Re: Passive Mode issue



Mm.. with firewall disabled, internal client works?


--
Regards,
Bernard Cheah
http://www.iis.net/
http://msmvps.com/blogs/bernard/


"Synapse120" <Synapse120@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:BC617D56-C579-4271-B4D7-2D1C2F663E93@xxxxxxxxxxxxxxxx
It falls within the specified port range, even with windows firewall
disabled
it fails. I have that port range specified for that IP in the Sonicwall.
In
my sonicwall i also have port 20 and 21 opened also.

"Bernard Cheah [MVP]" wrote:

I just like to see if the port in use is actually within the port range
you
specify
p1 x 256 + p2 = ?? is it within 5500 - 5550.

if you disable windows firewall does it works ?

--
Regards,
Bernard Cheah
http://www.iis.net/
http://msmvps.com/blogs/bernard/


"Synapse120" <Synapse120@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:821434E6-5411-4784-BC58-8E6C2AC8D081@xxxxxxxxxxxxxxxx
If i do a quote pasv it passes both internal and externally from the
network.
What does that mean?

"Bernard Cheah [MVP]" wrote:

if you do a quote pasv in ftp.exe. does the calculation falls inside
the
range ?

--
Regards,
Bernard Cheah
http://www.iis.net/
http://msmvps.com/blogs/bernard/


"Synapse120" <Synapse120@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:FC0D3815-1E41-4633-9C0D-752CCB2639C7@xxxxxxxxxxxxxxxx
In IIS i set the passive port range for 5500 - 5550, and opened
those
ports
in the windows firewall and the network firewall with the same
results.
The
Server is in the DMZ, and the ftp site is bound to a specific public
IP.
Internally and externally the site only works in active mode,
Command
line
ftp works, telnet connection to force passive results in connection
lost
by
remote host. From the Server it self browsing works in passive and
active.
The clients recieve FTP operation Timed out. I have the time out
set
to
400
right now.

"Bernard Cheah [MVP]" wrote:

what port range you set ? without firewall locally does it works?
and without firewall - remotely on the same LAN, does it works?

--
Regards,
Bernard Cheah
http://www.iis.net/
http://msmvps.com/blogs/bernard/


"Synapse120" <Synapse120@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in
message
news:861E4B30-9D70-4E46-BA0B-4B76159B7BB9@xxxxxxxxxxxxxxxx
I am running Windows 2003 r2 x64 SP2, and IIS 6 with 2 ftp sites
and
a
website running. The problem i see is fully related to passive
mode
FTP,
and
my firewall configuration. All users inside and outside can
connect
if
they
turn off passive FTP from IE or use a ftp client such as winSCP.

The server will timeout from all users trying passive mode. I
have
set
the
passive port range for IIS and opened those ports in the
firewall,
with
no
luck.

One special configuration i must note is the wan IP's for the 3
sites
are
all run from the same NIC.

I have opened up all ports to that specific IP for the ftp sites
and
still
fails on pasv mode, and windows firewall turned off as well. The
clients
return connection timeout when using passive mode. I have seen
other
posts,
with similar symptoms but, non of the suggestions seem to help.

I cant put my finger on what i am missing on the config. Someone
please
help.

thank you,











.



Relevant Pages

  • Re: Remote Admin Tools source code for Delphi 4,5,6 & 7
    ... this way I guess the traffic is outbound form the client to ... be remoted and opens up a channel on the firewall. ... the actual client you are going to remotely control. ... all using the same configuration and one Port on your machine. ...
    (borland.public.delphi.thirdpartytools.general)
  • Re: open a certain port
    ... My firewall client is enabled. ... set the option to bypass proxy for internal addresses ... ISA 2004 by default allows only SSL through port 443. ...
    (microsoft.public.isa.configuration)
  • Re: two way communication using NAT and port forwarding
    ... >> How does instant messengers like ICQ work from behind the firewall. ... >> seems to be done using NAT or port forwarding. ... A central server maintained by the creators of the messenger ... >> When the client messenger initiates a request from private IP like ...
    (comp.security.firewalls)
  • RE: RWW and New Firewall Problem
    ... firewall, the network configuration was also changed. ... Once the connection is established on port ... client at port 3389. ... What you cannot visit in RWW, is the computer Terminal Server or just ...
    (microsoft.public.windows.server.sbs)
  • fwop: win32 tcp port proxy tool
    ... fwop is a multi-threaded console application written in C for win-32 ... through a firewall or router with access lists that blocks such traffic. ... high tcp port (>1023} and use that port to connect to the server's tcp ... fwop on the client listens on two ports. ...
    (Pen-Test)

Loading