vlad73:
Перфектно
'>
Благодаря много
явно този ред, които си маркирал оправя нещата
iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
Само един проблем имам
пуснал сум proftpd na 2221 порт и от ftp клиента взимам следното съобщение:
Connecting to 192.168.1.99:2221 ...
Status: Connected with 192.168.1.99:2221. Waiting for welcome message...
Response: 220 ProFTPD 1.2.10 Server (ProFTPD Default Installation) [192.168.1.99]
Command: USER simo
Response: 331 Password required for simo.
Command: PASS *******
Response: 230 User simo logged in.
Command: FEAT
Response: 211-Features:
Response: MDTM
Response: REST STREAM
Response: SIZE
Response: 211 End
Command: SYST
Response: 215 UNIX Type: L8
Status: Connected
Status: Retrieving directory listing...
Command: PWD
Response: 257 "/" is current directory.
Command: TYPE A
Response: 200 Type set to A
Command: PASV
Response: 227 Entering Passive Mode (192,168,1,99,129,247).
Command: LIST
Error: Transfer channel can't be opened. Reason: A connection attempt failed because the connected party did not properly respond after a period of time, or established connection failed because connected host has failed to respond.
Error: Could not retrieve directory listing
В man iptables намерих:
string can be "ftp" for packets related to a ftp-session on
default port. For other ports append -portnr to the value, ie.
"ftp-2121".
Но нещо не успях да го добавя
На какво може да се дължи?
ftp-то бачка, щото като спра iptables-restore /etc/iptables.bak
и няма проблем