[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: ip_nat_ftp



Mikhail A Antonov wrote:
On Thursday 30 August 2007 17:07, sergio wrote:
 > возможно, где-то (например в FORWARD) не стоит
 > iptables -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT

 все полиси стоят на ACCEPT

А покажи -t nat -L
Chain PREROUTING (policy ACCEPT)
target     prot opt source               destination
DNAT tcp -- anywhere ext_ip tcp dpt:ftp to:192.168.2.2:21

Chain POSTROUTING (policy ACCEPT)
target     prot opt source               destination
SNAT 0 -- 192.168.2.0/24 !192.168.2.0/24 to:194.58.105.39


Chain OUTPUT (policy ACCEPT)
target     prot opt source               destination

И еще, у того ftp-сервера маршрут на внешку идет через этот роутер?

да


--
sergio



Reply to: