please, load nf_conntrack_ftp module (modprobe nf_conntrack_ftp)
your original iptables rules looks good
ip_conntrack is compiled into kernel already
jkk
--
W dniu 2010-03-27 13:04, Edward. S. P. Leong napisa?/?a:
Hello,
[r...@host1 ~]# lsmod|grep ftp
[r...@host1 ~]#
Output is nothing
And
What is output from command:
lsmod|grep ftp
module nf_conntrack_ftp is a must for passive mode
Dnia 27 Marca 2010, 09:42, So, Edward. S. P. Leong napisaĆ(a):
> ftp client ( passive mode ) :
> 227 Entering Passive Mode (192,168,1,254,226,220).
> connecting to 192.168.1.254:58076
> - -
> connecting