Skip to content

notas mentais de um nerd

tecnologia e finanças

Menu
  • Inicio
  • Sobre
  • BITcontrol
  • Pesquisar
Menu

iptables para liberar o FTP ativo

Posted on março 18, 2011

iptables -F FORWARD
iptables -F OUTPUT
iptables -F INPUT
iptables -F -t nat

#isso é o importante
depmod -a
/sbin/modprobe ip_conntrack_ftp
/sbin/modprobe ip_conntrack
/sbin/modprobe iptable_nat
/sbin/modprobe iptable_mangle
/sbin/modprobe iptable_filter
#/sbin/modprobe ipt_unclean
/sbin/modprobe ipt_tos
/sbin/modprobe ipt_tcpmss
/sbin/modprobe ipt_state
/sbin/modprobe ipt_owner
/sbin/modprobe ipt_multiport
/sbin/modprobe ipt_mark
/sbin/modprobe ipt_mac
/sbin/modprobe ipt_limit
/sbin/modprobe ipt_TOS
/sbin/modprobe ipt_TCPMSS
/sbin/modprobe ipt_REJECT
/sbin/modprobe ipt_REDIRECT
#/sbin/modprobe ipt_MIRROR
modprobe ip_nat_ftp
iptables -I FORWARD -m state –state RELATED,ESTABLISHED -j ACCEPT
##

iptables -t nat -A POSTROUTING -o eth1 -j MASQUERADE
# Allow FTP connections @ port 21
iptables -A INPUT -p tcp –sport 21 -m state –state ESTABLISHED -j ACCEPT
iptables -A OUTPUT -p tcp –dport 21 -m state –state NEW,ESTABLISHED -j ACCEPT

# Allow Active FTP Connections
iptables -A INPUT -p tcp –sport 20 -m state –state ESTABLISHED,RELATED -j ACCEPT
iptables -A OUTPUT -p tcp –dport 20 -m state –state ESTABLISHED -j ACCEPT

# Allow Passive FTP Connections
iptables -A INPUT -p tcp –sport 1024: –dport 1024: -m state –state ESTABLISHED -j ACCEPT
iptables -A OUTPUT -p tcp –sport 1024: –dport 1024: -m state –state ESTABLISHED,RELATED -j ACCEPT

Compartilhe isso:

  • Clique para compartilhar no X(abre em nova janela) 18+
  • Clique para compartilhar no Facebook(abre em nova janela) Facebook
  • Clique para imprimir(abre em nova janela) Imprimir
©2025 notas mentais de um nerd | Design: Newspaperly WordPress Theme