Re: FTP Uploads Connection Reset

From: Paul Lynch (paul.lynch_at_nospam.com)
Date: 03/29/04

  • Next message: Dvord Direwood: "Re: FTP Uploads Connection Reset"
    Date: Mon, 29 Mar 2004 17:32:20 +0100
    
    

    On Sun, 28 Mar 2004 18:19:28 -0800, Dvord Direwood <dvord@hotmail.com>
    wrote:

    >I'm using ISA Server 2000 SP1, IIS 5.0, MSFTP on a SBS 2000.
    >
    >I'm getting complaints from many remote clients that they are having
    >"connection reset", "connection reset by peer", and authentication errors
    >while uploading files to our FTP server.
    >
    >I have been able to duplicate the issue from home to work, but it's not
    >consistent. Out of 10 file transfer attempts, about half fail,
    >irregardless of number of files transferred, size of files transferred
    >(although problems occur more frequently the larger the total transfer
    >is), or time of day transferred.
    >
    >I've done some packet sniffing at home, as well as at work, just to see
    >if somethings getting dropped or what, but the only thing I see is that
    >when the problem occurs, the server starts sending out requests for a
    >previous packet. The client sends it, and some time later the transfer
    >fails with a 426 code in the log. Depending on what client you use, the
    >effects are slightly different:
    >
    >MS cmdline ftp: When it does fail, the error is connection reset by peer.
    >The log just gives a 426.
    >
    >IE WebFolders: When it does fail, there are several strange entries in
    >the log. An example below:
    >
    >22:49:14 123.456.78.90 0207 [295]USER book - 331 0 0 0 0
    >22:49:14 123.456.78.90 0207 [295]PASS - - 230 0 0 0 0
    >22:49:22 123.456.78.90 0207 [295]DELE E011.dwg - 250 0 0 0 0
    >22:49:53 123.456.78.90 0207 [295]created Copy+of+E011.dwg - 226 0 0
    >790403 18156
    >**Many Uploaded Files**
    >22:54:58 123.456.78.90 0207 [295]created E103.dwg - 226 0 0 1393001 38969
    >**Why opening a new connection???**
    >22:55:58 123.456.78.90 0207 [296]USER 0207 - 331 0 0 0 0
    >22:55:58 123.456.78.90 0207 [296]PASS - - 230 0 0 0 0
    >22:55:58 123.456.78.90 0207 [296]DELE E181.dwg - 550 32 0 0 0
    >**Delete Fails! Why trying to delete file???**
    >22:58:11 123.456.78.90 0207 [295]created E181.dwg - 426 10038 0 598016
    >192781
    >**Notice connection 295 finishes with an error 2 some minutes after the
    >client reconnected with connection 296!!!**
    >
    >I've been monitoring the firewall and there's no port blocking problem.
    >At least none are being recorded in the log (we're using ISA).
    >
    >It's a good thing I'm already bald, because after trying to figure this
    >out, I would be!
    >
    >Any help would be greatly appreciated! Thanks!

    You may not want to hear this but these problems are nearly *always*
    caused by network and connectivity issues.

    However, as you are using ISA Server to publish your FTP site you may
    care to check out these articles to ensure that you have got
    everything setup correctly. This is also where you'll find the best
    advice on using ISA in general :

    http://www.isaserver.org/tutorials/Publishing_FTP_server_on_ISA.html

    http://www.isaserver.org/tutorials/Publishing_an_FTP_Server_on_ISA_Server.html

    Regards,

    Paul Lynch
    MCSE


  • Next message: Dvord Direwood: "Re: FTP Uploads Connection Reset"

    Relevant Pages

    • Re: FTP Server setup... Im so close!
      ... > I have installed the Internet Information Services, etc, and have the FTP ... Your external client is trying to use Passive Mode. ... Since your server is behind NAT, ...
      (microsoft.public.windowsxp.network_web)
    • Re: Microsoft FTP Server problem on W2K?
      ... I have technical responsibility for this FTP implementation, ... Since PASV voids PORT, the client side ... connect to the server from" isn't implied by the text of the RFC. ...
      (microsoft.public.inetserver.iis.security)
    • Re: Telnet/ftp problems SBS2000
      ... | through the server to get internet access everything works. ... | client uses an internet backup company to backup his really vital data, ... I understand that you cannot use ftp service to ... the connection can be established ...
      (microsoft.public.windows.server.sbs)
    • [NEWS] Directory Traversal Vulnerabilities in FTP Clients
      ... vulnerable to certain directory traversal attacks by modified FTP servers. ... file/directory permissions and the privilege level of the client. ... A malicious server could potentially overwrite key files to cause a denial ... your vendor, or the associated CERT vulnerability note, if your product is ...
      (Securiteam)
    • Re: Configure ISA to allow ISA Server to make external FTP Connect
      ... your Server name and select properties, Installation mode is listed at the ... client, as well as being all three at the same time. ... This means that the workstation has the proxy server details ... Enter the name 'FTP Access', press next twice, from the drop down box ...
      (microsoft.public.isa.configuration)