Thanks for ur helpful answers. I am using following settings now and it works: #FTP-TABLE *filter : INPUT DROP [0:0] : FORWARD DROP [0:0] : OUTPUT DROP [0:0] -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT -A INPUT -p tcp -s 212.74.114.60 --sport 20:21 -m state --state NEW -j ACCEPT -A OUTPUT -p tcp -d 212.74.114.60 --dport 20:21 -m state --state NEW -j ACCEPT ################################################################### COMMIT |