• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

NAT port forwarding and system vulnerabilities

tronester

n00b
Joined
Oct 28, 2006
Messages
28
I run a virtualized instance of pfsense on my home server to function as my router. It works great, though one thing I have always been concerned with is port forwarding.

I have to forward a few ports, notably 21 and a port range for PASV mode. While I haven't had any issues yet, couldn't an attacker compromise the computer that has those ports forwarded to them? What are the best practices for making sure only the desired traffic (FTP) gets through?
 
Best Practice would be to limit the public ips allowed to access the ftp service, instead of every IP out there.
 
Unfortunately that isn't really feasible as sometimes I need to access the FTP when I'm on the road traveling, like at hotels.
 
Then yes, any vulnerabilities with your FTP server software are then accessible from anywhere on the internet, so you'd want to run a reputable service and keep it updated. I'd still suggest the use of a vpn or ssh tunnels instead of leaving straight ftp open to the internet though.
 
Another vote for VPN. OpenVPN is very easy to setup and it works great. I run it here on a Mac mini and I use it when I connect at a hotel to secure my traffic.
 
Back
Top