modprobe ip_nat_ftp
modprobe ip_conntrack
modprobe ip_conntrack_ftp
2,加上一条规则:
iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
-A INPUT -p tcp -m tcp --dport 21 -j ACCEPT
-A INPUT -p tcp -m tcp --dport 1024:65535 -m state --state RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -p tcp -m tcp --dport 21 -j ACCEPT
-A FORWARD -d 10.101.158.1 -o eth1 -p tcp -m tcp --dport 21 -j ACCEPT
-A FORWARD -s 10.101.158.1 -i eth1 -p tcp -m tcp --sport 21 -m state --state ESTABLISHED -j ACCEPT
-A PREROUTING -d 10.8.0.10 -p tcp -m tcp --dport 21 -j DNAT --to-destination 10.101.158.1:21
阅读(714) | 评论(0) | 转发(0) |