1 class ferm::ftp_conntrack {
3 # Allow non-passive connections to an FTP server
4 @ferm::rule { 'dsa-ftp-conntrack-client':
6 description => 'ftp client connection tracking',
9 rule => 'proto tcp dport 21 CT helper ftp'
12 # Allow passive connections from an FTP client
13 @ferm::rule { 'dsa-ftp-conntrack-server':
15 description => 'ftp server connection tracking',
17 chain => 'PREROUTING',
18 rule => 'proto tcp dport 21 CT helper ftp'