Groups | Blog | Home
all groups > iis ftp > june 2004 >

iis ftp : Secure FTP


Joe
6/19/2004 4:29:52 PM
Hello,

FTP Newbie here (sorry)

I am able to access the ftpsite and have been able to
upload a file by dragging it into the window of the site
The directory has been changed no problem. I find it
similar to the Http in IIS 6.0. I am hosting this over the
internet so I can have large files uploaded to my server.

I saw that there was a welcome message and I also saw that
there was a way to use the SSl or maybe not? I just got a
prompt when I removed the check mark in the anonymous
permission section.I also saw that there were two type of
transfer modes? I started here
http://support.microsoft.com/default.aspx?
kbid=814865&product=iis60 and now I need a little
clarification please
However what am I supposed to see and how can I secure
this to use on a regular basis on the internet?

Thanks very much
Joe
6/21/2004 12:37:04 PM
Thanks Bernard for your reply.
I have a VPN network but how would you use it with FTP I
thought FTP was an internet server which can be uploaded
to? I will read this article and get back to you.
Thanks Again
Joe
[quoted text, click to view]
Bernard
6/21/2004 5:05:50 PM
You need to secure the connection with IPsec or VPN, read
Information About the IIS File Transmission Protocol (FTP) Service
http://support.microsoft.com/?id=283679


--
Regards,
Bernard Cheah
http://www.tryiis.com/
http://support.microsoft.com/
http://www.msmvps.com/bernard/



[quoted text, click to view]

Joe
6/21/2004 5:44:04 PM
I just had a person try to upload to me via FTP and he was
able to see the folders and remove a file but not add to
the file. He could not put a file into the ftp folder. I
am very new at this so please be patient I am really
struggling here. Port 21 is open but not 20 is this a
problem? Do these logs say anything to you?


23:42:48 68.153.219.208 [9]USER anonymous 331 0
23:42:48 68.153.219.208 [9]PASS -
AppleNetworkingTechnology@apple.com 230 0
23:42:51 68.153.219.208 [9]sent /slovaun-logo.jpg 226 0
23:43:26 68.153.219.208 [5]closed - 426 1341
23:43:26 68.153.219.208 [8]closed - 426 1341
#Software: Microsoft Internet Information Services 6.0
#Version: 1.0
#Date: 2004-06-21 23:44:16
#Fields: time c-ip cs-method cs-uri-stem sc-status sc-
win32-status
23:44:16 68.153.219.208 [10]USER anonymous 331 0
23:44:16 68.153.219.208 [11]USER anonymous 331 0
23:44:16 68.153.219.208 [10]PASS -
AppleNetworkingTechnology@apple.com 230 0
23:44:16 68.153.219.208 [11]PASS -
AppleNetworkingTechnology@apple.com 230 0
23:44:16 68.153.219.208 [10]CWD / 250 0
23:44:16 68.153.219.208 [11]CWD / 250 0
23:44:17 68.153.219.208 [12]USER anonymous 331 0
23:44:17 68.153.219.208 [12]PASS -
AppleNetworkingTechnology@apple.com 230 0
23:44:18 68.153.219.208 [12]CWD / 250 0
23:44:20 68.153.219.208 [13]USER anonymous 331 0
23:44:20 68.153.219.208 [13]PASS -
AppleNetworkingTechnology@apple.com 230 0
23:44:23 68.153.219.208 [13]sent /slovaun-logo.jpg 226 0
23:44:46 68.153.219.208 [14]USER anonymous 331 0
23:44:46 68.153.219.208 [14]PASS -
AppleNetworkingTechnology@apple.com 230 0
23:44:48 68.153.219.208 [14]sent /slovaun-logo.jpg 226 0
23:45:32 68.153.219.208 [12]closed - 426 1341
#Software: Microsoft Internet Information Services 6.0
#Version: 1.0
#Date: 2004-06-21 23:46:06
#Fields: time c-ip cs-method cs-uri-stem sc-status sc-
win32-status
23:46:06 68.153.219.208 [15]USER anonymous 331 0
23:46:06 68.153.219.208 [15]PASS -
AppleNetworkingTechnology@apple.com 230 0
23:46:06 68.153.219.208 [16]USER anonymous 331 0
23:46:06 68.153.219.208 [16]PASS -
AppleNetworkingTechnology@apple.com 230 0
23:46:06 68.153.219.208 [15]CWD / 250 0
23:46:06 68.153.219.208 [16]CWD / 250 0
23:46:07 68.153.219.208 [17]USER anonymous 331 0
23:46:07 68.153.219.208 [17]PASS -
AppleNetworkingTechnology@apple.com 230 0
23:46:07 68.153.219.208 [17]CWD / 250 0
23:46:09 68.153.219.208 [18]USER anonymous 331 0
23:46:09 68.153.219.208 [18]PASS -
AppleNetworkingTechnology@apple.com 230 0
23:46:11 68.153.219.208 [18]sent /slovaun-logo.jpg 226 0
23:46:51 68.153.219.208 [19]USER anonymous 331 0
23:46:51 68.153.219.208 [20]USER anonymous 331 0
23:46:51 68.153.219.208 [20]PASS -
AppleNetworkingTechnology@apple.com 230 0
23:46:51 68.153.219.208 [19]PASS -
AppleNetworkingTechnology@apple.com 230 0
23:46:51 68.153.219.208 [20]CWD / 250 0
23:46:51 68.153.219.208 [19]CWD / 250 0
23:46:53 68.153.219.208 [21]USER anonymous 331 0
23:46:53 68.153.219.208 [21]PASS -
AppleNetworkingTechnology@apple.com 230 0
23:46:53 68.153.219.208 [21]CWD / 250 0
23:46:54 68.153.219.208 [22]USER anonymous 331 0
23:46:54 68.153.219.208 [22]PASS -
AppleNetworkingTechnology@apple.com 230 0
23:46:57 68.153.219.208 [22]sent /slovaun-logo.jpg 226 0
[quoted text, click to view]
Joe
6/22/2004 6:54:04 AM
I can ftp remotely and locally however I did not have port
20 opened. I have now opened it and I tried to add a file
from another location and it works. I need this for public
use. I have VPN but I can't have everyone I need to get a
file from create a VPN connection. Thus my reason for FTP.

