RE: FTP Server on SBS 2003

From: Bill Peng [MSFT] (v-bpeng_at_online.microsoft.com)
Date: 02/08/05


Date: Tue, 08 Feb 2005 07:21:27 GMT

Hi Eric,

I understand the problem to be as follows:

You connect the SBS to a third party Router and forward port 21 to the SBS
machine. However, the FTP does not work.

If I misunderstood your concern, please don't hesitate to let me know.

Based on my knowledge, PASV FTP will not only use port 21, but also use a
random range of higher ports. Please refer to the following article:

The File Transfer Protocol (FTP) and Your Firewall/Network Address
Translation (NAT) Router/Load-Balancing Router
http://www.ncftp.com/ncftpd/doc/misc/ftp_and_firewalls.html

For PASV FTP, there're 2 solutions.

Solution 1: The network administrator of the server network can configure
the firewall to allow in the entire ephemeral port range.

Solution 2: The network administrator of the server network can consult the
firewall vendor's documentation to see if FTP connections can be
dynamically monitored and ports dynamically opened when a passive FTP
connection is detected.

Personally, I recommend you to use the SBS machine as the router and
connect it to the internet directly. Then, you can run CEICW to enable
Firewall and enable FTP.

[Note] In another hand, you may also want to consult the IIS newsgroup for
other info about configuring the FTP service.

I hope the above info helps and I look forward to your update.

Have a nice day!

Bill Peng
MCSE 2000, MCDBA
Microsoft Online Partner Support

Get Secure! - www.microsoft.com/security
=====================================================
When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from your issue.
=====================================================
This posting is provided "AS IS" with no warranties, and confers no rights.

--------------------
>Thread-Topic: FTP Server on SBS 2003
>thread-index: AcUNbV7+SczUiGJYRla8g1ltT0yn2A==
>X-WBNR-Posting-Host: 65.66.170.25
>From: "=?Utf-8?B?RXJpYw==?=" <Eric@discussions.microsoft.com>
>Subject: FTP Server on SBS 2003
>Date: Mon, 7 Feb 2005 15:33:04 -0800
>Lines: 17
>Message-ID: <94FFE9E5-BA6D-4343-BB46-32826C914EE8@microsoft.com>
>MIME-Version: 1.0
>Content-Type: text/plain;
> charset="Utf-8"
>Content-Transfer-Encoding: 7bit
>X-Newsreader: Microsoft CDO for Windows 2000
>Content-Class: urn:content-classes:message
>Importance: normal
>Priority: normal
>X-MimeOLE: Produced By Microsoft MimeOLE V6.00.3790.0
>Newsgroups: microsoft.public.windows.server.sbs
>NNTP-Posting-Host: TK2MSFTNGXA03.phx.gbl 10.40.1.29
>Path:
cpmsftngxa10.phx.gbl!TK2MSFTNGXA06.phx.gbl!cpmsftngxa06.phx.gbl!TK2MSFTNGXA0
3.phx.gbl
>Xref: cpmsftngxa10.phx.gbl microsoft.public.windows.server.sbs:144310
>X-Tomcat-NG: microsoft.public.windows.server.sbs
>
>Hi,
>
>I just installed SBS 2003 everything is working great except for my ftp
>server.
>I'm on a two NIC server with a gateway router and a switch. My previous
>server was running SBS 2000 and had a ftp server that was working fine. I
>have the same ports open on the router and all routed to the WAN NIC(21,
23,
>25, 80, 110, 443, 444, 1723, 3389 and 4125) I did al my research on KB
>articles but at no avail.
>I installed ftp server and the common files with IIS and did everything
>acording to KB 323384. When I logon from the outside of my router I get
>permission errors and cannot find directory errors.
>Does anybody have a solution?
>
>Thanks,
>
>Eric
>



Relevant Pages

  • Re: moving sbs network
    ... The SBS network is connected to the LAN port. ... so the public wireless router is the DHCP ...
    (microsoft.public.windows.server.sbs)
  • Re: changed IP address: cant receive email & need to make domain name match IP address
    ... Port Forwarding for 2Wire 1701HG ... SBS CDs, but it's always a good idea to keep them handy. ... As you are set up now, your SBS server is "bare to the Internet" (not ... need to buy at least another inexpensive router to put between the SBS ...
    (microsoft.public.windows.server.sbs)
  • RE: router to router question...pls help
    ... that was done already all port are configured ... by the way i already have a full time router to router connection ... > I am glad to hear from you in the SBS newsgroup. ... > SBS 2003 to configure for the internet access and remote access. ...
    (microsoft.public.windows.server.sbs)
  • Re: getting vsftpd into active mode
    ... Is the an FTP command? ... but the client has to comply. ... Active ftp requires an incoming port open at the router ...
    (alt.os.linux)
  • Re: SBS 2003 cant ftp from outside lan
    ... To the best of my knowledge, there is no application level gateway in the SBS basic firewall, that's the sort of thing you get with ISA. ... If that's OK, or if there's only one NIC, then it's the router that's the issue. ... Henrik asked if you had opened it for FTP, and you replied as above, but that's not the answer to the question. ... This means that the initial connection must set up a NAT table entry not only for that connection, normally on port 21, but must set up the same translation for port 20, the data port, from which it has not yet seen any connection. ...
    (microsoft.public.windows.server.sbs)