iptables -A INPUT -s $PRIVATE -p tcp --dport 20 -j ACCEPT iptables -A INPUT -s $PRIVATE -p tcp --dport 21 -j ACCEPT # FTP on accepte les packets entrants relatifs à des connexions déjà établies iptables -A INPUT -i $INTERNET -p tcp --sport 21 -m state --state ESTABLISHED -j ACCEPT iptables -A OUTPUT -o $INTERNET -p tcp --dport 21 -m state --state NEW,ESTABLISHED -j ACCEPT iptables -A INPUT -i $INTERNET -p tcp --sport 20 -m state --state ESTABLISHED,RELATED -j ACCEPT iptables -A OUTPUT -o $INTERNET -p tcp --dport 20 -m state --state ESTABLISHED -j ACCEPT iptables -A INPUT -i $INTERNET -p tcp --sport 1024:65535 --dport 1024:65535 -m state --state ESTABLISHED -j ACCEPT iptables -A OUTPUT -o $INTERNET -p tcp --sport 1024:65535 --dport 1024:65535 -m state --state ESTABLISHED,RELATED -j ACCEPT |