You might be able to use the RELATED option for the ftp conntrack and mark them. I've not tried this myself, so I don't know if this works. Let us know if it does. Ramin On Sun, Apr 22, 2001 at 10:59:31AM -0400, johan@xxxxxxxxxxxxxx wrote: > Dear guys.. > We know all, that passive ftp took random port at server side, not port 20. > How to limit this passive ftp problem ? > Use mangle feature in iptables ? but how ? > any idea ? > > Thanks a lot. > > Best Regards > > Johan > > > > _______________________________________________ > LARTC mailing list / LARTC@xxxxxxxxxxxxxxx > http://mailman.ds9a.nl/mailman/listinfo/lartc HOWTO: http://ds9a.nl/2.4Routing/