From mboxrd@z Thu Jan 1 00:00:00 1970 From: Michael Gale Subject: Re: FTP passive not working Date: Tue, 13 Apr 2004 14:20:49 -0600 Sender: netfilter-admin@lists.netfilter.org Message-ID: <20040413142049.71d5a1ef@mgalepc.utilitran.com> References: <20040413114125.6d159e42@mgalepc.utilitran.com> <1081879193.3521.1.camel@katala.sterenborg.info> <20040413131336.2d9052b2@mgalepc.utilitran.com> <20040413134334.34894d8f@mgalepc.utilitran.com> <20040413140848.32857beb@mgalepc.utilitran.com> Mime-Version: 1.0 Content-Transfer-Encoding: 7bit Return-path: In-Reply-To: <20040413140848.32857beb@mgalepc.utilitran.com> Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="us-ascii" To: netfilter@lists.netfilter.org Nevermind --- not sure why it is not working --- I was able to get it to work by setting a port range for passive on the FTP server and then forwarding the port range to the FTP server. Michael. On Tue, 13 Apr 2004 14:08:48 -0600 Michael Gale wrote: > Hi, > > The log files from the LOG target show that the OUT interface for > packets > coming after the passive command is issue to be the exteranl interface, which > is wrong since all other commands show the out interface as eth1 the internal > nic. > > Michael. > > > On Tue, 13 Apr 2004 13:43:34 -0600 > Michael Gale wrote: > > > Hello again, > > > > It seems that on tablerule-36 (custom user chain) the --state RELATED > > does not > > work ? > > > > If I add a rule allowing all traffic it works ? > > > > Michael. > > > > > > On Tue, 13 Apr 2004 13:13:36 -0600 > > Michael Gale wrote: > > > > > Hello, > > > > > > I have all the iptable modules built into the kernel. I also forgot to > > > add the > > > for the custom tablerule I have allowed all established and related > > > connections. > > > > > > Michael. > > > > > > > > > On Tue, 13 Apr 2004 19:59:53 +0200 > > > Rob Sterenborg wrote: > > > > > > > On Tue, 2004-04-13 at 19:41, Michael Gale wrote: > > > > > Hello, > > > > > > > > > > I am having trouble getting a FTP connection to work in passive > > > > > mode from > > > > > behind a firewall. > > > > > > > > .... > > > > > > > > > So all rules with regards to this IP / PC are under one rule. > > > > > > > > > > This setup is working fine for all connections accept passive FTP -- > > > > > it seems the firewall is not forwarding the related data connection to > > > > > the internal server. > > > > > > > > Did you load the ip_conntrack_ftp and ip_nat_ftp modules ? > > > > > > > > > > > > Gr, > > > > Rob > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > -- > > > Michael Gale > > > Network Administrator > > > Utilitran Corporation > > > > > > > > > > > > > > > > > > > > > -- > > Michael Gale > > Network Administrator > > Utilitran Corporation > > > > > > > > > > > > > -- > Michael Gale > Network Administrator > Utilitran Corporation > > > > > -- Michael Gale Network Administrator Utilitran Corporation