Menu
NullMind's Lair
  • Home
  • Statue Collection
  • Jacket Collection
  • Contact
  • Archives
  • About
NullMind's Lair

Iptables w/ Proftpd

Posted on April 27, 2005 by NullMind

To minimize the range of open ports for iptables to allow “Passive” or “PASV” connections

in /etc/proftpd insert:

PassivePorts 60150 60200

Put in under the “Port” entry

then in Iptables rules:

iptables -t filter -A INPUT -p tcp –dport 60150:60200 -j ACCEPT

Related

6 thoughts on “Iptables w/ Proftpd”

  1. Oliver Demetz says:
    July 10, 2005 at 4:28 am

    NOTE: ****IMPORTANT****
    if proftp still does not work, then insert

    UseReverseDNS off

    into your proftpd.conf!!!
    It’s because if you chroot your users with sth. like “Default Root ~”, the /etc/hosts file won’t be visible for proftp anymore, so it will hang up on reverseLookups!

  2. Greg Forrest says:
    September 27, 2005 at 10:22 am

    When I enter this, there seems to a problem with the -dport 60150:60200 part. Oops. I just noticed there is two dashes there. Just pointing it out for anyone else that might not be as observant as me. 🙂

  3. Greg Forrest says:
    September 27, 2005 at 10:38 am

    I forgot to say Thanks! This was exactly what I was looking for. Active mode now works for me.

    I have one more problem though. When I login using Pasv mode, it hangs on LIST. Any idea why?

  4. nullmind says:
    September 27, 2005 at 4:14 pm

    This should make PASV mode work, post here your iptables config

  5. Greg Forrest says:
    September 28, 2005 at 9:26 am

    Here it is. The server is behind a router and I set the router to forward ports 60150-60200, 21, 80, and 22 to my local ip of 192.168.2.101. I’m new to iptables (and linux administering) so there are probably better setups to use than what I have here.

    iptables -L
    Chain INPUT (policy ACCEPT)
    target prot opt source destination
    ACCEPT tcp — anywhere anywhere tcp dpts:60150:6020
    0
    ACCEPT tcp — anywhere anywhere tcp dpt:http
    ACCEPT tcp — anywhere anywhere tcp dpt:ssh
    ACCEPT tcp — anywhere anywhere tcp dpt:ftp

    Chain FORWARD (policy ACCEPT)
    target prot opt source destination

    Chain OUTPUT (policy ACCEPT)
    target prot opt source destination

  6. nullmind says:
    October 16, 2005 at 1:05 am

    try adding

    ACCEPT tcp — anywhere anywhere tcp spts:60150:6020

    I believe thats the string for S port

    other than that, I would have no idea 🙁

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Carlos Rego – OnApp CVO & Co-Founder

Recent Comments

  • Carlos on French corvette ‘La Légère’
  • NullMind on My Magrette ‘Bronze’ … sort of
  • NullMind on Finally got the work desk fully setup, took forever for some things to arrive due to the delays on the postal system, but it’s finally all here !!
  • Fintan on Finally got the work desk fully setup, took forever for some things to arrive due to the delays on the postal system, but it’s finally all here !!
  • wm. spencer on My Magrette ‘Bronze’ … sort of

Null's Flickr Photos

Відпочинковий комплекс ШепільськаSete CidadesIslamic MuseumBoat in DohaVM-E with 50mm/0.95Double Rainbow
More Photos

Categories

  • Books / Movies (8)
  • Camping (1)
  • Cars (14)
  • Check Ins (69)
  • Computers / Internet (146)
  • Cooking Recipes (2)
  • Family (53)
  • Featured (4)
  • Flights (176)
  • General (107)
  • Models & Statues (42)
  • Photography (276)
  • RC (66)
  • Short Rants (14)
  • Stuff (6)
  • Toonz (24)
  • Trips / Places (36)
  • Uncategorized (38)
  • Vape (3)
  • Voicemails (1)
  • Watches (6)
  • Work (48)

Tag Cloug

1/4 scale 8IGHT-T 8T Azores BSL canon50mmf095 Car Check Ins Copenhagen CPH england Flickr IFTTT Instagram LCY LGW LHR LIS Lisbon london Lviv LWO Marvel PDL Plymouth Prowler Ponta Delgada (Azores) Prowler RC RC NUT sonya7r Statues STN Tattoo Trip Tripit UK2 unitedkingdom VIE Vienna VPS VPS.NET Warsaw WAW Work ¼ Scale

Next Azores Trip

Quick TripFebruary 29, 2020
Going Home to Visit
©2021 NullMind's Lair | Powered by WordPress & Superb Themes