an_gust
(usa Debian)
Enviado em 26/08/2009 - 14:09h
Amigos,
Consegui resolver com as seguintes regras.
#Ativando compartilhamento ftp
modprobe ip_nat_ftp
# Libera Banesfacil
# Abre uma porta FTP (inclusive para a Internet)
iptables -A INPUT -p tcp --dport 21 -j ACCEPT
iptables -A FORWARD -p tcp --dport 21 -j ACCEPT
iptables -A INPUT -p tcp --dport 20 -j ACCEPT
iptables -A FORWARD -p tcp --dport 20 -j ACCEPT
# Abre uma porta (inclusive para a Internet)
iptables -A INPUT -p tcp --dport 4226 -d 200.242.1.11 -j ACCEPT
iptables -A INPUT -p udp --dport 4226 -d 200.242.1.11 -j ACCEPT
iptables -A FORWARD -p udp --dport 4226 -d 200.242.1.11 -j ACCEPT
iptables -A INPUT -p tcp --dport 4226 -d 200.165.48.11 -j ACCEPT
iptables -A INPUT -p udp --dport 4226 -d 200.165.48.11 -j ACCEPT
iptables -A FORWARD -p udp --dport 4226 -d 200.165.48.11 -j ACCEPT
# Abrindo conexao ftp em modo passivo e ativo
iptables -A INPUT -p tcp --sport 20 -m state --state NEW,ESTABLISHED,RELATED -d 200.242.1.11 -j ACCEPT
iptables -A FORWARD -p tcp --sport 20 -m state --state NEW,ESTABLISHED,RELATED -d 200.242.1.11 -j ACCEPT
iptables -A OUTPUT -p tcp --dport 20 -m state --state ESTABLISHED -d 200.242.1.11 -j ACCEPT
iptables -A INPUT -p tcp --sport 20 -m state --state NEW,ESTABLISHED,RELATED -d 200.165.48.11 -j ACCEPT
iptables -A FORWARD -p tcp --sport 20 -m state --state NEW,ESTABLISHED,RELATED -d 200.165.48.11 -j ACCEPT
iptables -A OUTPUT -p tcp --dport 20 -m state --state ESTABLISHED -d 200.165.48.11 -j ACCEPT
iptables -A INPUT -p tcp --sport 21 -m state --state NEW,ESTABLISHED,RELATED -d 200.165.48.11 -j ACCEPT
iptables -A FORWARD -p tcp --sport 21 -m state --state NEW,ESTABLISHED,RELATED -d 200.165.48.11 -j ACCEPT
iptables -A OUTPUT -p tcp --dport 21 -m state --state ESTABLISHED,RELATED -d 200.165.48.11 -j ACCEPT
iptables -A INPUT -p tcp --sport 21 -m state --state NEW,ESTABLISHED,RELATED -d 200.242.1.11 -j ACCEPT
iptables -A FORWARD -p tcp --sport 21 -m state --state NEW,ESTABLISHED,RELATED -d 200.242.1.11 -j ACCEPT
iptables -A OUTPUT -p tcp --dport 21 -m state --state ESTABLISHED,RELATED -d 200.242.1.11 -j ACCEPT
iptables -A INPUT -p tcp --sport 1024: --dport 1024: -m state --state ESTABLISHED -d 200.242.1.11 -j ACCEPT
iptables -A FORWARD -p tcp --sport 1024: --dport 1024: -m state --state ESTABLISHED -d 200.242.1.11 -j ACCEPT
iptables -A OUTPUT -p tcp --sport 1024: --dport 1024: -m state --state ESTABLISHED,RELATED -d 200.242.1.11 -j ACCEPT
iptables -A INPUT -p tcp --sport 1024: --dport 1024: -m state --state ESTABLISHED -d 200.165.48.11 -j ACCEPT
iptables -A FORWARD -p tcp --sport 1024: --dport 1024: -m state --state ESTABLISHED -d 200.165.48.11 -j ACCEPT
iptables -A OUTPUT -p tcp --sport 1024: --dport 1024: -m state --state ESTABLISHED,RELATED -d 200.165.48.11 -j ACCEPT
#FIM BANESFACIL
Aqui na empresa esta funcionando redondo.