All of lore.kernel.org
 help / color / mirror / Atom feed
* ftp nat  MAX PORTS
@ 2005-02-02 16:32 iansolo
  2005-02-07 11:42 ` iansolo
       [not found] ` <bd35181c05020211473cb89b35@mail.gmail.com>
  0 siblings, 2 replies; 4+ messages in thread
From: iansolo @ 2005-02-02 16:32 UTC (permalink / raw)
  To: netfilter

Hi All,
I've a problem with ftpserver behind a NAT.
My necessity is to run ftpserver in a different port then 21.
This is the situation:

Router
|
Firewall
|
Ftpserver

I use this modules ad pass these parameters :

/sbin/modprobe ip_tables
/sbin/modprobe ip_conntrack
/sbin/modprobe ip_conntrack_ftp ports=21,9000
/sbin/modprobe iptable_nat
/sbin/modprobe ip_nat_ftp ports=21,9000
/sbin/modprobe ipt_MASQUERADE
/sbin/modprobe ipt_state

The realtive iptables rules are only these:

$IPTABLES -t nat -A PREROUTING -p tcp -d $EXT_LAN_FW --dport 9000 -j NAT 
--to-destination $IP_FTPSERVER:9000
$IPTABLES -A FORWARD -i $EXT_IF -p tcp --dport 9000 -j ACCEPT -d 
$IP_FTPSERVER

Unfortunately don't work!


VERY IMPORTANT :

- All work fine is the port is 21!!

- When I try to connect with my ftp-client(with port 9000), at a certain 
point I tray to send packets to local IP of firewall ($EXT_LAN_FW).....

Others Questions:

- In the source code of ip_conntrack_ftp there is a variable "MAX_PORTS",
but I don't understand what mean...
- What is "Patch-O-Matic" ?


Thanks a lot in advance!
iansolo

ps: excuse me, my English is poor



^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2005-02-08 13:54 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2005-02-02 16:32 ftp nat MAX PORTS iansolo
2005-02-07 11:42 ` iansolo
2005-02-07 12:49   ` pom rpc and rsh patches Alexander Piavka
     [not found] ` <bd35181c05020211473cb89b35@mail.gmail.com>
     [not found]   ` <4201D91A.5030500@betisgroup.com>
     [not found]     ` <200502081011.46026.luismnieto@gmail.com>
2005-02-08 13:54       ` ftp nat MAX PORTS iansolo

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.