使用NAT打造FTP服务新法
of accountability, redress of orders and prohibitions. Strengthening the honesty and self-discipains
我们用命令:ipmasqadm portfw -a -P tcp -L 21 -R 21来进行操作。
of accountability, redress of orders and prohibitions. Strengthening the honesty and self-discipline of leading cadres honesty in politics and education work, enhance leaders ability to resist
of accountability, redress of orders and prohibitions. Strengthening the honesty and self-discipline of leading cadres honesty in politics and education work, enhance leaders ability to resist
of accountability, redress of orders and prohibitions. Strengthening the honesty and self-discipline of leading cadres honesty in politics and education work, enhance leaders ability to resist
NAT服务器上的预设policy全为DENY,要设置所有必须的规则,让FTP能顺利向外提供服务。以如下示例说明:
ipchains -A input -i eth0 -p TCP -d 21 -j ACCEPT
ipchains -A forward -p TCP -d 21 -j ACCEPT
ipchains -A output -i eth1 -p TCP -d 21 -j ACCEPT
ipchains -A input -i eth1 -p TCP -s 21 -j ACCEPT
ipchains -A forward -p TCP -s 21 -j ACCEPT
ipchains -A output -i eth0 -p TCP -s 21 -j ACCEPT
ipchains -A input -i eth0 -p TCP -d 2121 -j ACCEPT
ipchains -A forward -p TCP -d 2121 -j ACCEPT
ipchains -A output -i eth1 -p TCP -d 2121 -j ACCEPT
ipchains -A input -i eth1 -p TCP -s 2121 -j ACCEPT
ipchains -A forward -p TCP -s 2121 -j ACCEPT
ipchains -A output -i eth0 -p TCP -s 2121 -j ACCEPT
以上是在没有考虑其它安全要求、单就FTP服务进行设置的情况下,以ipchains作为命令的操作。
ipchains -A input -i eth0 -p TCP -d 21 -j ACCEPT
ipchains -A forward -p TCP -d 21 -j MASQ
ipchains -A output -i eth1 -p TCP -d 21 -j ACCEPT
ipchains -A input -i eth1 -p TCP -s 21 -j ACCEPT
ipchains -A forward -p TCP -s 21 -j MASQ
ipchains -A output -i eth0 -p TCP -s 21 -j ACCEPT
of accountability, redress of o
使用NAT打造FTP服务新法 来自淘豆网m.daumloan.com转载请标明出处.