Welcome to the most active Linux Forum on the web.
Go Back > Forums > Linux Forums > Linux - Security
User Name
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.


  Search this Thread
Old 02-09-2002, 12:22 PM   #1
LQ Newbie
Registered: Feb 2002
Distribution: Red Hat 7.2
Posts: 1

Rep: Reputation: 0
Unhappy Portforwarding with Iptables

Hi all !

I have a problem,, I can't open any ports with my firewall-rules.
I have Red Hat 7.2.

the reson why I whant to open ports is that i want to forward port 21 (ftp) to another computer inside the firewall.
I have a ftp-server there.

Here is my firewall-rules..

insmod ip_conntrack
insmod ip_conntrack_ftp
insmod ip_nat_ftp
insmod iptable_nat
insmod ipt_MASQUERADE

echo "1" > /proc/sys/net/ipv4/ip_forward

#sätter upp starndarregler
iptables -P INPUT ACCEPT

# rensa bort gamla regler
iptables -F
iptables -t nat -F
iptables -X

iptables -A INPUT -i eth0 -p tcp --sport 21 -m state --state NEW,ESTABLISHED -j ACCEPT # Active FTP
iptables -A INPUT -i eth0 -p tcp --sport 20 -m state --state ESTABLISHED,RELATED -j ACCEPT

# logga och kasta all trafik till kedjan - används för att spärra och logga
iptables -N logdrop
iptables -A logdrop -j LOG
iptables -A logdrop DROP

#spärra netbus
iptables -A INPUT -p tcp --destination-port 12345 -j logdrop
iptables -A INPUT -p udp --destination-port 12345 -j logdrop

#om det inte är avsatt till det lokala nätet så ska den ut på nätet
iptables -t nat -A POSTROUTING -d ! -j MASQUERADE

iptables -A INPUT -m state --state NEW -p tcp --syn --dport 21 -j ACCEPT
iptables -A INPUT -m state --state ESTABLISHED,RELATED -p tcp --dport 21 -j ACCEPT

iptables -t nat -A PREROUTING -p tcp -d EXTERNAL_IP --dport 21 -j DNAT --to

iptables -A FORWARD -s -j ACCEPT
iptables -A FORWARD -d -j ACCEPT
iptables -A FORWARD -d -j ACCEPT

Please help me !!!
Old 02-09-2002, 03:17 PM   #2
LQ Newbie
Registered: Feb 2002
Location: Mölnlycke (Gothenburg), Sweden
Distribution: Slackware, Slackware, Slackware!
Posts: 2

Rep: Reputation: 0
I think you could use something like this to map port 21 to another computer within your network:

iptables -t nat -A PREROUTING -p tcp --dport 21 -j DNAT --to-destination

Old 02-15-2002, 12:52 AM   #3
Registered: Jan 2002
Location: India
Distribution: CentOS/Mandriva
Posts: 126

Rep: Reputation: 15

Ya I agree with machaus



Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
portforwarding using ipfw thar Linux - Networking 1 08-15-2005 06:38 PM
portforwarding joel b Linux - Newbie 3 05-11-2005 05:01 PM
Very Stupid Question about Iptables & Portforwarding kemplej Linux - Networking 20 07-27-2004 03:37 PM
IPTABLES and PortForwarding ComFox Linux - Networking 1 09-09-2002 05:37 PM
iptables and portforwarding gseven1 Linux - Networking 1 02-22-2002 11:20 AM

All times are GMT -5. The time now is 10:34 AM.

Main Menu
Write for LQ is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration