diff --git a/Shorewall-docs2/FTP.xml b/Shorewall-docs2/FTP.xml index bbd9daab4..c471ca5a5 100644 --- a/Shorewall-docs2/FTP.xml +++ b/Shorewall-docs2/FTP.xml @@ -15,7 +15,7 @@ - 2004-05-19 + 2004-12-21 2003 @@ -343,6 +343,14 @@ options ip_nat_ftp ports=21,49
Rules + + If you run an FTP server behind your firewall and your server + offers a method of specifying the external IP address of your firewall, + DON'T USE THAT FEATURE OF YOUR SERVER. Using that option will defeat the + purpose of the ftp helper modules and can result in a server that + doesn't work. + + If the policy from the source zone to the destination zone is ACCEPT and you don't need DNAT (see FAQ 30) then you need no rule.