IPFW firewall NAT and active FTP

Brett Glass brett at lariat.net
Tue Jan 11 23:31:24 UTC 2011


I'm working with a customer who has a FreeBSD 8.0 firewall, set up with firewall
NAT in IPFW. It uses one-to-one static NAT to redirect FTP sessions
originating on the outside to an FTP server on the inside. The FTP server is 
accessible via text-based FTP clients, but not via Web-based clients such as 
Mozilla Firefox or Internet Explorer. The internal FTP server is also a FreeBSD
machine.

He's wondering if the problem has to do with the lack of a "firewall punching" 
setting (which exists in natd but not in IPFW's built-in NAT). Can anyone
suggest what might be causing the problem?

--Brett Glass


More information about the freebsd-net mailing list