FTP Site Issues On Unique Port w/SBS03+ISA

From: Tony Su (anonymous_at_discussions.microsoft.com)
Date: 04/30/04


Date: Thu, 29 Apr 2004 19:52:27 -0700

Without going into a very long story on unique ISA
quirkiness at times and where/why ISA blocks what you're
trying to setup, just do this instead...

Use the default FTP site, then configure virtual
directories that point to each website.

Use the default IP and port settings.

Tony Su

>-----Original Message-----
>Urgent. Can anyone help??
>
>I am trying to setup a 4 unique ftp sites (different port
>#) for each of our 4 internal company web pages, since I
>have four different companies who we work with to design
>each separate page.
>
>The default ftp (port 21, ip all unassigned) works
>regardless of the directory that I specify, we are
>prompted for credentials then can see the correct files &
>folders instantly.
>
>However, if I set the sites up with individual port
>numbers, and the developer tries to logon using
>ftp://xx.xx.xx.xx:port# it promopts for credentials, but
>just displays the 'searching for contents' icon for 2
>minutes before giving up and saying timeout error.
During
>this time they ARE listed as a 'current session' in the
>FTP site properties. This result happens when the user
is
>not behind their own isa server, if they are out on the
>internet behind no firewall or router.
>
>A different result happens if they are behind their own
>isa server. immediately after typing in
>ftp://xx.xx.xx.xx:1500 they see a disclaimer saying it is
>going to read only mode, they see FTP Proxy warning
saying
>it is read only because the proxy server isnot setup to
>allow full access. When the user hits close they see
http
>502 proxy error the login request was denied 12015
>internet security and acceleration server. I'm sure this
>is a different issue entirely--in which the client's
>server needs extra rules/filters allowed if they are also
>running ISA.
>
>any clues?
>Here are the steps I did to try to make this ftp site:
>-IIS FTP, New Site (and also just tried changing default
>site from working port 21 to non working port 2099)
>-Changed port number to 2099
>-In ISA I defined FTP2099 as a protocol for tcp/inbound
>-In ISA I made a server publishing rule to allow inbound
>FTP2099
>-In ISA I made two new packet filters. Allow ftp 2099
>out, listen on external interface remote port 1500 local
>all ports. Second filter is allow ftp 2099 in, listen on
>external interface remote all ports local port 2099.
>.
>



Relevant Pages

  • Re: Is this a 3-Leg Perimeter scenario?
    ... Disabled the ISA firewall client on the LAN client by opening the configure ... server, and leave LAN clients as 'normal'? ... From the network diagram, to access the FTP server from the LAN client, ...
    (microsoft.public.windows.server.sbs)
  • RE: ISA access rules, help
    ... please let me know whether you're using ISA 2000 or ISA 2004 ... (SBS SP0 or SBS SP1). ... the ISA server will not be used as a proxy server. ... Since SBS already used port 80, ...
    (microsoft.public.windows.server.sbs)
  • Re: Is this a 3-Leg Perimeter scenario?
    ... Disabled the ISA firewall client on the LAN client by opening the configure ... server, and leave LAN clients as 'normal'? ... From the network diagram, to access the FTP server from the LAN client, ...
    (microsoft.public.windows.server.sbs)
  • RE: Remote Web Workplace not completely working.
    ... In order to allow a remote desktop connection to a client computer through ... TS requests through a firewall on TCP port 4125, ... To open the port 4125 on ISA, we can re-run CEICW to confirm it. ... server certificate) and then click Next. ...
    (microsoft.public.windows.server.sbs)
  • Re: Is this a 3-Leg Perimeter scenario?
    ... Do you mean the FTP server is hosted on the ... to control the traffic to not go though ISA but go to SmoothWall directly. ... Microsoft CSS Online Newsgroup Support ...
    (microsoft.public.windows.server.sbs)