1af5dd318SPeter WemmHow to setup FTP proxying using the built in proxy code. 2af5dd318SPeter Wemm======================================================== 3af5dd318SPeter Wemm 4af5dd318SPeter WemmNOTE: Currently, the built-in FTP proxy is only available for use with NAT 5*23a0caafSGuido van Rooij (i.e. only if you're already using "map" rules with ipnat). It does 6*23a0caafSGuido van Rooij support null-NAT mappings, that is, using the proxy without changing 7*23a0caafSGuido van Rooij the addresses. 8af5dd318SPeter Wemm 9af5dd318SPeter WemmLets assume your network diagram looks something like this: 10af5dd318SPeter Wemm 11af5dd318SPeter Wemm 12af5dd318SPeter Wemm[host A] 13af5dd318SPeter Wemm |a 14af5dd318SPeter Wemm---+-------------+---------- 15af5dd318SPeter Wemm |b 16af5dd318SPeter Wemm [host B] 17af5dd318SPeter Wemm |c 18af5dd318SPeter Wemm---+-------------+---------- 19af5dd318SPeter Wemm |d 20af5dd318SPeter Wemm[host C] 21af5dd318SPeter Wemm 22af5dd318SPeter Wemmand IP Filter is running on host B. If you want to proxy FTP from A to C 23af5dd318SPeter Wemmthen you would do: 24af5dd318SPeter Wemm 25c9bff7baSGuido van Rooijmap int-c ipaddr-a/32 -> ip-addr-c-net/32 proxy port ftp ftp/tcp 26af5dd318SPeter Wemm 27af5dd318SPeter Wemmint-c = name of "interface c" 28af5dd318SPeter Wemmipaddr-a = ip# of interface a 29af5dd318SPeter Wemmipaddr-c-net = another ip# on the C-network (usually not the same as the 30af5dd318SPeter Wemminterface). 31af5dd318SPeter Wemm 32af5dd318SPeter Wemme.g., if host A was 10.1.1.1, host B had two network interfaces ed0 and vx0 33af5dd318SPeter Wemmwhich had IP#'s 10.1.1.2 and 203.45.67.89 respectively, and host C was 34af5dd318SPeter Wemm203.45.67.90, you would do: 35af5dd318SPeter Wemm 36c9bff7baSGuido van Rooijmap vx0 10.1.1.1/32 -> 203.45.67.91/32 proxy port ftp ftp/tcp 37af5dd318SPeter Wemm 38af5dd318SPeter Wemmwhere: 39af5dd318SPeter Wemmipaddr-a = 10.1.1.1 40af5dd318SPeter Wemmint-c = vx0 41af5dd318SPeter Wemmipaddr-c-net = 203.45.67.91 42af5dd318SPeter Wemm 43*23a0caafSGuido van RooijThe "map" rule for this proxy should precede any other NAT rules you are 44*23a0caafSGuido van Rooijusing. 45*23a0caafSGuido van Rooij 46