Remove loading of (unneeded) ftp helper module.
This commit is contained in:
parent
7c660f3135
commit
88cb949089
2 changed files with 0 additions and 4 deletions
|
|
@ -111,8 +111,6 @@ start_firewall() {
|
|||
ip6tables -A INPUT -i "$EX_IF" -p tcp --syn -m multiport --dports 80,443 -m conntrack --ctstate NEW -j ACCEPT
|
||||
|
||||
# Service: FTP.
|
||||
modprobe nf_conntrack_ftp
|
||||
echo 1 >/proc/sys/net/netfilter/nf_conntrack_helper # Required to allow nf_conntrack_ftp to actually work.
|
||||
iptables -A INPUT -i "$EX_IF" -p tcp --syn --dport 21 -m conntrack --ctstate NEW -j ACCEPT
|
||||
ip6tables -A INPUT -i "$EX_IF" -p tcp --syn --dport 21 -m conntrack --ctstate NEW -j ACCEPT
|
||||
iptables -A INPUT -i "$EX_IF" -p tcp --syn --dport 20 -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT
|
||||
|
|
|
|||
|
|
@ -111,8 +111,6 @@ start_firewall() {
|
|||
ip6tables -A INPUT -i "$EX_IF" -p tcp -d "$FLOATINGIP6" --syn -m multiport --dports 80,443 -m conntrack --ctstate NEW -j ACCEPT
|
||||
|
||||
# Service: FTP.
|
||||
modprobe nf_conntrack_ftp
|
||||
echo 1 >/proc/sys/net/netfilter/nf_conntrack_helper # Required to allow nf_conntrack_ftp to actually work.
|
||||
iptables -A INPUT -i "$EX_IF" -p tcp -d "$FLOATINGIP" --syn --dport 21 -m conntrack --ctstate NEW -j ACCEPT
|
||||
ip6tables -A INPUT -i "$EX_IF" -p tcp -d "$FLOATINGIP6" --syn --dport 21 -m conntrack --ctstate NEW -j ACCEPT
|
||||
iptables -A INPUT -i "$EX_IF" -p tcp -d "$FLOATINGIP" --syn --dport 20 -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue