Find the answer to your Linux question:
Results 1 to 5 of 5
Hi Friends, We are using Centos 6, in our system two Ethernet Cards are used one for LAN Access and another one for WAN internet. We are used for Appache ...
Enjoy an ad free experience by logging in. Not a member yet? Register.
  1. #1
    Just Joined!
    Join Date
    Dec 2011
    Posts
    9

    Urgent Help: Need to Restrict Ftp on WAN Allow only on LAN


    Hi Friends,

    We are using Centos 6, in our system two Ethernet Cards are used one for LAN Access and another one for WAN internet.
    We are used for Appache server, for showing demo site to clients.

    So I need to give Restrict permission for the following.
    1. Restrict FTP access on internet WAN. Only LAN users can use FTP.
    2. In internet users (client) can only view Http site. Ftp should restricted on internet.

    Please anyone Help me. Its very Urgent.

  2. #2
    Trusted Penguin Irithori's Avatar
    Join Date
    May 2009
    Location
    Munich
    Posts
    3,391
    The easiest solution is to configure, on which interfaces the http/ftp daemons listen.
    In apache, this is how itīs done:
    mpm_common - Apache HTTP Server
    You must always face the curtain with a bow.

  3. #3
    Just Joined!
    Join Date
    Sep 2007
    Location
    Silver Spring, MD
    Posts
    95

    Post Restrict access to the ftp and websites

    Quote Originally Posted by kavirajan View Post
    Hi Friends,

    We are using Centos 6, in our system two Ethernet Cards are used one for LAN Access and another one for WAN internet.
    We are used for Appache server, for showing demo site to clients.

    So I need to give Restrict permission for the following.
    1. Restrict FTP access on internet WAN. Only LAN users can use FTP.
    2. In internet users (client) can only view Http site. Ftp should restricted on internet.

    Please anyone Help me. Its very Urgent.
    =========================================

    This is Tdsan, you might want to try this.

    ex - 10.10.10.0/24 - Please use your own ip subnet address

    Use this code to address the ftp issue
    Code:
    iptables -I INPUT 1 -p tcp -s 10.10.10.0/24 -m multiport --dport 21 -m state --state NEW -i eth0 -j ACCEPT
    Use this code to address the html issue, allows users from the internet to connect to the server from external connect (i.e. 192.168.1.10 - web server)
    Code:
    iptables -I INPUT 2 -p tcp -d 192.168.1.10 -m multiport --dport 80 -m state --state NEW -i eth1 -j ACCEPT
    iptables -I INPUT 3 -p tcp -d 192.168.1.0/24 -m multiport 21 -i eth1 -j DROP

  4. #4
    Just Joined!
    Join Date
    Dec 2010
    Posts
    13
    #This will block ACCESS TO FTP FROM OUTSIDE WORLD
    iptables -I INPUT -i <WAN-Interface-name> -p tcp --dport 20 -j DROP
    iptables -I INPUT -i <WAN-Interface-name> -p tcp --dport 21 -j DROP

    # TO ALLOW ONLY WEB ACCESS FROM OUTSIDE WORLD
    iptables -I INPUT -i <WAN-Interface-name> -p tcp --dport 80 -j ACCEPT

  5. #5
    Just Joined!
    Join Date
    Dec 2011
    Posts
    9
    Thanks for the replies.


    ________________________________________
    thekavirajan.blogspot.com

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •