RE: [Security Firewall] FTP Problem

"Mitchell, Neill" <[email protected]> Thu, 6 Oct 2005 09:19:16 +0100
Newsgroups gmane.linux.mandrake.security.firewall
Message-ID <[email protected]>
This is a multi-part message in MIME format...

------------=_1128586765-811-107
Content-class: urn:content-classes:message
Content-Type: text/plain;
	charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

Do you have an earlier DNAT ftp rule? If you do it will be taking
precedent. Why are you doing DNAT? You realise that all ftp traffic will
go to that one box if you do that? Perhaps that is what you want though.
Have you setup the masquerade rule for the 192.168.1.11 box? I assume
you have allocated it an external IP.

Cheers

-----Original Message-----
From: security-firewall-owner-4qZELD6FgxheH41UXmfQsti2O/[email protected]
[mailto:security-firewall-owner-4qZELD6FgxheH41UXmfQsti2O/[email protected]] On Behalf Of Mark
Tiller
Sent: 06 October 2005 07:06
To: security-firewall-4qZELD6FgxheH41UXmfQsti2O/[email protected]
Subject: [Security Firewall] FTP Problem

Hi All,

I'm having trouble allowing someone to FTP inwards through my MNF 2
firewall.

I'm currently running MNF 1 and MNF 2 in parallel (obviously on separate
boxes) until I can get all my functionality working on MNF 2.  The FTP
server is  at 192.168.1.11.

On MNF 1 I have the following rules which work.

ACCEPT 	wan:nn.nn.nn.nn 	lan:192.168.1.11 	tcp 	ftp
all
ACCEPT 	wan:nn.nn.nn.nn 	lan:192.168.1.11 	tcp 	ftp-data
all


On MNF 2 I have the following rules which do NOT work

DNAT 	wan:nn.nn.nn.nn 	lan:192.168.1.11 	tcp 	ftp

DNAT 	wan:nn.nn.nn.nn 	lan:192.168.1.11 	tcp 	ftp-data

Can anybody tell me what I'm dong wrong?

Thanks in advance

Mark





_____________________________________________________________________
This message has been checked for all known viruses by Minuco delivered
through the MessageLabs Virus Scanning Service. For further infomation
visit http://www.minuco.com or alternatively mail [email protected]



- ------------------------------

minuco
vigilize product suite   |   internet solutions   |   graphic design

31 Museum Street
London WC1A 1LG

t: +44 (0)20 7436 9944
f: +44 (0)20 7436 9955

http://www.minuco.com

You have received this e-mail from minuco. It is intended to be read by the=
 addressee because it could contain confidential and privileged information=
 (including any attachments). If you are not the person or organisation thi=
s e-mail was intended for please return it to the sender and delete it from=
 your computer(s). You must not copy, distribute, disclose, or disseminate =
the contents of this e-mail or its attachments to any third party unless au=
thorised by minuco.

It is the responsibility of the recipient to ensure that the forwarding, op=
ening or use of the e-mail (and any attachments) will not adversely affect =
their systems or data. Please carry out appropriate virus checks.

All rights reserved. The intellectual property in this e-mail and any attac=
hments are vested solely in minuco.
_____________________________________________________________________
This message has been checked for all known viruses by Minuco delivered thr=
ough the MessageLabs Virus Scanning Service. For further infomation visit h=
ttp://www.minuco.com or alternatively mail [email protected]


------------=_1128586765-811-107
Content-Type: text/plain; name="message.footer"
Content-Disposition: inline; filename="message.footer"
Content-Transfer-Encoding: quoted-printable

____________________________________________________
Want to buy your Pack or Services from Mandriva?=20
Go to http://store.mandriva.com
Join the Club : http://www.mandrivaclub.com
____________________________________________________

------------=_1128586765-811-107--