Linux Netfilter discussions
 help / color / mirror / Atom feed
* Ftp (pass mode ) and Iptables
@ 2006-01-05  3:51 ludi
  2006-01-05  9:14 ` Boryan Yotov
  0 siblings, 1 reply; 6+ messages in thread
From: ludi @ 2006-01-05  3:51 UTC (permalink / raw)
  To: netfilter

I have a ftp server and run a script of iptables on the server (not a
nat-gateway).  The follow is the script:

iptables -F OUTPUT
iptables -F INPUT
iptables -F FORWARD



iptables -A INPUT -p udp -i eth0 -s 0/0 -d $HOME_ADDR --dport 53 -j ACCEPT
iptables -A INPUT -p tcp -i eth0 -s 0/0 -d $HOME_ADDR --dport 22 -j ACCEPT
iptables -A INPUT -p udp -i eth0 -s 0/0 -d $HOME_ADDR --sport 53 -j ACCEPT
iptables -A INPUT -p tcp -i eth0 -s 0/0 -d $HOME_ADDR --dport 80 -j ACCEPT
iptables -A INPUT -p icmp -i eth0 -s 0/0 -d $HOME_ADDR -m limit
--limit 6/m --limit-burst 6 -j ACCEPT
iptables -A INPUT -i lo -s 0/0 -d 127.0.0.1/32 -j ACCEPT
iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
iptables -P INPUT DROP


iptables -A OUTPUT -o lo -s 127.0.0.1 -j ACCEPT
iptables -A OUTPUT -o eth0 -s $HOME_ADDR -j ACCEPT
iptables -P OUTPUT DROP
Now, my question is that I can not connect the ftp server with pass
mode until I stop the iptables. I had tried the ip_conntrack_ftp.o
module, but it didnt effect.
Could anyone give me some idea?

^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2006-01-06  9:37 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2006-01-05  3:51 Ftp (pass mode ) and Iptables ludi
2006-01-05  9:14 ` Boryan Yotov
2006-01-05 10:18   ` Boryan Yotov
2006-01-05 17:15   ` Eric Marty
2006-01-06  6:30     ` ludi
2006-01-06  9:37       ` Boryan Yotov

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox