probleme de connection a mon srv ftp - Codes et scripts - Linux et OS Alternatifs
MarshPosté le 05-11-2002 à 13:17:05
voila, j utilise proftp et j ai fai des regles iptables mais le probleme est que lorsque mes regles sont active il est impossible de se connecter a mon ftp. en gros je dois mettre dans filter "input et forward" en accept.
Citation :
# Generated by iptables-save v1.2.2 on Sat Jan 26 16:02:22 2002 *nat REROUTING ACCEPT [42:4177] OSTROUTING ACCEPT [80:6965] UTPUT ACCEPT [83:7557] -A POSTROUTING -s 192.168.0.0/255.255.255.0 -j MASQUERADE COMMIT # Completed on Sat Jan 26 16:02:22 2002 # Generated by iptables-save v1.2.2 on Sat Jan 26 16:02:22 2002 *mangle REROUTING ACCEPT [1179:478951] UTPUT ACCEPT [1173:104477] COMMIT # Completed on Sat Jan 26 16:02:22 2002 # Generated by iptables-save v1.2.2 on Sat Jan 26 16:02:22 2002 *filter :INPUT ACCEPT [854:419769] :FORWARD ACCEPT [0:0] UTPUT ACCEPT [1173:104477] -A INPUT -s 127.0.0.1 -d 127.0.0.1 -j ACCEPT -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT -A INPUT -i eth1 -p udp -m udp --sport 68 --dport 67 -j ACCEPT -A INPUT -i eth1 -p tcp -m tcp --sport 68 --dport 67 -j ACCEPT -A INPUT -i eth1 -p udp -m udp --sport 67 --dport 68 -j ACCEPT -A INPUT -i eth1 -p tcp -m tcp --sport 67 --dport 68 -j ACCEPT -A INPUT -p tcp -m state --state NEW -m tcp --sport 1024:65535 --dport 20 -j ACCEPT -A INPUT -p tcp -m state --state NEW -m tcp --sport 1024:65535 --dport 21 -j ACCEPT -A INPUT -p tcp -m state --state NEW -m tcp --sport 1024:65535 --dport 22 -j ACCEPT -A INPUT -p tcp -m state --state NEW -m tcp --sport 1024:65535 --dport 53 -j ACCEPT -A INPUT -p udp -m state --state NEW -m udp --sport 1024:65535 --dport 53 -j ACCEPT -A INPUT -p tcp -m state --state new -m tcp --sport 1024:65535 --dport 80 -j ACCEPT -A INPUT -p tcp -m state --state new -m tcp --sport 1024:65535 --dport 443 -j ACCEPT -A INPUT -p udp -m state --state NEW -m udp --sport 1024:65535 --dport 27015 -j ACCEPT -A INPUT -p tcp -m state --state new -m tcp --sport 1024:65535 --dport 10000 -j ACCEPT -A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT -A FORWARD -s 192.168.0.0/255.255.255.0 -m state --state NEW -j ACCEPT COMMIT # Completed on Sat Jan 26 16:02:22 2002
Moi je ve input et forward en drop ! comment faire?
Message édité par nikauch le 05-11-2002 à 13:18:00
Marsh Posté le 05-11-2002 à 13:17:05
voila, j utilise proftp et j ai fai des regles iptables mais le probleme est que lorsque mes regles sont active il est impossible de se connecter a mon ftp.
en gros je dois mettre dans filter "input et forward" en accept.
# Generated by iptables-save v1.2.2 on Sat Jan 26 16:02:22 2002
*nat
REROUTING ACCEPT [42:4177]
OSTROUTING ACCEPT [80:6965]
UTPUT ACCEPT [83:7557]
-A POSTROUTING -s 192.168.0.0/255.255.255.0 -j MASQUERADE
COMMIT
# Completed on Sat Jan 26 16:02:22 2002
# Generated by iptables-save v1.2.2 on Sat Jan 26 16:02:22 2002
*mangle
REROUTING ACCEPT [1179:478951]
UTPUT ACCEPT [1173:104477]
COMMIT
# Completed on Sat Jan 26 16:02:22 2002
# Generated by iptables-save v1.2.2 on Sat Jan 26 16:02:22 2002
*filter
:INPUT ACCEPT [854:419769]
:FORWARD ACCEPT [0:0]
UTPUT ACCEPT [1173:104477]
-A INPUT -s 127.0.0.1 -d 127.0.0.1 -j ACCEPT
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -i eth1 -p udp -m udp --sport 68 --dport 67 -j ACCEPT
-A INPUT -i eth1 -p tcp -m tcp --sport 68 --dport 67 -j ACCEPT
-A INPUT -i eth1 -p udp -m udp --sport 67 --dport 68 -j ACCEPT
-A INPUT -i eth1 -p tcp -m tcp --sport 67 --dport 68 -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --sport 1024:65535 --dport 20 -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --sport 1024:65535 --dport 21 -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --sport 1024:65535 --dport 22 -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --sport 1024:65535 --dport 53 -j ACCEPT
-A INPUT -p udp -m state --state NEW -m udp --sport 1024:65535 --dport 53 -j ACCEPT
-A INPUT -p tcp -m state --state new -m tcp --sport 1024:65535 --dport 80 -j ACCEPT
-A INPUT -p tcp -m state --state new -m tcp --sport 1024:65535 --dport 443 -j ACCEPT
-A INPUT -p udp -m state --state NEW -m udp --sport 1024:65535 --dport 27015 -j ACCEPT
-A INPUT -p tcp -m state --state new -m tcp --sport 1024:65535 --dport 10000 -j ACCEPT
-A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -s 192.168.0.0/255.255.255.0 -m state --state NEW -j ACCEPT
COMMIT
# Completed on Sat Jan 26 16:02:22 2002
Moi je ve input et forward en drop !
comment faire?
Message édité par nikauch le 05-11-2002 à 13:18:00
---------------
http://nikauch.dyndns.org/board/