LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Debian
User Name
Password
Debian This forum is for the discussion of Debian Linux.

Notices

Reply
 
Search this Thread
Old 12-12-2004, 10:46 PM   #1
colabus
Member
 
Registered: Mar 2004
Distribution: Debian Sarge, FC4
Posts: 100

Rep: Reputation: 15
FTP issues


For some time I've had my Debian box run nicely as a gatewat server but just recently I've added another machine to my network and I'm having some issues.

I do alot of file-sharing via FTP and having one main box to do this (WinXP). With this sites I connect to some don't support PASV and some perform ident checks. To combat this I wrote my firewall like below.

Code:
#!/bin/sh

iptables=/sbin/iptables
modprobe=/sbin/modprobe


# Clearing tables..
$iptables -F
$iptables -t nat -F

# Loading modules..
$modprobe ip_conntrack_irc
$modprobe ip_nat_irc
$modprobe ip_conntrack_ftp
$modprobe ip_nat_ftp

# Allowing designated ports..
$iptables -A INPUT -i ppp0 -p tcp --dport 22 -j ACCEPT
$iptables -A INPUT -i ppp0 -p tcp --dport 80 -j ACCEPT
$iptables -A INPUT -i ppp0 -p tcp --dport 113 -j ACCEPT

# Allowing new/already non-ppp0 connections..
$iptables -A INPUT -m state --state NEW -i ! ppp0 -j ACCEPT
$iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT

# Blocking everything..
$iptables -A INPUT -i ppp0 -p all -j DROP

# IP forwarding/masq rules..
echo "1" > /proc/sys/net/ipv4/ip_forward
$iptables -t nat -A POSTROUTING -o ppp0 -j MASQUERADE

# Port forwarding..
$iptables -t nat -A PREROUTING -p tcp --dport 113 -j DNAT --to 192.168.0.5:113
As you can see the last line will forward ident reqs to my main box, but this is a problem when i'm using .5, same thing happens with IRC obviously.

As far as PASV goes i've modified the firewall have allow access on certain ports which are then forwarded to me @ .1, and hence not work @ .5.

My mate told me to load the modules which I have above but they aren't working as I'd like

Does anyone know of a way around this? Any help would honestly be much appreciated
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
FTP issues dpp777 Linux - Networking 4 07-21-2004 10:46 AM
FTP issues (redhat 9.0) Gear_freak2000 Linux - Software 14 06-04-2003 05:15 PM
Beginner FTP issues Tenover Linux - Software 2 03-25-2003 10:38 AM
FTP and Firewall issues plisken Linux - Software 2 03-13-2003 03:03 PM
ftp server issues munyard Linux - Software 1 11-07-2002 08:55 AM


All times are GMT -5. The time now is 09:19 AM.

Main Menu
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration