Hello,
i'm just done setting up the fw for a machine that act's as a masquerading proxie and a ftp server. Unfortunately i'm far from a pro on this area, so i'd like to ask here if what i have done about the ftp part is okay or if i messed up. Masquerading works, btw, so there should be at last _some_ hope left :-)
$EXTIF points to my ppp0, ppp0 gets a new dynamic ip each time i dial in.
$IPTABLES -A INPUT -i $EXTIF -p tcp --dport 21 -m state --state NEW,ESTABLISHED,RELATED -j ACCEPT
$IPTABLES -A OUTPUT -o $EXTIF -p tcp --sport 21 -m state --state ESTABLISHED,RELATED -j ACCEPT
$IPTABLES -A INPUT -i $EXTIF -p tcp --sport 1024: --dport 20 -m state
--state ESTABLISHED,RELATED -j ACCEPT
$IPTABLES -A OUTPUT -o $EXTIF -p tcp --dport 1024: --sport 20 -m state
--state ESTABLISHED -j ACCEPT
$IPTABLES -A INPUT -i $EXTIF -p tcp --sport 1024: --dport 1024: -m state
--state ESTABLISHED,RELATED -j ACCEPT
$IPTABLES -A OUTPUT -o $EXTIF -p tcp --sport 1024: --dport 1024: -m state
--state ESTABLISHED -j ACCEPT
Thanks!