Groups | Blog | Home
all groups > iis ftp > october 2007 >

iis ftp : Passive Mode issue


Synapse120
10/17/2007 5:39:01 AM
I am running Windows 2003 r2 x64 SP2, and IIS 6 with 2 ftp sites and a
website running. The problem i see is fully related to passive mode FTP, and
my firewall configuration. All users inside and outside can connect if they
turn off passive FTP from IE or use a ftp client such as winSCP.

The server will timeout from all users trying passive mode. I have set the
passive port range for IIS and opened those ports in the firewall, with no
luck.

One special configuration i must note is the wan IP's for the 3 sites are
all run from the same NIC.

I have opened up all ports to that specific IP for the ftp sites and still
fails on pasv mode, and windows firewall turned off as well. The clients
return connection timeout when using passive mode. I have seen other posts,
with similar symptoms but, non of the suggestions seem to help.

I cant put my finger on what i am missing on the config. Someone please help.

Bernard Cheah [MVP]
10/18/2007 12:00:00 AM
what port range you set ? without firewall locally does it works?
and without firewall - remotely on the same LAN, does it works?

--
Regards,
Bernard Cheah
http://www.iis.net/
http://msmvps.com/blogs/bernard/


[quoted text, click to view]

Synapse120
10/18/2007 6:57:00 AM
In IIS i set the passive port range for 5500 - 5550, and opened those ports
in the windows firewall and the network firewall with the same results. The
Server is in the DMZ, and the ftp site is bound to a specific public IP.
Internally and externally the site only works in active mode, Command line
ftp works, telnet connection to force passive results in connection lost by
remote host. From the Server it self browsing works in passive and active.
The clients recieve FTP operation Timed out. I have the time out set to 400
right now.

[quoted text, click to view]
Bernard Cheah [MVP]
10/19/2007 12:00:00 AM
if you do a quote pasv in ftp.exe. does the calculation falls inside the
range ?

--
Regards,
Bernard Cheah
http://www.iis.net/
http://msmvps.com/blogs/bernard/


[quoted text, click to view]

Synapse120
10/19/2007 5:24:00 AM
If i do a quote pasv it passes both internal and externally from the network.
What does that mean?

[quoted text, click to view]
Bernard Cheah [MVP]
10/21/2007 12:00:00 AM
I just like to see if the port in use is actually within the port range you
specify
p1 x 256 + p2 = ?? is it within 5500 - 5550.

if you disable windows firewall does it works ?

--
Regards,
Bernard Cheah
http://www.iis.net/
http://msmvps.com/blogs/bernard/


[quoted text, click to view]

Synapse120
10/22/2007 6:21:04 AM
It falls within the specified port range, even with windows firewall disabled
it fails. I have that port range specified for that IP in the Sonicwall. In
my sonicwall i also have port 20 and 21 opened also.

[quoted text, click to view]
Bernard Cheah [MVP]
10/23/2007 12:00:00 AM
Mm.. with firewall disabled, internal client works?


--
Regards,
Bernard Cheah
http://www.iis.net/
http://msmvps.com/blogs/bernard/


[quoted text, click to view]

Synapse120
10/23/2007 3:53:06 AM
I bound the Ftp site to the internal IP, and disabled the firewall and it
worked, as i expected it to. For my internal IP, i never configured the
windows firewall for ftp, so it does fail with the firewall enabled, this is
a dual NIC server. Normally the FTP site is bound to the public IP, so even
internal users browse to the external address. I will do more tests on the
firewall ports, but i think i have all those correct.

[quoted text, click to view]
Bernard Cheah [MVP]
10/26/2007 12:00:00 AM
Then it could be NAT'ing issue between public and internal IP.
I have no further info on that, sorry.

--
Regards,
Bernard Cheah
http://www.iis.net/
http://msmvps.com/blogs/bernard/


[quoted text, click to view]

AddThis Social Bookmark Button