|
楼主 |
发表于 2004-11-4 00:37:17
|
显示全部楼层
我按老大的帮助,做了设置iptables 中显示如下,但还未成功,
Generated by iptables-save v1.2.8 on Thu Nov 4 00:14:59 2004
*filter
:INPUT ACCEPT [0]
:FORWARD ACCEPT [0]
:OUTPUT ACCEPT [13570]
:RH-Firewall-1-INPUT - [0]
-A INPUT -j RH-Firewall-1-INPUT
-A INPUT -p tcp -m tcp --dport 3701:3740 -j ACCEPT
-A INPUT -i eth0 -p tcp -m tcp --dport 20 --tcp-flags SYN,RST,ACK SYN -j ACCEPT
-A INPUT -i eth0 -p tcp -m tcp --dport 21 --tcp-flags SYN,RST,ACK SYN -j ACCEPT
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -j RH-Firewall-1-INPUT
-A RH-Firewall-1-INPUT -i lo -j ACCEPT
-A RH-Firewall-1-INPUT -p icmp -m icmp --icmp-type 255 -j ACCEPT
-A RH-Firewall-1-INPUT -p esp -j ACCEPT
-A RH-Firewall-1-INPUT -p ah -j ACCEPT
-A RH-Firewall-1-INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A RH-Firewall-1-INPUT -p tcp -m state --state NEW -m tcp --dport 80 -j ACCEPT
-A RH-Firewall-1-INPUT -p tcp -m state --state NEW -m tcp --dport 21 -j ACCEPT
-A RH-Firewall-1-INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
-A RH-Firewall-1-INPUT -j REJECT --reject-with icmp-host-prohibited
COMMIT
# Completed on Thu Nov 4 00:14:59 2004
以下是我ftpaccess 的配置
class all real,guest,anonymous *
limit all 1000 Any /etc/msgs/msg.dead
email root@localhost
loginfails 5
readme README* login
readme README* cwd=*
message /welcome.msg login
message .message cwd=*
compress yes all
tar yes all
chmod no guest,anonymous
delete no guest,anonymous
overwrite no guest,anonymous
rename no guest,anonymous
#Passive mode config
#pasv-allow all xxx.xxx.xxx.xxx
#port-allow all xxx.xxx.xxx.xxx
#passive address xxx.xxx.xxx.xxx 0.0.0.0/0
#(以上3行我不知道应不应该配置--我是从Landfield上看来的),其中xxx.xxx.xxx.xxx是我网卡的地址,机器放在长宽机房#有独立ip)
passive ports 0.0.0.0/0 3701 3740
log transfers anonymous,real inbound,outbound
shutdown /etc/shutmsg
passwd-check rfc822 warn
greeting brief
现在问题是如果我用ssh连上后,在本地用无论用fpt 127.0.0.1,还是ftp xxx.xxx.xxx.xxx都能在passive mode 工作,所以我觉得是不是应该把问题琐定在iptables的配置上呢,
另外ip_conntrack_ftp, ipt_state 这两过模块是不是只要modprobe ip_conntrack_ftp 和 modprobe ipt_state 命令执行后没任何提示就算已经装载了是吗?每次重启后是否还要重新载入。
谢谢,古公也来了,哈哈。。。 |
|