Page 1 of 1

Changed FTP port, CSF banning valid accounts.

Posted: 23 Feb 2014, 01:33
by Seventh
Probably something simple that I missed here, but I'd love some insight.

I changed the default FTP port on my host, and notified my members of the change. For the sake of conversation, I'll say I changed it to 888. I'm running Pure-FTPD, and change the bind port in pure-ftpd.conf.

I can FTP right in because my client is in the allow file, but nobody else can. I added the new port to csf.conf under TCP_IN and TCP_OUT, but LFD/CSF is still permanently blocking anyone that tries to connect to the FTP server on the new port. I did restart CSF as well.

What did I miss? Any insight would be great. Thanks!

Re: Changed FTP port, CSF banning valid accounts.

Posted: 23 Feb 2014, 03:15
by Seventh
I've fiddled with it a bit more, and members can connect - but some of them can't get a directory listing, and some are getting banned after browsing folders. Here's a sample of the block, with the IP removed.

Sample of block hits:
Feb 22 21:49:06 s1 kernel: Firewall: *TCP_IN Blocked* IN=eth0 OUT= MAC=00:1c:c0:81:42:6f:00:12:da:23:16:00:08:00 SRC=A.B.C.D DST=(my host) LEN=64 TOS=0x00 PREC=0x00 TTL=55 ID=53690 DF PROTO=TCP SPT=55718 DPT=40607 WINDOW=65535 RES=0x00 SYN URGP=0