`
cakin24
  • 浏览: 1328056 次
  • 性别: Icon_minigender_1
  • 来自: 西安
社区版块
存档分类
最新评论

iptables场景二——ftp被动模式

阅读更多
一 配置方法一


 
二 配置方法一设置
1、配置前测试
[root@localhost ~]# ftp 192.168.0.103
Connecting to 192.168.0.108:22...
Connection established.
To escape to local shell, press 'Ctrl+Alt+]'.
 
Last login: Sat Aug 19 11:46:14 2017 from 192.168.0.107
[root@localhost ~]# ftp 192.168.0.103
Connected to 192.168.0.103 (192.168.0.103).
220 (vsFTPd 3.0.2)
Name (192.168.0.103:root): anonymous
331 Please specify the password.
Password:
230 Login successful.
Remote system type is UNIX.
Using binary mode to transfer files.
ftp> ls
227 Entering Passive Mode (192,168,0,103,223,71).
ftp: connect: Connection refused
2、配置ftp配置文件
[root@localhost Packages]# vim /etc/vsftpd/vsftpd.conf
129 pasv_min_port=50000
130 pasv_max_port=60000
[root@localhost Packages]# systemctl restart vsftpd.service
3、配置ftp的iptables规则
[root@localhost Packages]# iptables -I INPUT -p tcp --dport 50000:60000 -j ACCEPT
[root@localhost Packages]# iptables -nL
Chain INPUT (policy ACCEPT)
target prot opt source destination
ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpts:50000:60000
ACCEPT all -- 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED
ACCEPT icmp -- 0.0.0.0/0 0.0.0.0/0
ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:22
ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:21
REJECT all -- 0.0.0.0/0 0.0.0.0/0 reject-with icmp-port-unreachable
4、配置后测试
ftp> ls
227 Entering Passive Mode (192,168,0,103,204,179).
150 Here comes the directory listing.
drwxr-xr-x 2 0 0 6 Nov 05 2016 pub
226 Directory send OK.
三 配置方法二


 
四 配置方法二设置
[root@localhost Packages]# iptables -D INPUT -p tcp --dport 50000:60000 -j ACCEPT
[root@localhost Packages]# iptables -nL
[root@localhost Packages]# iptables -nL
Chain INPUT (policy ACCEPT)
target prot opt source destination
ACCEPT all -- 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED
ACCEPT icmp -- 0.0.0.0/0 0.0.0.0/0
ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:22
ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:21
REJECT all -- 0.0.0.0/0 0.0.0.0/0 reject-with icmp-port-unreachable
 
临时生效:
[root@localhost Packages]# modprobe nf_conntrack_ftp
永久生效:
[root@localhost Packages]# vi /etc/sysconfig/iptables-config
IPTABLES_MODULES="nf_conntrack_ftp"

 

 
  • 大小: 116.1 KB
  • 大小: 123.2 KB
分享到:
评论

相关推荐

Global site tag (gtag.js) - Google Analytics