RE: RE: [Security Firewall] FTP Problem
"Mitchell, Neill" <[email protected]> Fri, 7 Oct 2005 09:18:08 +0100
| Newsgroups | gmane.linux.mandrake.security.firewall |
|---|---|
| Message-ID | <[email protected]> |
This is a multi-part message in MIME format... ------------=_1128673109-811-215 Content-class: urn:content-classes:message Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: quoted-printable Can you post your masquerading NAT settings as well? Cheers. -----Original Message----- From: security-firewall-owner-4qZELD6FgxheH41UXmfQsti2O/[email protected] [mailto:security-firewall-owner-4qZELD6FgxheH41UXmfQsti2O/[email protected]] On Behalf Of Mark Tiller Sent: 06 October 2005 21:48 To: security-firewall-4qZELD6FgxheH41UXmfQsti2O/[email protected] Subject: RE: RE: [Security Firewall] FTP Problem =20 > -----Original Message----- > From: security-firewall-owner-4qZELD6FgxheH41UXmfQsti2O/[email protected]=20 > [mailto:security-firewall-owner-4qZELD6FgxheH41UXmfQsti2O/[email protected]] On Behalf=20 > Of Mitchell, Neill > Sent: 06 October 2005 11:22 > To: security-firewall-4qZELD6FgxheH41UXmfQsti2O/[email protected] > Subject: RE: RE: [Security Firewall] FTP Problem >=20 > Next step is to post a dump of your rules I think :)=20 >=20 > Cheers. 1 ACCEPT fw wan tcp+udp 53 dns_queries enabled=20=09=09=09 2 ACCEPT dmz wan udp 53 dns_queries enabled 3 ACCEPT lan wan udp 53 dns_queries enabled 4 ACCEPT wifi wan udp 53 dns_queries enabled 5 REJECT wan fw tcp 113 ident_port enabled 6 ACCEPT lan fw tcp 22 ssh_port enabled 7 ACCEPT lan fw tcp 8443 mnf_web_admin_port enabled=20=09=09=09 8 ACCEPT fw lan icmp 8 ping enabled 9 ACCEPT lan fw icmp 8 ping enabled 10 ACCEPT lan dmz icmp 8 ping enabled 11 ACCEPT dmz lan icmp 8 ping enabled 12 ACCEPT dmz fw icmp 8 ping enabled 13 ACCEPT fw dmz icmp 8 ping enabled 14 ACCEPT lan wan tcp pop3 receive_mail enabled 15 ACCEPT lan wan tcp smtp send_mail enabled 16 ACCEPT lan wan tcp http web_surfing enabled 17 ACCEPT lan wan tcp https secure_web_surfing enabled=20=09=09=09 18 ACCEPT lan wan tcp ssh ssh enabled 19 ACCEPT lan wan tcp ftp ftp enabled 20 ACCEPT lan wan tcp nntp news enabled 21 ACCEPT fw wan udp ntp time_synchronisation enabled=20=09=09=09 22 ACCEPT lan wan tcp imap internet_mail enabled 23 ACCEPT fw wan icmp 8 Ping enabled 24 ACCEPT fw:20022 wan tcp ftp enabled 25 DNAT wan:aa.aa.aa.aa lan:192.168.1.11 tcp ftp enabled=20=09=09=09 26 DNAT wan:aa.aa.aa.aa lan:192.168.1.11 tcp ftp-data enabled=20=09=09=09 27 DNAT wan:bb.bb.bb.bb lan:192.168.1.11 tcp ftp enabled=20=09=09=09 28 DNAT wan:bb.bb.bb.bb lan:192.168.1.11 tcp ftp-data enabled=20=09=09=09 29 ACCEPT lan wan tcp 28805 enabled 30 DNAT wan:cc.cc.cc.cc lan:192.168.1.11 tcp ftp enabled=20=09=09=09 31 DNAT wan:cc.cc.cc.cc lan:192.168.1.11 tcp ftp-data enabled=20=09=09=09 32 ACCEPT lan wan udp ntp NTP_for_LAN enabled 33 ACCEPT lan wan udp 500 enabled 34 ACCEPT lan wan tcp 50 enabled 35 ACCEPT lan wan udp 2746 enabled 36 ACCEPT lan wan tcp 1797 enabled 37 ACCEPT lan wan tcp 389 enabled 38 ACCEPT fw wan tcp ftp FW_URPMI_updates enabled=20=09=09=09 39 ACCEPT lan wan tcp 1000 enabled 40 ACCEPT lan wan tcp 10000 enabled 41 ACCEPT lan:192.168.1.1 wan tcp 1024:65535 enabled=20=09=09=09 42 DNAT wan:dd.dd.dd.dd lan:192.168.1.11 tcp ftp enabled=20=09=09=09 43 DNAT wan:dd.dd.dd.dd lan:192.168.1.11 tcp ftp-data enabled=20=09=09=09 44 ACCEPT lan wan tcp 18001 enabled 45 ACCEPT lan wan udp 123 enabled 46 DNAT wan lan:192.168.1.5 tcp 4672 enabled=20=09=09=09 47 DNAT wan lan:192.168.1.5:4711 tcp 4711 enabled=20=09=09=09 48 ACCEPT lan:192.168.1.1 wan gre enabled=20=09=09=09 49 ACCEPT lan:192.168.1.1 wan tcp 1723 enabled=20=09=09=09 50 ACCEPT lan wan tcp telnet enabled 51 ACCEPT lan:192.168.1.18 wan tcp 1723 enabled=20=09=09=09 52 REDIRECT lan 3328 tcp www proxy_server enabled=20=09=09=09 53 ACCEPT fw wan tcp www proxy_server enabled 54 ACCEPT lan wan icmp 8 enabled 55 ACCEPT lan:192.168.1.5 wan tcp 1024:65535=20 _____________________________________________________________________ This message has been checked for all known viruses by Minuco delivered through the MessageLabs Virus Scanning Service. For further infomation visit http://www.minuco.com or alternatively mail [email protected] - ------------------------------ minuco vigilize product suite | internet solutions | graphic design 31 Museum Street London WC1A 1LG t: +44 (0)20 7436 9944 f: +44 (0)20 7436 9955 http://www.minuco.com You have received this e-mail from minuco. It is intended to be read by the= addressee because it could contain confidential and privileged information= (including any attachments). If you are not the person or organisation thi= s e-mail was intended for please return it to the sender and delete it from= your computer(s). You must not copy, distribute, disclose, or disseminate = the contents of this e-mail or its attachments to any third party unless au= thorised by minuco. It is the responsibility of the recipient to ensure that the forwarding, op= ening or use of the e-mail (and any attachments) will not adversely affect = their systems or data. Please carry out appropriate virus checks. All rights reserved. The intellectual property in this e-mail and any attac= hments are vested solely in minuco. _____________________________________________________________________ This message has been checked for all known viruses by Minuco delivered thr= ough the MessageLabs Virus Scanning Service. For further infomation visit h= ttp://www.minuco.com or alternatively mail [email protected] ------------=_1128673109-811-215 Content-Type: text/plain; name="message.footer" Content-Disposition: inline; filename="message.footer" Content-Transfer-Encoding: quoted-printable ____________________________________________________ Want to buy your Pack or Services from Mandriva?=20 Go to http://store.mandriva.com Join the Club : http://www.mandrivaclub.com ____________________________________________________ ------------=_1128673109-811-215--