FTP and Firewalls
Lázaro Morales
lazaro at frioclima.com.cu
Mon Mar 26 18:02:32 UTC 2012
Hello,
I have a question about FTP service and iptables. This is the default
configuration for iptables on Fedora. I just added the 4th rule giving
access to port 21 running vsftpd.
# iptables -nL
Chain INPUT (policy ACCEPT)
target prot opt source destination
ACCEPT all -- 0.0.0.0/0 0.0.0.0/0 state
RELATED,ESTABLISHED
ACCEPT icmp -- 0.0.0.0/0 0.0.0.0/0
ACCEPT all -- 0.0.0.0/0 0.0.0.0/0
ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 state NEW tcp
dpt:21
ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 state NEW tcp
dpt:22
REJECT all -- 0.0.0.0/0 0.0.0.0/0 reject-with
icmp-host-prohibited
Chain FORWARD (policy ACCEPT)
target prot opt source destination
REJECT all -- 0.0.0.0/0 0.0.0.0/0 reject-with
icmp-host-prohibited
Chain OUTPUT (policy ACCEPT)
target prot opt source destination
When I connect through a FTP client like `ftp` all work fine but when I
try through a web browser for example or through `yum` isn't not work.
When I remove the INPUT rules:
# iptables -F INPUT
all start working. I don't understand what is the problem and I don't wish
remove the INPUT rules.
Regards,
Lázaro.
Este mensaje de correo electrónico ha sido procesado por el servidor de Frioclima
More information about the users
mailing list