LinuxSir.cn,穿越时空的Linuxsir!

 找回密码
 注册
搜索
热搜: shell linux mysql
12
返回列表 发新帖
楼主: guanhuaming

内网建ftp的问题

[复制链接]
发表于 2004-6-9 18:51:54 | 显示全部楼层
我知道啦。但给state New了呀。

下面是摘录的一部分
/usr/share/doc/iptables/html/NAT-HOWTO.html

7. Special Protocols

   Some protocols do not like being NAT'ed. For each of these protocols, two extensions must be written; one for the connection tracking of the protocol, and one for the actual NAT.

   Inside the netfilter distribution, there are currently modules for ftp: ip_conntrack_ftp.o and ip_nat_ftp.o. If you insmod these into your kernel (or you compile them in permanently), then doing any kind of NAT on ftp connections should work. If you don't, then you can only use passive ftp, and even that might not work reliably if you're doing more than simple Source NAT.

8. Caveats on NAT

   If you are doing NAT on a connection, all packets passing both ways (in and out of the network) must pass through the NAT'ed box, otherwise it won't work reliably. In particular, the connection tracking code reassembles fragments, which means that not only will connection tracking not be reliable, but your packets may not get through at all, as fragments will be withheld.
发表于 2004-6-9 19:14:32 | 显示全部楼层
应该是21端口和20端口,不是22
发表于 2004-12-9 02:27:16 | 显示全部楼层

这两句怎么执行不了呀?

[root@atai ezip]# iptables -t nat -A PREROUTING -p tcp --dport 21 -j DNAT --to $FTL_localnet
iptables v1.2.11: Unknown arg `--to'
Try `iptables -h' or 'iptables --help' for more information.
[root@atai ezip]# iptables -A FORWARD -p tcp -d $FTL_localnet --dport 21 -m state --state NEW -j ACCEPT
Bad argument `21'
Try `iptables -h' or 'iptables --help' for more information.
[root@atai ezip]#

请faint再仔细讲讲好吗?
发表于 2004-12-9 05:33:27 | 显示全部楼层
ez-ipupdate
记得这东东怎么设置,提交的都是内网的保留IP,使用宽带路由多机共享的情况下
您需要登录后才可以回帖 登录 | 注册

本版积分规则

快速回复 返回顶部 返回列表