Quote:
Originally Posted by bhaslinux
it will be lot more easier if you can give us the iptables rules you have used.
iptables -t nat -L
iptables -L
|
I've not set anything on nat-table.
This is an example of my rules, I may add other stuff, but you can understand the point by reading the rows bellow.
Chain INPUT (policy DROP)
target prot opt source destination
ACCEPT all -- anywhere anywhere state RELATED,ESTABLISHED
ACCEPT all -- localhost anywhere
ACCEPT tcp -- anywhere anywhere tcp dpt:ssh state NEW
ACCEPT tcp -- anywhere anywhere tcp dpt:ftp state NEW
Chain FORWARD (policy DROP)
target prot opt source destination
ACCEPT all -- anywhere anywhere state RELATED,ESTABLISHED
Chain OUTPUT (policy ACCEPT)
target prot opt source destination
Note the last rule in the INPUT, (ftp=21). I want to change my listening port to 21001, then I would, of course, replace that rule with --dport 21001 - but it doesn't work then, the contrack_ftp module works only with passive ftp if 21 is used as the listening port. Is there a way to make it work with 21001 for instance, and how im that case?
So, I simply wonder whether there is a way to use iptables ftp-helper modules with an alternative listening port (instead of port 21).