On Jul 5, 2011, at 5:46 PM, Ricardo Rios wrote: > Hi all, hi tom, i have a problem with passive ftp connections, i have 2 > box, boths with shorewall > > lan(10.10.10.0/24)-------Box-1(192.168.41.1)------------Box-2(192.168.41.2)-----------Inet > > Box2 is provider of Box1 with 8 DSLs > > When i connect from Box-2 to any ftp, works all ok, but when i try to > connect from Box-1 i get this on /var/log/firewall > > 21:37:40 insert-master kernel: [832161.057782] nf_ct_ftp: dropping > packetIN=eth4 OUT= MAC=00:0a:cd:1a:d1:95:00:22:6b:be:3c:41:08:00 > SRC=66.199.187.46 DST=192.168.41.1 LEN=102 TOS=0x00 PREC=0x00 TTL=45 > ID=30239 DF PROTO=TCP SPT=21 DPT=50892 SEQ=698644583 ACK=3438176321 > WINDOW=46 RES=0x00 ACK PSH URGP=0 OPT (0101080A932DFE0231935CF7) MARK=0x1 > > Also i get alot of error with DST=Lan-IPs > > I am sure the ftp helper is working on boths servers, what can be the > problem ?
Everything I know about FTP and Shorewall is described at http;//www.shorewall.net/FTP.html -Tom Tom Eastep \ When I die, I want to go like my Grandfather who Shoreline, \ died peacefully in his sleep. Not screaming like Washington, USA \ all of the passengers in his car http://shorewall.net \________________________________________________
PGP.sig
Description: This is a digitally signed message part
------------------------------------------------------------------------------ All of the data generated in your IT infrastructure is seriously valuable. Why? It contains a definitive record of application performance, security threats, fraudulent activity, and more. Splunk takes this data and makes sense of it. IT sense. And common sense. http://p.sf.net/sfu/splunk-d2d-c2
_______________________________________________ Shorewall-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/shorewall-users
