From f174f081d0cd45100bf04e0fe294d96888074460 Mon Sep 17 00:00:00 2001 From: teastep Date: Fri, 27 Jan 2006 19:51:07 +0000 Subject: [PATCH] Clarify FTP conntrack issue git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@3391 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb --- Shorewall-docs2/FTP.xml | 10 ++++++---- 1 file changed, 6 insertions(+), 4 deletions(-) diff --git a/Shorewall-docs2/FTP.xml b/Shorewall-docs2/FTP.xml index 74d15bd9c..9dac4cf9c 100644 --- a/Shorewall-docs2/FTP.xml +++ b/Shorewall-docs2/FTP.xml @@ -15,7 +15,7 @@ - 2005-08-31 + 2006-01-27 2003 @@ -24,6 +24,8 @@ 2005 + 2006 + Thomas M. Eastep @@ -347,9 +349,9 @@ FTP/ACCEPT dmz net Note that the FTP connection tracking in the kernel cannot handle - cases where a PORT command (or PASV reply) is broken across two packets. - When such cases occur, you will see a console message similar to this - one: + cases where a PORT command (or PASV reply) is broken across two packets or + is misssing the ending <cr>/<lf>. When such cases occur, you + will see a console message similar to this one: Apr 28 23:55:09 gateway kernel: conntrack_ftp: partial PORT 715014972+1