all groups > iis ftp > december 2006 >
You're in the

iis ftp

group:

Advice on troubleshooting ftp site



Advice on troubleshooting ftp site Jim Helfer
12/12/2006 8:06:02 PM
iis ftp:
I have an ftp that was used by a photcopier as a network scanning
catch. It runs on a Win 2003sp1 server and is simply an ftp site that
is logged onto with a particular username.

It suddenly stopped working. All the settings for the rights to the
folders and the ftp site in IIS seem completely fine. However, I can't
log into the ftp. My login gets rejected. I can log in with the
administrator account, but 'pwd' tells me I'm in the root directory and
there aren't any other directories to change to.

The 'Big Change' that seemed to coincide with this problem is that
server that hosted the ftp site was also a DC,GC, and a DNS server. I
demoted that server to a member server, and it didn't go completely
succesfully, since a couple little problems like this popped up.

I believe I have addressed the AD problems caused by the demotion, but
this service continues to be stubborn. I've tried the normal stuff, and
I'm stuck on where to go next.

Thanks in Advance for Any Ideas
Jim Helfer
WTW Architects
Re: Advice on troubleshooting ftp site Bernard Cheah [MVP]
12/13/2006 12:00:00 AM
Are you using any user isolation feature?

and post the output when you connecting via ftp.exe

--
Regards,
Bernard Cheah
http://www.iis.net/
http://www.iis-resources.com/
http://msmvps.com/blogs/bernard/


[quoted text, click to view]

Re: Advice on troubleshooting ftp site Jim Helfer
12/13/2006 12:01:59 PM
[quoted text, click to view]

I don't even know what that is <g>. So, I'm thinking no.
[quoted text, click to view]

C:\>ftp 192.168.1.6
Connected to 192.168.1.6.
220 Microsoft FTP Service
User (192.168.1.6:(none)): scanner
331 Password required for scanner.
Password:
530 User scanner cannot log in.
Login failed.

The 'scanner' user is a member of domain users and has R/W rights to
the directory that the ftp site is on. I have allowed anon logins for
testing purposes, and I can log in anonymously just fine. Scanner
account can also log onto the server. The only thing it can't do is
connect to the ftp site.

Jim


Re: Advice on troubleshooting ftp site Jim Helfer
12/13/2006 1:18:52 PM
[quoted text, click to view]


Turns out the the ftp serve was fine with someone logging on with a
domain account when the it was hosted on a DC, however that same account
was not being allowed after the demotion.
I deleted the user and remade it as a local machine account, and now
it works.

Thanks!
Re: Advice on troubleshooting ftp site Bernard Cheah [MVP]
12/18/2006 12:00:00 AM
Cool :) 530 normally indicated some access rights or priviliges is missing
from the account.

--
Regards,
Bernard Cheah
http://www.iis.net/
http://www.iis-resources.com/
http://msmvps.com/blogs/bernard/


[quoted text, click to view]

Re: Advice on troubleshooting ftp site Jim Helfer
12/18/2006 4:12:34 PM
[quoted text, click to view]

Then this is strange. The local account I am using to log onto the
ftp site "scanner" belongs to "Users" and "Domain Users" of the domain
that the server is a member of, and the user is given rights to all the
directories in the share specifically. I'm not sure what other rights
need to be included.

But here's the strange thing. Users complained about not being able
to connect to that ftp site, and I looked over on the server, and found
that I was connected to it via the "scannner" user using ftp.exe on the
server. I disconnected that, and the ability to connect was restored.

Could there be somewhere in the configuration or security policy that
limits this ftp site to a single connection?

Thanks
Re: Advice on troubleshooting ftp site Bernard Cheah [MVP]
12/21/2006 12:00:00 AM
Base on your explanation, I suspect yes. the demotion of the dc removes or
mess up some of the user rights.

--
Regards,
Bernard Cheah
http://www.iis.net/
http://www.iis-resources.com/
http://msmvps.com/blogs/bernard/


[quoted text, click to view]

AddThis Social Bookmark Button