[squid-users] FTP proxy

Sticher, Jascha jascha.sticher at tds.fujitsu.com
Mon Dec 7 07:20:15 UTC 2020


Hi Andrea,

> I see this feature was introduced in 3.5 as an experimental one; at 4.13
> is it still so or is it considered stable and dependable?

We are using the squid ftp_port feature for some customers. So far, we have not experienced any issues.
The only downside to using frox (from which we also have migrated) ist the missing feature setting an upstream proxy (proxy-chaining FTP).

> Is there a way to restrict the port range of the additional connections
> (e.g. to 40000-50000)?
As Alex mentioned, squid forces passive FTP, which is the better for firewalled environments anyways.
You should activate automatic FTP detection on your firewall (hint: FTP helper for iptables) - this way you don't need to add any extra rules besides the FTP data connection port.


Kind regards,

Jascha Sticher
Fujitsu


More information about the squid-users mailing list