Re: Need Simple FTP Service - Two More Questions

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance




" AA Smith" <SmithRMS@xxxxxxxxxxx> wrote in message
news:uQy6hA8iFHA.320@xxxxxxxxxxxxxxxxxxxxxxx
> Thanks, Lance!
>
> I really appreciate your help.
>
> I installed a third-party FTP application. However to get it to work
> (testing with another computer in my LAN) I had to shut down Windows
> Firewall. Is there some way that I can leave the Firewall running and
> still let folks outside my LAN access files in the FTP Server?
>
> And, in order for them to access my LAN, do I have to have a static IP
> address. My current IP addresses are like 192.168.1.1. I'm not sure if
> or how I might use them as alternatives, but my DNS Server addresses start
> with numbers like 83 and 204.
>
> Again, thanks!
>
> I look forward to hearing from you.
> --
> With kindest regards,
>
> Dick Smith


The router that's connected to your internet connection should be able to
give you the WAN address that people outside your LAN will have to use.
192.168.xxx.xxx addresses like you described won't work off the LAN. These
are reserved for LANS and won't route over the internet.

Most ISP change these WAN addresses from time to time so you won't be able
to guarantee an FTP server address to last very long. This will most likely
confuse relatives so they can't be bothered to use it. To get a static WAN
IP you usually have to pay extra. Alternatively you can use a service like
this
http://www.dyndns.com/ and create a domain name.

For free you can get a website from Yahoo if you can tolerate ads, but for
as little as $5 a month you can get a hosted site and get your own domain
name from www.dotearth.com or somewhere which cost $35 a year last I looked.
If you family is anything like mine they will look if there's an icon but
not bother to chase your server :)

As to access there are some routers which cannot translate FTP to any port
other than 21 so you may need to stick with default settings (although using
another port can help with security). Your router may be blocking WAN access
as well as your firewall. Look in the instructions for "Port Forwarding" and
set up static forwarding for port 21 to machine with IP 192.168.xxx.xxx
where xxx.xxx points to your FTP server machine. I would make sure this is
set up first before playing with the windows firewall - in both cases you'll
probably have to test it from work or some place off your own LAN (Even the
dial up next door).

I hope this means something to you, I am certainly no expert but find an FTP
server handy when I am away from home.

Charlie


.



Relevant Pages

  • Re: Hacked? External address knocks on internal private address...
    ... The important part of your message is that FTP is allowed out... ... You open a connection to an FTP Server and logon. ... When you ask the server for a file the server issues a "PORT" command ... so it can open a port on the firewall to allow the incoming Data ...
    (comp.security.firewalls)
  • Re: IPSwitch, Inc. WS_FTP Server
    ... > bounce attack as well as PASV connection hijacking. ... > The FTP bounce vulnerability allows a remote attacker to cause the ... > anonymously along with any internal addresses that the FTP server has ... That means it's got to handle a PORT ...
    (Bugtraq)
  • active ftp
    ... Does anyone have a pf config for active ftp? ... # Redirect lan client FTP requests ... # to the ftp-proxy running on the firewall host (via inetd on port 8021) ... rdr on $int_if inet proto tcp from $int_if:network to any port www -> ...
    (comp.unix.bsd.openbsd.misc)
  • Re: Internet Explorer Keeps Timing out on FTP
    ... > This is a problem with the FTP client. ... When the PORT command is used, the FTP client is asking the FTP server to ...
    (microsoft.public.inetserver.iis.ftp)
  • Re: sonicwall port configuration
    ... It sounds as if you wish to keep the world out of your LAN... ... This blocks all traffic from the WAN to your LAN. ... ignore the port scans that you see logged. ... adding the rule "Deny File Transfer (FTP) LAN to WAN ...
    (comp.security.firewalls)