IT/리눅스(linux)
FTP Passive Mode 설정(vsftpd) 및 iptables
이금성
2015. 10. 15. 15:49
1. vsftpd 설정
/etc/vsftpd/vsftpd.conf 에 다음 내용을 추가합니다.
pasv_enable=YES
pasv_promiscuous=YES
pasv_min_port=20000
pasv_max_port=20010
2. vsftpd 재시작
service vsftpd restart
2. iptables 설정
vi /etc/sysconfig/iptables
-A INPUT -p tcp -m tcp --dport 21 -j ACCEPT
-A INPUT -p tcp -m tcp --sport 21 --dport 1024:65535 -m state --state ESTABLISHED -j ACCEPT
-A INPUT -p tcp -m tcp --dport 20000:20010 -j ACCEPT
-A INPUT -p tcp -m tcp --sport 20000:20010 --dport 1024:65535 -m state --state ESTABLISHED -j ACCEPT
3. iptables 재시작
service iptables restart