Thanks for your advice, I have now loaded the ftp conntrack and nat modules and it is now working /sbin/modprobe ip_conntrack_ftp /sbin/modprobe ip_nat_ftp Nevertheless, the problem i'm getting now is that after sometime then i do the 'lsmod command', i don't see the two modules anymore(they disappear after sometime, don't know exactly after how many hours but it is like if i load today, the next day the modules disappear) Please advice, Thanks, Steven -----Original Message----- From: netfilter-admin@xxxxxxxxxxxxxxxxxxx [mailto:netfilter-admin@xxxxxxxxxxxxxxxxxxx]On Behalf Of Philip Craig Sent: Monday, May 26, 2003 3:46 AM To: Steven Mugassa Cc: netfilter@xxxxxxxxxxxxxxxxxxx Subject: Re: Help- can't ftp Steven Mugassa wrote: > I have got Windows machines behind a Red Hat 9.0 Linux router (with SNAT + > CIPE-VPN). The problem i'm getting is that the machines behind that router > can't open ftp sites. The error message is "__ Invalid PORT command" (and > for some sites there is one more error message " __ command not > understood"). However, the router itself can open ftp sites. > > Can this be a problem with ip_conntrack or something else? Have you loaded the ftp conntrack and nat modules? /sbin/modprobe ip_conntrack_ftp /sbin/modprobe ip_nat_ftp -- Philip Craig - philipc@xxxxxxxxxxxx - http://www.SnapGear.com SnapGear - Custom Embedded Solutions and Security Appliances