3.5.3. Creating Network Packet Filter Rules
iptablesrules for FTP service, review the information in Section 3.4.1, “Assigning Firewall Marks” concerning multi-port services and techniques for checking the existing network packet filtering rules.
21in the Firewall Mark field. See Section 4.6.1, “The VIRTUAL SERVER Subsection” for details.
22.214.171.124. Rules for Active Connections
iptablescommand allows the LVS router to accept outgoing connections from the real servers that IPVS does not know about:
/sbin/iptables -t nat -A POSTROUTING -p tcp -s n.n.n.0/24 --sport 20 -j MASQUERADE
iptablescommand, n.n.n should be replaced with the first three values for the floating IP for the NAT interface's internal network interface defined in the GLOBAL SETTINGS panel of the Piranha Configuration Tool.