[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Public IP's with 1:1 mapping does not map all ports or passive ftp does not work [long]



Wojciech Ziniewicz wrote:
> 
> I give my customers public ips with SNAT/DNAT (we call it 1:1) ip
> mapping. When A client with lan ip 10.100.1.123 has public ip
> 217.17.x.123 he can use all the apps he want (apps that demand public
> ip or forwardded port) so everything seems to be okay...
> 
> but ...
> 
> a) active ftp does not work

Did you load the ip_conntrack_ftp and ip_nat_ftp iptables helper module?

Hans



Reply to: