bonjour,
je galère dur, je n'ai pas d'accès au ftp en tant que client à partir de mon LAN.
les modules suivant sont chargés
lsmod |grep ftp
ip_nat_ftp 2272 0
iptable_nat 19060 3 ipt_MASQUERADE,ip_nat_ftp
ip_conntrack_ftp 71344 1 ip_nat_ftp
ip_conntrack 37400 5 ipt_MASQUERADE,ipt_state,ip_nat_ftp,iptable_nat,ip_conntrack_ftp
et mes règles iptables sur la passerelle:
Code :
- [root@ordiyo lionel]# iptables-save
- # Generated by iptables-save v1.2.9 on Sun Sep 10 00:18:00 2006
- *filter
- :INPUT DROP [0:0]
- :FORWARD DROP [0:0]
- :OUTPUT DROP [0:0]
- -A INPUT -s 192.168.0.0/255.255.255.0 -i eth0 -j DROP
- -A INPUT -s 127.0.0.0/255.0.0.0 -i eth0 -j DROP
- -A INPUT -s 10.0.0.0/255.0.0.0 -i eth0 -j DROP
- -A INPUT -s 255.255.255.255 -i eth0 -j DROP
- -A INPUT -i lo -j ACCEPT
- -A INPUT -s 192.168.0.0/255.255.255.0 -d 192.168.0.0/255.255.255.0 -i eth2 -j ACCEPT
- -A INPUT -s 200.33.220.206 -i eth0 -j ULOG
- -A INPUT -s 200.33.220.206 -i eth0 -j DROP
- -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
- -A INPUT -s 212.27.38.253 -i eth0 -p udp -m udp --dport 1024:65535 -j ACCEPT
- -A INPUT -s 212.27.38.253 -i eth0 -p tcp -m tcp --dport 1024:65535 -j ACCEPT
- -A INPUT -i eth0 -p tcp -m tcp --dport 21 -j ULOG
- -A INPUT -i eth0 -p tcp -m tcp --dport 21 -j ACCEPT
- -A INPUT -i eth0 -p tcp -m tcp --dport 6891:6892 -j ACCEPT
- -A INPUT -i eth0 -p tcp -m tcp --dport 6891:6892 -j ULOG
- -A INPUT -p icmp -m state --state RELATED,ESTABLISHED -j ACCEPT
- -A INPUT -p icmp -m state --state NEW -m limit --limit 10/min -j ACCEPT
- -A INPUT -j DROP
- -A FORWARD -s 192.168.0.0/255.255.255.0 -i eth2 -o eth0 -p tcp -m tcp ! --sport 80 -j ACCEPT
- -A FORWARD -d 192.168.0.0/255.255.255.0 -i eth0 -o eth2 -p tcp -m tcp ! --dport 80 -j ACCEPT
- -A FORWARD -m state --state NEW,RELATED,ESTABLISHED -j ACCEPT
- -A FORWARD -j DROP
- -A OUTPUT -o lo -j ACCEPT
- -A OUTPUT -s 192.168.0.0/255.255.255.0 -d 192.168.0.0/255.255.255.0 -o eth2 -j ACCEPT
- -A OUTPUT -d 200.33.220.206 -o eth0 -j ULOG
- -A OUTPUT -d 200.33.220.206 -o eth0 -j DROP
- -A OUTPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
- -A OUTPUT -d 212.27.38.253 -o eth0 -p udp -m udp --dport 1024:65535 -j ACCEPT
- -A OUTPUT -o eth0 -p udp -m udp --dport 554 -j ACCEPT
- -A OUTPUT -o eth0 -p tcp -m tcp --dport 554 -j ACCEPT
- -A OUTPUT -o eth0 -p udp -m udp --dport 53 -j ACCEPT
- -A OUTPUT -o eth0 -p tcp -m tcp --dport 53 -j ACCEPT
- -A OUTPUT -o eth0 -p udp -m udp --dport 67 -j ACCEPT
- -A OUTPUT -o eth0 -p tcp -m tcp --dport 80 -j ACCEPT
- -A OUTPUT -o eth0 -p tcp -m tcp --dport 443 -j ACCEPT
- -A OUTPUT -o eth0 -p tcp -m tcp --dport 110 -j ACCEPT
- -A OUTPUT -o eth0 -p tcp -m tcp --dport 25 -j ACCEPT
- -A OUTPUT -o eth0 -p tcp -m tcp --dport 21 -j ACCEPT
- -A OUTPUT -o eth0 -p tcp -m tcp --dport 1441 -j ACCEPT
- -A OUTPUT -o eth0 -p tcp -m tcp --dport 1755 -j ACCEPT
- -A OUTPUT -o eth0 -p tcp -m tcp --dport 8080 -j ACCEPT
- -A OUTPUT -o eth0 -p tcp -m tcp --dport 1863 -j ACCEPT
- -A OUTPUT -o eth0 -p tcp -m tcp --dport 6891:6892 -j ACCEPT
- -A OUTPUT -o eth0 -p tcp -m tcp --dport 6891:6892 -j ULOG
- -A OUTPUT -p icmp -m state --state NEW,RELATED,ESTABLISHED -j ACCEPT
- -A OUTPUT -o eth0 -p udp -m udp --dport 123 -j ACCEPT
- -A OUTPUT -j DROP
- COMMIT
- # Completed on Sun Sep 10 00:18:00 2006
- # Generated by iptables-save v1.2.9 on Sun Sep 10 00:18:00 2006
- *mangle
- :PREROUTING ACCEPT [2:96]
- :INPUT ACCEPT [2:96]
- :FORWARD ACCEPT [0:0]
- :OUTPUT ACCEPT [0:0]
- :POSTROUTING ACCEPT [0:0]
- COMMIT
- # Completed on Sun Sep 10 00:18:00 2006
- # Generated by iptables-save v1.2.9 on Sun Sep 10 00:18:00 2006
- *nat
- :PREROUTING ACCEPT [2:96]
- :POSTROUTING ACCEPT [0:0]
- :OUTPUT ACCEPT [0:0]
- -A POSTROUTING -s 192.168.0.0/255.255.255.0 -o eth0 -j MASQUERADE
- COMMIT
- # Completed on Sun Sep 10 00:18:00 2006
|
par contre je passe par squid et sur firefox en précissant :3128 pour le ftp ça passe??
là je sèche.
merci lionel