On Tue, 10 Dec 2002, Alexandros Papadopoulos wrote: > In any case, the relevant rules from the output chain are: ^^^^^^^^^^^^^^ Isn't there a rule intented for other purposes, which blocks the passive data channel? > I'd bet that the problem is that the SYN request sent from the client to > my server gets dropped, though. Seems like a conntrack/INPUT thing. I'd setup logging rules to see where and why the connection gets blocked. Regards, Jozsef - E-mail : kadlec@blackhole.kfki.hu, kadlec@sunserv.kfki.hu PGP key : http://www.kfki.hu/~kadlec/pgp_public_key.txt Address : KFKI Research Institute for Particle and Nuclear Physics H-1525 Budapest 114, POB. 49, Hungary