Re: VPN to ISA server, can't FTP through it

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



The monitoring Log will tell you what Rule is being used for the FTP.

By default the FTP Application Filter does not allow uploads.

--
Phillip Windell
www.wandtv.com

The views expressed, are my own and not those of my employer, or Microsoft,
or anyone else associated with me, including my cats.
-----------------------------------------------------
Understanding the ISA 2004 Access Rule Processing
http://www.isaserver.org/articles/ISA2004_AccessRules.html

Troubleshooting Client Authentication on Access Rules in ISA Server 2004
http://download.microsoft.com/download/9/1/8/918ed2d3-71d0-40ed-8e6d-fd6eeb6cfa07/ts_rules.doc

Microsoft Internet Security & Acceleration Server: Partners
http://www.microsoft.com/isaserver/partners/default.mspx

Microsoft ISA Server Partners: Partner Hardware Solutions
http://www.microsoft.com/forefront/edgesecurity/partners/hardwarepartners.mspx
-----------------------------------------------------

"jogdial" <jogdial@xxxxxxxxx> wrote in message
news:6bcc320e-f20b-4b68-8157-e3738df66890@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Hi,

I seem to have isolated a problem to the ISA server, but it doesn't
make sense to me.

I have several LAN to LAN IPSEC firewalls that endpoint at my ISA
server and connect to a LAN at another place I work and my home
network. I also have the ISA server setup to accept client VPN
connections using PPTP and L2TP.

These all work fine, but the other day, I set up an FTP server on our
internal network. I can FTP to it and put files on it form our
internal network, and all it's segments... so there are no internal
firewall problems.

The problem occurs when I try to "put" a file using FTP through any of
the VPNs. The VPNs are setup to all all protocols, there is no
filtering of any kind. I can connect to the FTP server and login I
can list, I can get files. I CAN'T put files. I can put files from
the internal network, all segments. But I CAN'T put files through the
VPNs. There is an FTP rule on the ISA server (2004 ISA) for our
public FTP server and that allows external users to FTP to the FTP
server in our DMZ. But the other system in our DMZ that I am trying
to FTP to, but going through a VPN has no rules set up for FTP or
anything else, and I would normally not think you need to right?

when I try to put, I get

ftp> put tmp.tmp
200 PORT command successful.
550 Access is denied.
ftp>

Any insight on this problem would be greatly appreciated...

Thanks


.



Relevant Pages

  • Re: VPN to ISA server, cant FTP through it
    ... FTP connection for that matter. ... through a VPN, will they not be encrypted anyway? ... but have really only been doing simple maintenance on the ISA server, ... Troubleshooting Client Authentication on Access Rules in ISA Server 2004http://download.microsoft.com/download/9/1/8/918ed2d3-71d0-40ed-8e6d- ... ...
    (microsoft.public.isa.vpn)
  • Help with IPFW + NATD + Passive FTP
    ... passive FTP connections through IPFW with NATD enabled. ... $cmd 005 allow all from any to any via dc0 ... # Interface facing Public internet ... # Allow out access to my ISP's Domain name server. ...
    (freebsd-questions)
  • RE: Client Computers cannot upload or download from Remote FTP ser
    ... SBS External NIC - Cannot FTP From this server ... SBS Internal NIC ... FTP server is Checked in Routing and Remote Access - Internet Connection - ...
    (microsoft.public.windows.server.sbs)
  • Re: FTP PUT with Store Unique
    ... The best list for topics related to the Communications Server IP ... command or vice versa. ... Instructs the FTP client not to include a name with the STOU ... -- If NONAME is in effect, no name string specifying a foreign_file value follows ...
    (bit.listserv.ibm-main)
  • RE: Client Computers cannot upload or download from Remote FTP ser
    ... Only FTP via the MS DOS FTP Client ... The server that works is a member of the SBS's Domain, BUT as I indicated, ... the router, not the SBS server. ... The client event log has nothing related logged. ...
    (microsoft.public.windows.server.sbs)