Groups | Blog | Home
all groups > iis ftp > may 2007 >

iis ftp : IIS 6 FTP Cannot logon externally


Joe Santangelo
5/14/2007 9:13:03 AM
I recently created a new FTP site in isolated user mode using active
directory. From the LAN the site and associated folder work as expected.
You re prompted for a user name and password and after successful
authentication you are directed to the appropriate folder.

Externally, I cannot seem to logon. I have tried everything including
logging on from a command line interface. At first I get a connected to host
message and then after a period of time I get "connection closed by remote
host." If I use IE as the client I get a web page cannot be found.

If I create a VPN tunnel first and try to connect I get a different message.
It says "cannot connect to server 426."

The firewall is set to pass both ports 20 and 21 to the appropriate server.
I thought for certain that after creating a VPN tunnel I would be able to
access the site without issue just as I had internally, but that did not work
either.

Is there something more that the firewall needs to pass in order for this to
work? Any help is greately appeciated.


--
Joe Santangelo
5/14/2007 5:54:00 PM
An additional piece of information. When connecting using a VPN, I am able
to connect to the FTP site using windows explorer. I fail when using both
IE7 and Firefox.

Still no luck making any headway connecting directly from the outside.
Still getting connection closed by remote host when trying to connect using
ftp.exe.
--
Joe


[quoted text, click to view]
Bernard Cheah [MVP]
5/16/2007 12:00:00 AM
You should be able to connect via ftp.exe if windows explorer works.
IE 7 ftp connection is not working for isolation mode, use windows explorer
instead.
For FF - see if you can set it to active mode.

--
Regards,
Bernard Cheah
http://www.iis.net/
http://www.iis-resources.com/
http://msmvps.com/blogs/bernard/


[quoted text, click to view]

Joe Santangelo
5/16/2007 7:31:01 AM
Thanks Bernard. That works through the VPN tunnel. However, I am still
unable to access the server directly from outside. It seems to be forwarding
the correct ports because you can connect briefly. Then you get the message
that the connection was dropped by remote host. It does not even prompt you
for an ID or password.

Any thoughts on what may be wrong? Should I configure the server for active
mode as opposed to passive?

Thanks again for your help.
--
Joe


[quoted text, click to view]
Joe Santangelo
5/16/2007 9:02:03 AM
Bernard,

Here is a copy of what I get back when trying to access the FTP site
externally using ftp.exe.

ftp> open 67.158.122.98
Connected to 67.158.122.98.
Connection closed by remote host.
ftp>

So far, the only way I can connect to the site is if I create a VPN tunnel
first.


--
Joe


[quoted text, click to view]
Bernard Cheah [MVP]
5/17/2007 12:00:00 AM
Well, if it's not connecting via VPN and it breaks.
it is somewhere in between that not working, it is not IIS FTP.

without VPN, does it go through firewall ? NAT correctly?
check log files in all devices.... see where it stucks.

--
Regards,
Bernard Cheah
http://www.iis.net/
http://www.iis-resources.com/
http://msmvps.com/blogs/bernard/


[quoted text, click to view]

Joe Santangelo
5/17/2007 8:13:01 AM
Bernard,

I think it has something to do with the router./firewall. If I make a VPN
connection it works fine with windows explorer and FTP.exe. However, if I do
not make a VPN connection the session is dropped. (connection closed by
remote host.)

Currently the router/firewall has port 20 and 21 open and is routing to the
ftp server. The router itself is a Linksys BEFSR41 and the server is a
Windows Small Business Server 2003 Standard. (No ISA Server.) Windows
firewall is not running because I am running RRAS.

Is there something more that needs to be done with the firewall for this to
work?

Thanks again for your help.

--
Joe


[quoted text, click to view]
Bernard Cheah [MVP]
5/18/2007 12:00:00 AM
Mm?? RRAS?
so assuming you have configure linksys to port forward port 21 correctly.
then the suspect is RRAS. I have no clue about this, but seen some post
related to RRAS for ftp.

you might want to try RRAS or network newsgroups, etc. Check if there's any
log info to give you more hints.

--
Regards,
Bernard Cheah
http://www.iis.net/
http://www.iis-resources.com/
http://msmvps.com/blogs/bernard/


[quoted text, click to view]

AddThis Social Bookmark Button