gabrix <gabrix@xxxxxxxxxxxxx> [2006-09-28 00:12]: > I have a debian sarge kernel 2.6 stable and proftpd as ftpd ... .My > ftpd is open to internet users and i accept passive ftping.I have > inserted a PassivePorts 60000 65534 directive in proftpd.conf for > passive connections which it's still a hole of 5534 ports in my > firewall.Could i accept connections to this ports in a state > ESTABLISHED,RELATED in my iptables script ? If you haven't already, you might want to check out the ip_conntrack_ftp and ip_nat_ftp modules. I believe they do some sort of magic with passive FTP. Shane -- Shane Hickey <shane@xxxxxxxxxxxxxxxxxxx>: Network/System Consultant GPG KeyID: 777CBF3F Key fingerprint: 254F B2AC 9939 C715 278C DA95 4109 9F69 777C BF3F