3

I have recently had to rebuild my iptables configuration and when I run

service iptables restart

I now receive the following error line:

iptables: Loading additional modules: nf_conntrack_ftp   [FAILED]

My iptables-config file includes the following line:

IPTABLES_MODULES="nf_conntrack_ftp"

When I run modprobe nf_conntrack_ftp the response is:

FATAL: Module nf_conntrack_ftp not found.

Here's my iptables file:

Table: mangle Chain PREROUTING (policy ACCEPT) num target prot opt source destination

Chain INPUT (policy ACCEPT) num target prot opt source
destination 1 ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0
state NEW tcp dpt:8447 2 ACCEPT tcp -- 0.0.0.0/0
0.0.0.0/0 state NEW tcp dpt:8443

Chain FORWARD (policy ACCEPT) num target prot opt source
destination

Chain OUTPUT (policy ACCEPT) num target prot opt source
destination

Chain POSTROUTING (policy ACCEPT) num target prot opt source
destination

Table: filter Chain INPUT (policy DROP) num target prot opt source destination 1 ACCEPT all -- 0.0.0.0/0
0.0.0.0/0 state RELATED,ESTABLISHED 2 DROP tcp -- 0.0.0.0/0 0.0.0.0/0 tcp flags:0x3F/0x00 3 DROP tcp -- 0.0.0.0/0 0.0.0.0/0 tcp flags:!0x17/0x02 state NEW 4 DROP tcp -- 0.0.0.0/0 0.0.0.0/0
tcp flags:0x3F/0x3F 5 ACCEPT all -- 0.0.0.0/0
0.0.0.0/0 6 ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:80 7 ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0
tcp dpt:443 8 ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0
tcp dpt:25 9 ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0
tcp dpt:995 10 ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0
tcp dpt:143 11 ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0
tcp dpt:993 12 ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0
tcp dpt:22 13 ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0
tcp dpt:110 14 ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0
tcp dpt:465 15 ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0
tcp dpt:8181 16 ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0
tcp dpt:8443 17 ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0

Chain FORWARD (policy ACCEPT) num target prot opt source
destination

Chain OUTPUT (policy ACCEPT) num target prot opt source
destination

It seems nf_conntrack_ftp isn't loading -- how do I load this?

1 Answers1

2

Try issuing the following:

modprobe ip_conntrack & modprobe ip_conntrack_ftp

Then substitute nf_conntrack_ftp with ip_conntrack_ftp in your iptables configuration.

HopelessN00b
  • 54,273