All you need is having a forward rule for the ftp-data connection which uses the port below the ftp port e.g: ftp at port 21 ftp-data at port 20 Rune Petersen ----- Original Message ----- From: "Jonathan Humphrey" <jhumphrey@codemasters.com> To: <netfilter@lists.netfilter.org> Sent: Thursday, March 06, 2003 7:20 PM Subject: Passive FTP through IPTables DNAT > Does anyone have a working script for this? > > I'm attempting to hide a FTP server behind a Linux IPTables firewall using > dnat but having problems > > thx! > > > ********************************************************************** > This email and any files transmitted with it are confidential and > intended solely for the use of the individual or entity to whom they > are addressed. If you have received this email in error please notify > the system manager. > > This footnote also confirms that this email message has been swept by > MIMEsweeper for the presence of computer viruses. > > ********************************************************************** > >