From: Boryan Yotov <yotov@prosyst.com>
To: netfilter@lists.netfilter.org
Subject: Re: Ftp (pass mode ) and Iptables
Date: Thu, 05 Jan 2006 10:14:51 +0100 [thread overview]
Message-ID: <43BCE38B.5080007@prosyst.com> (raw)
In-Reply-To: <d27cd2010601041951n33224017m@mail.gmail.com>
ludi wrote:
> I have a ftp server and run a script of iptables on the server (not a
> nat-gateway). The follow is the script:
>
> iptables -F OUTPUT
> iptables -F INPUT
> iptables -F FORWARD
>
>
>
> iptables -A INPUT -p udp -i eth0 -s 0/0 -d $HOME_ADDR --dport 53 -j ACCEPT
> iptables -A INPUT -p tcp -i eth0 -s 0/0 -d $HOME_ADDR --dport 22 -j ACCEPT
> iptables -A INPUT -p udp -i eth0 -s 0/0 -d $HOME_ADDR --sport 53 -j ACCEPT
> iptables -A INPUT -p tcp -i eth0 -s 0/0 -d $HOME_ADDR --dport 80 -j ACCEPT
> iptables -A INPUT -p icmp -i eth0 -s 0/0 -d $HOME_ADDR -m limit
> --limit 6/m --limit-burst 6 -j ACCEPT
> iptables -A INPUT -i lo -s 0/0 -d 127.0.0.1/32 -j ACCEPT
> iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
> iptables -P INPUT DROP
>
>
> iptables -A OUTPUT -o lo -s 127.0.0.1 -j ACCEPT
> iptables -A OUTPUT -o eth0 -s $HOME_ADDR -j ACCEPT
> iptables -P OUTPUT DROP
> Now, my question is that I can not connect the ftp server with pass
> mode until I stop the iptables. I had tried the ip_conntrack_ftp.o
> module, but it didnt effect.
> Could anyone give me some idea?
Do you have TLS or SSL encryption over the FTP's server command channel?
next prev parent reply other threads:[~2006-01-05 9:14 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2006-01-05 3:51 Ftp (pass mode ) and Iptables ludi
2006-01-05 9:14 ` Boryan Yotov [this message]
2006-01-05 10:18 ` Boryan Yotov
2006-01-05 17:15 ` Eric Marty
2006-01-06 6:30 ` ludi
2006-01-06 9:37 ` Boryan Yotov
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=43BCE38B.5080007@prosyst.com \
--to=yotov@prosyst.com \
--cc=netfilter@lists.netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.