On Tue, 4 Jun 2002, Antony Stone wrote:

> On Tuesday 04 June 2002 11:24 pm, Omar Castaneda Acosta wrote:
> 
> > I've never included port 20 on my firewall rules and both passive and
> > active ftp work fine.
> 
> Yeah, but I'll bet you're not translating the service to run on a weird port 
> number, are you ?
> 
> You're almost certainly using "-m state --state RELATED" to handle port 20 
> for you.   Isn't stateful inspection wonderful :-)
> 

And also loading ip_conntrack_ftp.o and ip_nat_ftp.o.

-Tom
-- 
Tom Eastep    \ Shorewall - iptables made easy
AIM: tmeastep  \ http://www.shorewall.net
ICQ: #60745924  \ [EMAIL PROTECTED]


Reply via email to