Re: [Fwd: Firewall ( iptables ) enabled for ftp ( active mode & passive mode ) problem]

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



please, load nf_conntrack_ftp module (modprobe nf_conntrack_ftp)
your original iptables rules looks good
ip_conntrack is compiled into kernel already
jkk
--
W dniu 2010-03-27 13:04, Edward. S. P. Leong napisał/ła:
Hello,

[root@host1 ~]# lsmod|grep ftp
[root@host1 ~]#

Output is nothing

And:

[root@host1 ~]# iptables -A INPUT -i eth1 -m nf_conntrack_ftp -p tcp --dport 21 -d 192.168.1.254  -j ACCEPT
iptables v1.4.3.1: Couldn't load match `nf_conntrack_ftp':/lib/xtables/libipt_nf_conntrack_ftp.so: cannot open shared object file: No such file or directory

Try `iptables -h' or 'iptables --help' for more information.
[root@host1 ~]#

No of the modules can't be loaded...

Any other help ?

Thanks !

jkk@xxxxxxxxxxxxxxxx wrote:
What is output from command:
lsmod|grep ftp

module nf_conntrack_ftp is a must for passive mode

Dnia 27 Marca 2010, 09:42, So, Edward. S. P. Leong napisa�(a):
  
ftp client ( passive mode ) :
227 Entering Passive Mode (192,168,1,254,226,220).
connecting to 192.168.1.254:58076
- -
connecting to 192.168.1.254:58076
! Connection failed 192.168.1.254 - connection timed out
! connect: error 0
PORT 192,168,1,101,17,247
200 PORT command successful
LIST
150 Opening ASCII mode data connection for file list
Received 61 bytes in 0.1 secs, (6100.00 bps), transfer succeeded
226 Transfer complete

-------- Original Message --------
Subject: 	Firewall ( iptables ) enabled for ftp ( active mode & passive
mode ) problem
Date: 	Sat, 27 Mar 2010 16:39:01 +0800
From: 	Edward. S. P. Leong <edwardspl@xxxxxxxxxx>
To: 	fedora-list@xxxxxxxxxx <fedora-list@xxxxxxxxxx>,
proftp-user@xxxxxxxxxxxxxxxxxxxxx



Dear All,

Mine is FC11 OS...
So, how can we enable the firewall ( iptables ) for using ftp ( active
mode & passive mode ) service ?

For the existing setting :
iptables -F
iptables -X
iptables -F -t nat
iptables -X -t nat
iptables -F -t mangle
iptables -X -t mangle

iptables -P INPUT DROP
iptables -P OUTPUT ACCEPT
iptables -P FORWARD ACCEPT
iptables -t nat -P OUTPUT ACCEPT
iptables -t nat -P PREROUTING ACCEPT
iptables -t nat -P POSTROUTING ACCEPT
iptables -t mangle -P PREROUTING ACCEPT
iptables -t mangle -P POSTROUTING ACCEPT
iptables -t mangle -P INPUT ACCEPT
iptables -t mangle -P OUTPUT ACCEPT
iptables -t mangle -P FORWARD ACCEPT

iptables -A INPUT -i lo -j ACCEPT
iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT

int="eth1"
int_add="192.168.1.254"
int_src="192.168.1.0/24"
# Only allow users to use port 22 ( ssh services ) :
iptables -A INPUT -i $int -p tcp --dport 22 -s $int_src -d $int_add -j
ACCEPT
# Only allow users to use port 20 & 21 ( ftp services ) :
iptables -A INPUT -i $int -p tcp --dport 20 -s $int_src -d $int_add -j
ACCEPT
iptables -A INPUT -i $int -p tcp --dport 21 -s $int_src -d $int_add -j
ACCEPT
# ping ( ICMP )
iptables -A INPUT -i $int -p icmp --icmp-type echo-request -s $int_src
-d $int_add -j ACCEPT

Problem of ftp client :
connection timenout

Thanks !

Edward.


--
users mailing list
users@xxxxxxxxxxxxxxxxxxxxxxx
To unsubscribe or change subscription options:
https://admin.fedoraproject.org/mailman/listinfo/users
Guidelines: http://fedoraproject.org/wiki/Mailing_list_guidelines

    
  



-- 
*****************************************************
* jan k.kaminski, nucl.med.dept, med.univ. of lodz  *
*     pgpkey http://w4u.am.lodz.pl/~jkk/            *
***** BC02 E8F1 7FAE 1138  9182 F56D BC5A 4059 ******
fluctuat nec mergitur
-- 
users mailing list
users@xxxxxxxxxxxxxxxxxxxxxxx
To unsubscribe or change subscription options:
https://admin.fedoraproject.org/mailman/listinfo/users
Guidelines: http://fedoraproject.org/wiki/Mailing_list_guidelines

[Index of Archives]     [Current Fedora Users]     [Fedora Desktop]     [Fedora SELinux]     [Yosemite News]     [Yosemite Photos]     [KDE Users]     [Fedora Tools]     [Fedora Docs]

  Powered by Linux