From: Richard <netfilter@ghz.fr>
To: Patrik <patrik@chorus.com.br>, netfilter@lists.netfilter.org
Subject: Re: RES: RES: IPtables settings to access a backup FTP
Date: Sat, 18 Aug 2007 21:58:55 +0200 [thread overview]
Message-ID: <46C74F7F.4080502@ghz.fr> (raw)
In-Reply-To: <01ac01c7e1d0$3d1a00f0$150aa8c0@station21>
thanks but I don't understant about the eth1, my network only runs on
eth0 ... could you explain what the whole line does?
Thanks !
Patrik a écrit :
> --syn is a Synonym for --tcp-flags SYN, RST and ACK
>
>
>
> Chorus Informatica
> Patrik Souza - Diretor
> Fone: 11 5621-6177
> Mobile: 11 8154-0794
>
> A informação contida nesta mensagem é confidencial. É destinada somente para
> uso do(s) indivíduo(s) e/ou entidade(s) para os quais foi endereçada. Se
> você não é o destinatário pretendido, fica desde já notificado de que
> qualquer revelação, cópia, disseminação ou uso desta mensagem ou das
> informações nela contidas é estritamente proibido. Se você recebeu esta
> mensagem erroneamente, por favor, notifique-nos por correio eletrônico e
> apague-a do seu sistema. / The information contained in this message is
> confidential. It is intended solely for the use of the individual(s) and/or
> entity (ies) addressed above. If you are not the intended recipient, you are
> hereby notified that any disclosure, copying, dissemination or using this
> message or the information contained herein is strictly prohibited. If you
> have received this message in error, please notify us by electronic mail and
> please delete the message from your system.
>
>
> -----Mensagem original-----
> De: netfilter-bounces@lists.netfilter.org
> [mailto:netfilter-bounces@lists.netfilter.org] Em nome de Richard
> Enviada em: sábado, 18 de agosto de 2007 16:27
> Para: patrik@chorus.com.br; netfilter@lists.netfilter.org
> Assunto: Re: RES: IPtables settings to access a backup FTP
>
> Hi thanks, could you explain what this line does ?
>
> This is what I understand :
>
> Foward incomming form eth0 to Output eth1 with tcp port 21 but I dont
> understant the --syn or exactly what this whole line does ...
>
> Patrik a écrit :
>> Richard, try to use
>>
>> # iptables -A FORWARD -i eth0 -o eth1 -p tcp --syn --dport 21 -j ACCEPT
>>
>> I think that´s solve
>>
>>
>> Chorus Informatica
>> Patrik Souza - Diretor
>> Fone: 11 5621-6177
>> Mobile: 11 8154-0794
>>
>> A informação contida nesta mensagem é confidencial. É destinada somente
> para
>> uso do(s) indivíduo(s) e/ou entidade(s) para os quais foi endereçada. Se
>> você não é o destinatário pretendido, fica desde já notificado de que
>> qualquer revelação, cópia, disseminação ou uso desta mensagem ou das
>> informações nela contidas é estritamente proibido. Se você recebeu esta
>> mensagem erroneamente, por favor, notifique-nos por correio eletrônico e
>> apague-a do seu sistema. / The information contained in this message is
>> confidential. It is intended solely for the use of the individual(s)
> and/or
>> entity (ies) addressed above. If you are not the intended recipient, you
> are
>> hereby notified that any disclosure, copying, dissemination or using this
>> message or the information contained herein is strictly prohibited. If you
>> have received this message in error, please notify us by electronic mail
> and
>> please delete the message from your system.
>>
>> -----Mensagem original-----
>> De: netfilter-bounces@lists.netfilter.org
>> [mailto:netfilter-bounces@lists.netfilter.org] Em nome de Richard
>> Enviada em: sábado, 18 de agosto de 2007 16:09
>> Para: netfilter@lists.netfilter.org
>> Assunto: IPtables settings to access a backup FTP
>>
>> Hello, this is my first message so I hope I'm doing this right ! :)
>>
>> I've got iptables setup and running well on my server and up to now I've
>> not had any problems, however I have just installed a backup system
>> which needs to connect by FTP to a distant server.
>>
>> With my firewall disactivated all works fine, however with the firewall
>> activated when I use the "ls" command of the debian ftp command line
>> package (CWD) I get:
>>
>> 200 ok then a long wait then :
>> 421 Service not available, remote server has closed connection.
>>
>> I've tried this on two different FTP's and it only works if the firewall
>> is disactivated.
>>
>> One server is a plesk server but the server I need to connect to I do
>> not know much about, with filezilla on my pc I've managed to connect to
>> it with both FTP active and FTP passive so I guess it can do both.
>>
>> On my server I just do :
>>
>> ftp ftp.server.com
>> username
>> password
>>
>> So I'm not sure if it connects as passive or active.
>>
>> These are the ports that I have got open :
>>
>> -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
>> -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
>>
>> -A INPUT -p tcp -m tcp --dport 20 -j ACCEPT
>> -A INPUT -p tcp -m tcp --dport 21 -j ACCEPT
>>
>> -A OUTPUT -p tcp -m tcp --dport 20 -j ACCEPT
>> -A OUTPUT -p tcp -m tcp --dport 21 -j ACCEPT
>>
>> Which ports do you suggest I should open to connect to this FTP server ?
>>
>> Thanks in advance,
>>
>> Richard
>>
>>
>>
>
>
parent reply other threads:[~2007-08-18 19:58 UTC|newest]
Thread overview: expand[flat|nested] mbox.gz Atom feed
[parent not found: <01ac01c7e1d0$3d1a00f0$150aa8c0@station21>]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=46C74F7F.4080502@ghz.fr \
--to=netfilter@ghz.fr \
--cc=netfilter@lists.netfilter.org \
--cc=patrik@chorus.com.br \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.