RE: FTP connection via ISA and Linksys gateway



Hi Miles,

Thank you very much for your reply.


The simplified topology of our network
===================================

Application updates @ programmer’s ISP FTP server
|
|
|
Internet
|
|
|
Linksys RV042 (Dual-WAN) (as load balancing gateway and as external
firewall)
|
|
|
SBS 2003 R2 Premium with ISA 2004
|
|
|
Internal network (PC that needs the update, done thru the script)

===================================
As you can see the application that needs the updates has to traverse ISA
2004 and the Linksys to pick up the update at the ftp server.


Question 1: the pc is located in the internal network.
Question 2: it does not connect with the ftp server on port 21.


I will have a look at your links and tell you more.

Thanks once more and best regards,
Vasco


"Miles Li [MSFT]" wrote:


Hello,

Thank you for posting here.

According to your description, I understand that:

You have a concern about the reason why the script with FTP function is
blocked in the SBS environment.

If I have misunderstood the problem, please don't hesitate to let me know.

Suggestions:
==================
The Windows Sockets Error Codes 87 means WSA_INVALID_PARAMETER (One or more
parameters are invalid.) Typically this error results from the invalid
parameters in the request. So I'd like to suggest you have a test to run
the Application in the internal network (not pass through the router and
ISA server) to verify whether this issue result from the firewall or the
application itself.

For the further investigation, I'd like to know the exact topology of your
SBS network. This will help us to verify the possible devices (router or
ISA server) that block the FTP traffic. From your description, I suspect
that you have a back-to-back perimeter network with the Linksys RV042 as
the Front Firewall and SBS server with ISA as the Back Firewall. Is that
right?

Internet
|
|
|
Linksys RV042
|
|
|
DMZ
|
|
|
SBS 2003 with ISA 2004
|
|
|
Internal network (FTP server)

Please also collect the following information for the issue:

1. Where the computer that you have the application run on is located? On
the Internet?
1. Can you telnet to the port 21 on the FTP server from the computer that
run the application?


More related information about publishing a FTP server with ISA server:

Publishing FTP Servers Using ISA Server 2004
http://technet.microsoft.com/en-us/library/cc713319.aspx


How the FTP protocol Challenges Firewall Security
http://www.isaserver.org/articles/How_the_FTP_protocol_Challenges_Firewall_S
ecurity.html


Troubleshooting Outbound FTP Access in ISA Server
http://technet.microsoft.com/en-us/library/bb794745.aspx

Hope it helps. If you have any questions or concerns, please do not
hesitate to let me know.






Best regards,
Miles Li

Microsoft Online Partner Support
Microsoft Global Technical Support Center

Get Secure! - www.microsoft.com/security
=====================================================
When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from your issue.
=====================================================
This posting is provided "AS IS" with no warranties, and confers no rights.


.



Relevant Pages

  • Re: Bestcrypt brute force
    ... >> The problem is that (if I understand your network correctly), ... >> a free license but a good commercial one is Blackmoon Ftp Server. ...
    (Security-Basics)
  • Re: How safe are FTP servers?
    ... I've been using that FTP server for years, ... To the OP, if you're only *sending* files to your clients, as someone ... Whether these passwords are likely to be intercepted at any ... and the network it's on, the server and the network it's on, and all ...
    (comp.os.linux.security)
  • Re: securing an FTP service
    ... Davide wrote: ... The problem is that (if I understand your network correctly), ... I am not aware of any TLS enabled FTP server for windows licensed under ... a free license but a good commercial one is Blackmoon Ftp Server. ...
    (Security-Basics)
  • Re: best gpld norton ghost-like solution?
    ... Its easy, and if you have a fast network and a good FTP server, it doesnt take to long. ... >> since I'd like to make these backup images over the network and the ... > Warp Drive Networks ...
    (RedHat)
  • sysinstall flakey after PXE booting 5.3 / AMD64
    ... boot directory onto my OpenBSD DHCP server. ... Under sysinstall I was able to run fdisk and disklabel successfully, ... Then sysinstall complains that it can't talk to my FTP server and returns ... it asks me if I want to skip network config. ...
    (freebsd-questions)

Quantcast