RE: lug-bg: VSFTPD + IPTABLES PROBLEM
- Subject: RE: lug-bg: VSFTPD + IPTABLES PROBLEM
- From: bkrosnov@email.domain.hidden (Boyan Krosnov)
- Date: Fri, 25 Jul 2003 13:46:36 +0300
trqbva ti da trackvash ftp konekciite (modprobe ip_conntrack_ftp) i
posle da pozvolqvash vsichki data konekcii.
Za passive mode (data conn high port client -> high port server, adresa
i porta na servera - po izbor na servera)
iptables -I INPUT -i eth0 -m state --state ESTABLISHED,RELATED -j ACCEPT
(neshto takova beshe) v posokata ot klienta kym teb.
Za active mode (data conn port 20 na server -> high port na klienta,
porta na klienta - po izbor na klienta)
prosto trqbva da pozvolqvash konekcii ot port 20 na tvoqta mashina
navsqkyde
iptables -I OUTPUT -o eth0 -p tcp --sport 20 -j ACCEPT
Drug variant e da fiksirash portovete na koito ftp servera ti poluchava
passive mode konekcii
za poveche info www.netfilter.org
BR,
Boyan Krosnov, CCIE#8701
http://boyan.ludost.net/
just another techie speaking for himself
<em class="quotelev1">> -----Original Message-----
<em class="quotelev1">> From: Nikolay Bogdanov Toshev [mailto:niki_at_art.bg]
<em class="quotelev1">> Sent: Friday, July 25, 2003 10:26 AM
<em class="quotelev1">> To: lug-bg_at_linux-bulgaria.org
<em class="quotelev1">> Subject: lug-bg: VSFTPD + IPTABLES PROBLEM
<em class="quotelev1">>
<em class="quotelev1">>
<em class="quotelev1">> Niakoi znae li kak da se razreshi ftp dostapa chrez vsftpd
<em class="quotelev1">> prez iptables?
<em class="quotelev1">> V moia sluchaj az moga da se konektna prez port 21, no kogato
<em class="quotelev1">> se stigne do
<em class="quotelev1">> listing na direktoriata ili niakoia druga transakcia ftp
<em class="quotelev1">> vrazkata zaspiva i
<em class="quotelev1">> sled izvestno vreme spira.
<em class="quotelev1">>
<em class="quotelev1">> Moje li niakoi da dade akal?
<em class="quotelev1">>
<em class="quotelev1">> Blagodaria predvaritelno
<em class="quotelev1">>
<em class="quotelev1">>
<em class="quotelev1">>
<em class="quotelev1">> ==============================================================
<em class="quotelev1">> ==============
<em class="quotelev1">> A mail-list of Linux Users Group - Bulgaria (bulgarian linuxers).
<em class="quotelev1">> http://www.linux-bulgaria.org - Hosted by Internet Group Ltd.
<em class="quotelev1">> - Stara Zagora
<em class="quotelev1">> To unsubscribe: http://www.linux-bulgaria.org/public/mail_list.html
<em class="quotelev1">> ==============================================================
<em class="quotelev1">> ==============
<em class="quotelev1">>
============================================================================
A mail-list of Linux Users Group - Bulgaria (bulgarian linuxers).
http://www.linux-bulgaria.org - Hosted by Internet Group Ltd. - Stara Zagora
To unsubscribe: http://www.linux-bulgaria.org/public/mail_list.html
============================================================================
|