: 9363512

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]09.15.2003 at 11:26AM PDT, ID: 9364971

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]03.14.2004 at 06:04AM PST, ID: 10591870

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
 
Loading Advertisement...
20080716-EE-VQP-32