1 |
Am Dienstag 12 Juni 2007 17:36 schrieb Hans-Werner Hilse: |
2 |
> Hi, |
3 |
> |
4 |
> On Tue, 12 Jun 2007 17:17:04 +0200 Florian Philipp |
5 |
> |
6 |
> <f.philipp@××××××.de> wrote: |
7 |
> > tcp 0 0 *:ftp *:* LISTEN |
8 |
> |
9 |
> That's it. Now better make sure that you were right when you stated |
10 |
> your provider doesn't block it. BTW, if I as a provider had a no file |
11 |
> sharing policy, I'd definitely block Port 21. Maybe I would leave Port |
12 |
> 20 open (ftp-data), but on Port 21 only the ftp server is supposed to |
13 |
> listen, not really the client. |
14 |
> |
15 |
> The other clients are supposed to use whatever port you specify, BTW. |
16 |
> I'm using 50000-50400 myself, and others work fine, too. |
17 |
> |
18 |
> If you want to know whether incoming connections reach your site at all |
19 |
> (not taking server software and firewall into account), run |
20 |
> "tcpdump -vvns 1600 dst port 21" (I guess it wouldn't reveal anything |
21 |
> at all). |
22 |
> |
23 |
> You're not by chance behind a router? |
24 |
> |
25 |
> -hwh |
26 |
|
27 |
dsl@HOMER_GENTOO64 ~ $ sudo tcpdump -vvns 1600 dst port 21 |
28 |
Password: |
29 |
tcpdump: listening on eth1, link-type EN10MB (Ethernet), capture size 1600 |
30 |
bytes |
31 |
18:37:12.543965 IP (tos 0x8, ttl 64, id 27970, offset 0, flags [DF], proto: |
32 |
TCP (6), length: 60) 192.168.1.2.45269 > 89.57.3.60.21: S, cksum 0x8013 |
33 |
(correct), 1866573467:1866573467(0) win 5840 <mss 1460,sackOK,timestamp |
34 |
6212569 0,nop,wscale 5> |
35 |
18:37:12.544426 IP (tos 0x8, ttl 64, id 17977, offset 0, flags [DF], proto: |
36 |
TCP (6), length: 60) 192.168.1.2.45288 > 89.57.3.60.21: S, cksum 0x98ab |
37 |
(correct), 1867615712:1867615712(0) win 5840 <mss 1460,sackOK,timestamp |
38 |
6212569 0,nop,wscale 5> |
39 |
19:07:52.537852 IP (tos 0x8, ttl 64, id 17709, offset 0, flags [DF], proto: |
40 |
TCP (6), length: 60) 192.168.1.2.36423 > 89.57.3.60.21: S, cksum 0x3a4e |
41 |
(correct), 3820262832:3820262832(0) win 5840 <mss 1460,sackOK,timestamp |
42 |
6672541 0,nop,wscale 5> |
43 |
[...] |
44 |
27 packets captured |
45 |
54 packets received by filter |
46 |
0 packets dropped by kernel |
47 |
|
48 |
In the past Tiscali (my ISP) did not stop file sharing, they just slowed it |
49 |
down to 10-12k. |
50 |
|
51 |
Yes, I am behind a router, NAT is activated, UPnP deactivated. That was no |
52 |
problem up to now... |