FTP server publishing

From: norwich5 (norwich5_at_discussions.microsoft.com)
Date: 11/30/04


Date: Tue, 30 Nov 2004 11:23:01 -0800

I have ISA2004 in a back to back firewall config. ISA external is my
perimeter network on the back firewall. I am able to publish my webserver
sites with no problem. I have run the Server publishing wizard to publish
FTP on the same server as the web sites are published. The ftp site worked
fine before the introduction of ISA. The monitoring logs show the initial
connection (client to the external address/port 21 on the ISA external NIC)
is denied due to the default rule. I have tried setting the From tab to
anywhere and the Networks tab to all networks with no difference.

If instead of the publishing rule I set an access rule to permit FTP and FTP
server FROM the external network, local host, perimeter addresses TO the
internal ftp server, local host, internal network the connection is no longer
denied but instead fails.

I notice in the logs that HTTP connections through ISA typically begin with
an initiation that has no rule associated with it. Basically, the connection
to port 80 on the external NIC of ISA is initiated and then connections to
the internal address of the published server begin. The FTP connection never
gets initiated. I suspect this may be through some System rule, though I
don't know why there wouldn't be one to allow ftp access as well.

Any help is greatly appreciated.

Thanks,



Relevant Pages

  • Re: Problem with RWW, can list computers/servers, cannot get logged in
    ... > When I say "outside the network" I mean accessing the network via a ... > one of two errors at the remote desktop, ... > connection might not be enabled or the computer might be too bust to ... Even turned off connection limits in ISA General... ...
    (microsoft.public.windows.server.sbs)
  • Re: DNS Issues?
    ... server it lists the LAN adapter first then the WAN adapter. ... Open Network Connections window, click the Advanced menu, ... Server local area connection ... are you sure you are using the Vista capable ISA client? ...
    (microsoft.public.windows.server.sbs)
  • Re: VPN not working when i connect through SBS 2003 server running ISA 2004
    ... appears in the Application log in ISA Server 2006 or in ISA Server 2004 ... do not correlate with the network element to which this adapter belongs. ... VPN to another network where there is a Draytek router as ... Telnetting to port 1723 on network 1 seems to elicit a connection. ...
    (microsoft.public.windows.server.sbs)
  • Re: VPN not working when i connect through SBS 2003 server running ISA 2004
    ... appears in the Application log in ISA Server 2006 or in ISA Server 2004 ... do not correlate with the network element to which this adapter belongs. ... will VPN to another network where there is a Draytek ... Telnetting to port 1723 on network 1 seems to elicit a connection. ...
    (microsoft.public.windows.server.sbs)
  • Re: VPN not working when i connect through SBS 2003 server running ISA 2004
    ... appears in the Application log in ISA Server 2006 or in ISA Server 2004 ... ISA Server detected routes through adapter External Area Connection ... the address range of an ISA Server network ... Draytek router as the PPTP VPN endpoint. ...
    (microsoft.public.windows.server.sbs)