Ports needed to access FTP.



Hi,

I want to allow someone access to my network by using vpn but restrict
traffic to specific ports. I am using MS Server 2003 SP1 as the VPN server
and have configure a Remote Access policy for the user. I edited the
policy's profile to only allow access to TCP port 21. This is working well.
I tested it by logging in to the VPN server using the userss (not my) login
and doing a telnet in to various ports I know are running on the different
servers and only port 21 works. When I login as myself then my profile
kicks in and I can telnet everything.

The problem I am having is that 21 doesn't seem to be enough. I have opened
up the default FTP site in IE and after it logs me on it tell me I don't
have permisson to access the site. When I remove the packet filter rule in
the policy that applies to the user's login they can access the site, read
its content and write to it.

What else do I need to allow through? I have disabled annoymous access.
The NTFS permissions on the home directory allow only myself and the user
access (Full Control), all other accounts have been deleted from the
folder's ACL. The site security is set to read/write.

I imagine that I need to open some authentication ports, ldap 389 and
kerberos. Is that correct? And is there anything else?

TIA,

Jarryd

P.S. Is there a way to restrict access to a specific destination IP
address?


.



Relevant Pages

  • RE: PPTP remote access ports dissapear - HELP PLEASE!
    ... ports disappear from the RRAS console. ... Based on my research, SBS have wizard to configure the VPN, we do not need ... Please open Routing and Remote Access console on SBS thru run command ... You have to rerun the CEICW to make sure your SBS 2003 server have right ...
    (microsoft.public.windows.server.sbs)
  • RE: PPTP remote access ports dissapear - HELP PLEASE!
    ... ports disappear from the RRAS console. ... Based on my research, SBS have wizard to configure the VPN, we do not need ... Please open Routing and Remote Access console on SBS thru run command ... You have to rerun the CEICW to make sure your SBS 2003 server have right ...
    (microsoft.public.windows.server.sbs)
  • RE: VPN times out on connect
    ... There are two NIC installed on the SBS server. ... are in the same subnet) and then manually create a VPN dial entry. ... We also can use the PPTP Ping tool included in Windows XP Support tools ... to check whether the ports are opened to allow VPN connection. ...
    (microsoft.public.windows.server.sbs)
  • Re: vpn access from hotel room
    ... screening any ports, it will automatically forward any requests on ports to ... your SBS box and ISA will determine if it is allowed to pass through to the ... VPN is a bit more difficult to setup as you'll need to configure an ISA ... I do not understand how i can access the server from the internet through ...
    (microsoft.public.windows.server.sbs)
  • RE: OWA and my firewall
    ... Ports to Forward for SBS2003 ... "Dave Cason" wrote: ... Mobile to access his Exchange 2003 e-mail on my SBS server. ... server via my VPN tunnel and then point the browser again to the same ...
    (microsoft.public.windows.server.sbs)