Networking Forums

Networking Forums > Computer Networking > Linux Networking > Problem setting up ftp server inside lan (iptables)

Reply
Thread Tools Display Modes

Problem setting up ftp server inside lan (iptables)

 
 
Sam
Guest
Posts: n/a

 
      08-16-2004, 05:38 PM
Hi,

I am trying to set up my ftp server located inside my lan. It thought
everything has been done, but when I try to access the ftp server from
the outside, it fails.

There's got to be something I'm missing here. Any help would be very
appreciated.

Thanks,

Sam



Here are the rules in iptables:

*********

WAN=$(nvram_get wan_ifname)

IPT=/usr/sbin/iptables

for T in filter nat mangle ; do
$IPT -t $T -F
$IPT -t $T -X
done

$IPT -t filter -A INPUT -m state --state INVALID -j DROP
$IPT -t filter -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
$IPT -t filter -A INPUT -p icmp -j ACCEPT
$IPT -t filter -A INPUT -i $WAN -p tcp -j REJECT --reject-with
tcp-reset
$IPT -t filter -A INPUT -i $WAN -j REJECT --reject-with
icmp-port-unreachable
$IPT -t filter -A FORWARD -m state --state INVALID -j DROP
$IPT -t filter -A FORWARD -m state --state RELATED,ESTABLISHED -j
ACCEPT
$IPT -t filter -A FORWARD -i $WAN -m state --state NEW,INVALID -j DROP

$IPT -t nat -A POSTROUTING -o $WAN -j MASQUERADE

****

I added the following to redirect port 20 and 21, and 10000-12000
(passive port range)

iptables -t nat -A PREROUTING -p tcp --dport 20 -j DNAT
--to-destination 192.168.1.20:20

iptables -t nat -A PREROUTING -p tcp --dport 21 -j DNAT
--to-destination 192.168.1.20:21

iptables -t nat -A PREROUTING -p tcp --dport 10000:12000 -j DNAT
--to-destination 192.168.1.20
 
Reply With Quote
 
 
 
 
vhu
Guest
Posts: n/a

 
      08-16-2004, 09:26 PM
Sam wrote:
( .. snip .. )
> $IPT -t filter -A FORWARD -m state --state INVALID -j DROP
> $IPT -t filter -A FORWARD -m state --state RELATED,ESTABLISHED -j
> ACCEPT


Add these lines here:

$IPT -t filter -A FORWARD -i $WAN -d 192.168.1.20 -p tcp --dport 21 -j
ACCEPT

Line above is needed as the next rule drops all new connections from WAN
to LAN.

> $IPT -t filter -A FORWARD -i $WAN -m state --state NEW,INVALID -j DROP

 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Setting up public IP inside firewall: possible? Max Linux Networking 4 09-07-2007 05:29 PM
Cisco 827 NAT + Access server inside problem pc-check Network Routers 0 04-23-2007 04:50 PM
Connect public IP from inside - IPTables Marv Linux Networking 1 03-04-2004 01:07 AM
Iptables: How do I forwarding public IPs into a router inside a privateIP network? Stephen Hurrell Linux Networking 1 11-22-2003 10:17 PM
iptables: redirecting packets inside a firewall pete@mynix.org Linux Networking 3 09-04-2003 08:06 AM



1 2 3 4 5 6 7 8 9 10 11