Hi!
We have a mikrotik with two WAN connections.
We use mangle rules to mark connection, and routes that take marked connections, thus separating different marked connections to different gateways.
We have rules like:
[admin@PCMEDIC_LX] /ip firewall mangle> print all
Flags: X - disabled, I - invalid, D - dynamic
0 ;;; OUTPUT - WEB - Vodafone
chain=prerouting action=mark-routing new-routing-mark=to_vodafone2 passthrough=no protocol=tcp src-address=192.168.2.0/24 dst-address=!213.63.137.0/24 dst-port=80
1 ;;; OUTPUT - HTTPS - Vodafone
chain=prerouting action=mark-routing new-routing-mark=to_vodafone2 passthrough=no protocol=tcp src-address=192.168.2.0/24 dst-address=!213.63.137.0/24 dst-port=443
2 ;;; OUTPUT - SSH Vodafone
chain=prerouting action=mark-routing new-routing-mark=to_vodafone2 passthrough=no protocol=tcp src-address=192.168.2.0/24 dst-address=!213.63.137.0/24 dst-port=22
These all work quite good.
Now, passive FTP connections are initially made trough port 21, but then it necgociates a different port.
We now need a mangle rule that will mark ftp connections and related connections, else the ftp server will not allow us in.
ftpd log:
Jul 11 12:08:05 your-insight ftpd: pam_unix(proftpd:session): session opened for user cusco by (uid=0)
Jul 11 12:08:05 your-insight ftpd[25910]: your-insight.eu (33.83.136.95.rev.vodafone.pt[95.136.83.33]) - USER cusco: Login successful.
Jul 11 12:08:05 your-insight ftpd[25910]: your-insight.eu (33.83.136.95.rev.vodafone.pt[95.136.83.33]) - Preparing to chroot to directory '/home/cusco'
Jul 11 12:08:15 your-insight ftpd[25910]: your-insight.eu (33.83.136.95.rev.vodafone.pt[95.136.83.33]) - SECURITY VIOLATION: Passive connection from 213.141.21.122 rejected.
Can anybody help?
Thanks in advnace.