All of lore.kernel.org
 help / color / mirror / Atom feed
* how do i forward ftp from my firewall to an internal server?
@ 2004-02-28  8:27 Gustav Petersson
  2004-02-29 16:36 ` Mark E. Donaldson
  2004-02-29 20:16 ` Jeroen Vriesman
  0 siblings, 2 replies; 9+ messages in thread
From: Gustav Petersson @ 2004-02-28  8:27 UTC (permalink / raw)
  To: netfilter

Like the subject line says.. how do I do it?

I have port http traffic forwarded to the same server but when i use the 
same rule with only the port(s) changed for ftp traffic my ftp server 
opens the connection but immediately closes it again. I have tried 
running both the standard in.ftpd and proftpd. Any help would be greatly 
appreciated.

Gustav Petersson

I am running debian 3.0 with kernel 2.4.24 and I have the following 
modules loaded:

ipt_LOG
ipt_state
iptable_filter
ip_nat_ftp
ip_conntrack_ftp
iptable_nat
ip_conntrack
ip_tables

Here is my firewall config:
#!/bin/sh
 
EXT_IP=1.2.3.4
INT_IP=192.168.x.x

modprobe iptable_nat
modprobe ip_conntrack_ftp
modprobe ip_nat_ftp
 
echo "1" > /proc/sys/net/ipv4/ip_forward
 
iptables -P INPUT ACCEPT
iptables -F INPUT
iptables -P OUTPUT ACCEPT
iptables -F OUTPUT
iptables -P FORWARD ACCEPT
iptables -F FORWARD
iptables -t nat -F

# NAT
iptables -t nat -A POSTROUTING -o eth0 -j SNAT --to 213.88.181.68
 
                                                                                

# Forward port 80 to internal server
iptables -A PREROUTING -t nat -p tcp -d $EXT_IP --dport 80 \
        -j DNAT --to $INT_IP:80

# Forward ports 20 and 21 to internal server
iptables -A PREROUTING -t nat -p tcp -d $EXT_IP --dport 20 \
        -j DNAT --to $INT_IP:20
                                                                                

iptables -A PREROUTING -t nat -p tcp -d $EXT_IP --dport 21 \
        -j DNAT --to $INT_IP:21





^ permalink raw reply	[flat|nested] 9+ messages in thread

end of thread, other threads:[~2004-03-01  0:47 UTC | newest]

Thread overview: 9+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2004-02-28  8:27 how do i forward ftp from my firewall to an internal server? Gustav Petersson
2004-02-29 16:36 ` Mark E. Donaldson
2004-02-29 19:15   ` Gustav Petersson
2004-02-29 20:58     ` Mark E. Donaldson
2004-02-29 22:10       ` Gustav Petersson
2004-02-29 23:15         ` Mark E. Donaldson
2004-03-01  0:08           ` Gustav Petersson
2004-03-01  0:47             ` Mark E. Donaldson
2004-02-29 20:16 ` Jeroen Vriesman

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.