andrecanhadas
(usa Debian)
Enviado em 29/01/2012 - 16:37h
jona04 escreveu:
------------------ nmap do IP EXTERNO -------------
Starting Nmap 5.21 (
http://nmap.org ) at 2012-01-29 15:23 BRT
Nmap scan report for 18741154028.user.veloxzone.com.br (187.41.154.28)
Host is up (0.025s latency).
Not shown: 997 closed ports
PORT STATE SERVICE
21/tcp open ftp
23/tcp open telnet
80/tcp open http
Nmap done: 1 IP address (1 host up) scanned in 1.95 seconds
--------------------- nmap do IP INTERNO --------------
Starting Nmap 5.21 (
http://nmap.org ) at 2012-01-29 15:25 BRT
Nmap scan report for 192.168.1.108
Host is up (0.000011s latency).
Not shown: 998 closed ports
PORT STATE SERVICE
139/tcp open netbios-ssn
445/tcp open microsoft-ds
Nmap done: 1 IP address (1 host up) scanned in 0.13 seconds
----------- script Firewall -------------------------
iptables -A INPUT -p tcp --dport 2321 -j ACCEPT #FTP
iptables -A INPUT -p tcp --dport 21 -j ACCEPT #FTP
iptables -A INPUT -p tcp --dport 20 -j ACCEPT #FTP
iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
echo 1 > /proc/sys/net/ipv4/ip_forward
iptables -A INPUT -p tcp -i eth0 --dport ssh -j ACCEPT
Estou usando a porta 2321 no vsftpd
Como disse que esta usando o porta 2321 ela esta bloqueada
Limpe suas regras de firewall com isto:
iptables -F
iptables -t nat -F
iptables -t mangle -F
iptables -t filter -F
iptables -X
iptables -Z
Ai sim pode executar os comandos:
iptables -A INPUT -p tcp --dport 2321 -j ACCEPT #FTP
iptables -A INPUT -p tcp --dport 21 -j ACCEPT #FTP
iptables -A INPUT -p tcp --dport 20 -j ACCEPT #FTP
iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
echo 1 > /proc/sys/net/ipv4/ip_forward
iptables -A INPUT -p tcp -i eth0 --dport ssh -j ACCEPT
feito isso posta a saida do nmap externo novamente. junto com a saida do comando iptables -L