Re: Multiple FTP sites problem



Elie Grouchko <elie@xxxxxxxxxxx> wrote:

I tried to setup the following configuration of 2 FTP sites:

1. Default FTP site, port 21, no user isolation, read + write.
2. 2nd FTP site (same IP as the first), port 7721, users isolated (no
AD), read only.

The second site returns an error (from the Windows explorer) when I
try to access it

The error I get is:
500 Invalid PORT Command

If I shutdown the first site, and change the port of the second site
to 21, it works fine, so I assume it has to do with the port number.

You dont'say, but I'm guessing that your FTP client is running behind a NAT
router. NAT routers at the client end cannot handle Active Mode FTP
correctly unless they specially recognise it, and they recognise an FTP
connection by a TCP connection being made to remote port 21. Therefore
client-side NAT routers fail to handle Active Mode FTP conenctions to ports
other than 21.

This is not an FTP server issue. It is an issue with the NAT box at the
client end in particular, and an issue with the FTP protocol in general.

--
Robin Walker [MVP Networking]
rdhw@xxxxxxxxx


.



Relevant Pages

  • RE: Telnet/ftp problems SBS2000
    ... Please make sure your client computers are configured as both Firewall ... will find two options "Enable folder view for FTP sites" and "Use Passive ... that the control connection has been successfully established, ... (other than port 21) ...
    (microsoft.public.windows.server.sbs)
  • FTP transfer port
    ... FTP transfer port ... the FTP server "listens" for client connections on its port 21. ... it will establish a separate control connection and data connection with ...
    (bit.listserv.ibm-main)
  • Re: Hacked? External address knocks on internal private address...
    ... The important part of your message is that FTP is allowed out... ... You open a connection to an FTP Server and logon. ... When you ask the server for a file the server issues a "PORT" command ... so it can open a port on the firewall to allow the incoming Data ...
    (comp.security.firewalls)
  • Re: Question: FTP via alternate port
    ... The problem with FTP is that it requires two ports to operate. ... FTP command stream in order to dynamically open that port for the data ... Ideally the attacker would want to upload another tool onto the ...
    (Pen-Test)
  • Re: Internet Explorer Keeps Timing out on FTP
    ... > This is a problem with the FTP client. ... When the PORT command is used, the FTP client is asking the FTP server to ...
    (microsoft.public.inetserver.iis.ftp)

Quantcast