Bernard the anonymous was so he did not get any problems
on access however I do have a login now and it prompts for
it when I type the address in the browser.

The machine that was able to add the file was a XP machine
does this matter that the other is MAC OS? i will read
those articles(thanks)and let you know
I really do appreciate your help!!

Thanks
Joe
[quoted text, click to view]
Bernard
6/22/2004 5:23:07 PM
it appears that you got error 426 - connection closed.
can you ftp locally ?

also, you are not advice to enable anonymous write access,
try create a new login and secure your ftp with proper NTFS permissions.
HOW TO: Limit FTP Access in Windows 2000
http://support.microsoft.com/?id=318712
HOW TO: Create a Secure FTP Directory that Uses Password Authentication
http://support.microsoft.com/?id=239120

next, ask your friend to try ftp.exe at command prompt to try upload file.
for active mode, you need inbound 21 and outbound 20, make sure this two
ports are properly forwarded.

--
Regards,
Bernard Cheah
http://www.tryiis.com/
http://support.microsoft.com/
http://www.msmvps.com/bernard/



[quoted text, click to view]

Joe
6/23/2004 10:09:23 AM
Hello Bernard,

for VPN i was referring that client machine VPN to your
router or device,
then secure all sort of communication, including FTP. not
direct VPN to your
FTP machine.

This is not an option in my set up I have no router. me
and the internet that is it. So FTP is a browser option
only for anyone if this is not good I set up an HTTP
upload form in FP and FPSE it works but sometimes FPSE
gives trouble. That is why I also added a FTP site. I do
keep it stopped until I am contacted and then I let them
upload. Any other suggestions on sevure FTP publically?
Thanks
Joe
[quoted text, click to view]
Bernard
6/23/2004 6:11:46 PM
for VPN i was referring that client machine VPN to your router or device,
then secure all sort of communication, including FTP. not direct VPN to your
FTP machine.

and I also don't see any problem with other OS client. as long as it's a
compatible FTP client, you should be able to use FTP protocol.

--
Regards,
Bernard Cheah
http://www.tryiis.com/
http://support.microsoft.com/
http://www.msmvps.com/bernard/



[quoted text, click to view]
Bernard
6/28/2004 3:33:52 PM
Third party -
http://www.ford-hutchinson.com/~fh-1-pfh/ftps-ext.html

--
Regards,
Bernard Cheah
http://www.tryiis.com/
http://support.microsoft.com/
http://www.msmvps.com/bernard/



[quoted text, click to view]
AddThis Social Bookmark Button