kmmx
(usa Debian)
Enviado em 02/12/2012 - 03:59h
O meu ProFTPd está sem acesso externo.
Coloquei a máquina como DMZ no doteador, mesmo assim setei a a porta 21 para ele.
Mesmo assim não funciona.
O meu iptables está assim:
root@debian:~# iptables -L
Chain INPUT (policy ACCEPT)
target prot opt source destination
LOG all -- anywhere anywhere LOG level debug prefix `BANDWIDTH_IN:'
Chain FORWARD (policy ACCEPT)
target prot opt source destination
LOG all -- anywhere anywhere LOG level debug prefix `BANDWIDTH_OUT:'
LOG all -- anywhere anywhere LOG level debug prefix `BANDWIDTH_IN:'
Chain OUTPUT (policy ACCEPT)
target prot opt source destination
LOG all -- anywhere anywhere LOG level debug prefix `BANDWIDTH_OUT:'
fiz um sniffer com o tcpdump na pota 21:
root@debian:~# tcpdump -vv dst port 21
tcpdump: listening on eth0, link-type EN10MB (Ethernet), capture size 65535 bytes
03:48:21.163675 IP (tos 0x88, ttl 53, id 10484, offset 0, flags [DF], proto TCP (6), length 60)
187-24-5-75.3g.claro.net.br.40715 > debian.KmmX.ftp: Flags [S], cksum 0x51b5 (correct), seq 3013312231, win 14600, options [mss 1460,sackOK,TS val 2119187 ecr 0,nop,wscale 4], length 0
03:48:23.995228 IP (tos 0x88, ttl 53, id 10485, offset 0, flags [DF], proto TCP (6), length 60)
187-24-5-75.3g.claro.net.br.40715 > debian.KmmX.ftp: Flags [S], cksum 0x4f5c (correct), seq 3013312231, win 14600, options [mss 1460,sackOK,TS val 2119788 ecr 0,nop,wscale 4], length 0
03:48:30.835063 IP (tos 0x88, ttl 53, id 10486, offset 0, flags [DF], proto TCP (6), length 60)
187-24-5-75.3g.claro.net.br.40715 > debian.KmmX.ftp: Flags [S], cksum 0x4aa8 (correct), seq 3013312231, win 14600, options [mss 1460,sackOK,TS val 2120992 ecr 0,nop,wscale 4], length 0
03:48:42.062742 IP (tos 0x88, ttl 53, id 10487, offset 0, flags [DF], proto TCP (6), length 60)
187-24-5-75.3g.claro.net.br.40715 > debian.KmmX.ftp: Flags [S], cksum 0x4140 (correct), seq 3013312231, win 14600, options [mss 1460,sackOK,TS val 2123400 ecr 0,nop,wscale 4], length 0
^C
4 packets captured
4 packets received by filter
0 packets dropped by kernel
root@debian:~# tcpdump -vv src port 21
tcpdump: listening on eth0, link-type EN10MB (Ethernet), capture size 65535 bytes
03:49:14.362614 IP (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto TCP (6), length 60)
debian.KmmX.ftp > 187-24-5-75.3g.claro.net.br.40319: Flags [S.], cksum 0xe005 (correct), seq 2301723679, ack 901073419, win 5792, options [mss 1460,sackOK,TS val 1446333 ecr 2129731,nop,wscale 6], length 0
03:49:16.726925 IP (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto TCP (6), length 60)
debian.KmmX.ftp > 187-24-5-75.3g.claro.net.br.40319: Flags [S.], cksum 0xddb6 (correct), seq 2301723679, ack 901073419, win 5792, options [mss 1460,sackOK,TS val 1446924 ecr 2129731,nop,wscale 6], length 0
03:49:17.760307 IP (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto TCP (6), length 60)
debian.KmmX.ftp > 187-24-5-75.3g.claro.net.br.40319: Flags [S.], cksum 0xdcb3 (correct), seq 2301723679, ack 901073419, win 5792, options [mss 1460,sackOK,TS val 1447183 ecr 2129731,nop,wscale 6], length 0
03:49:23.429307 IP (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto TCP (6), length 60)
debian.KmmX.ftp > 187-24-5-75.3g.claro.net.br.40319: Flags [S.], cksum 0xd72a (correct), seq 2301723679, ack 901073419, win 5792, options [mss 1460,sackOK,TS val 1448600 ecr 2129731,nop,wscale 6], length 0
03:49:24.160262 IP (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto TCP (6), length 60)
debian.KmmX.ftp > 187-24-5-75.3g.claro.net.br.40319: Flags [S.], cksum 0xd673 (correct), seq 2301723679, ack 901073419, win 5792, options [mss 1460,sackOK,TS val 1448783 ecr 2129731,nop,wscale 6], length 0
03:49:35.477591 IP (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto TCP (6), length 60)
debian.KmmX.ftp > 187-24-5-75.3g.claro.net.br.40319: Flags [S.], cksum 0xcb66 (correct), seq 2301723679, ack 901073419, win 5792, options [mss 1460,sackOK,TS val 1451612 ecr 2129731,nop,wscale 6], length 0
03:49:36.960283 IP (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto TCP (6), length 60)
debian.KmmX.ftp > 187-24-5-75.3g.claro.net.br.40319: Flags [S.], cksum 0xc9f3 (correct), seq 2301723679, ack 901073419, win 5792, options [mss 1460,sackOK,TS val 1451983 ecr 2129731,nop,wscale 6], length 0
03:49:54.807819 IP (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto TCP (6), length 60)
debian.KmmX.ftp > 187-24-5-75.3g.claro.net.br.40715: Flags [S.], cksum 0x75e6 (correct), seq 1435856700, ack 3013312232, win 5792, options [mss 1460,sackOK,TS val 1456444 ecr 2119187,nop,wscale 6], length 0
03:49:55.560277 IP (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto TCP (6), length 60)
debian.KmmX.ftp > 187-24-5-75.3g.claro.net.br.40715: Flags [S.], cksum 0x7529 (correct), seq 1435856700, ack 3013312232, win 5792, options [mss 1460,sackOK,TS val 1456633 ecr 2119187,nop,wscale 6], length 0
03:49:58.830067 IP (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto TCP (6), length 60)
debian.KmmX.ftp > 187-24-5-75.3g.claro.net.br.40319: Flags [S.], cksum 0xb498 (correct), seq 2301723679, ack 901073419, win 5792, options [mss 1460,sackOK,TS val 1457450 ecr 2129731,nop,wscale 6], length 0
03:50:00.960286 IP (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto TCP (6), length 60)
debian.KmmX.ftp > 187-24-5-75.3g.claro.net.br.40319: Flags [S.], cksum 0xb283 (correct), seq 2301723679, ack 901073419, win 5792, options [mss 1460,sackOK,TS val 1457983 ecr 2129731,nop,wscale 6], length 0
^C
11 packets captured
11 packets received by filter
0 packets dropped by kernel
root@debian:~#
Alguém tem alguma idéia do que pode ser feito?