In addition, You may want to check youtr MTU settings...
Main Topics
Browse All TopicsWe have changed isa 2004 to isa 2006. It is multihomed firewall and proxy.
Native ftp command does not work now.
I use it from isa server directly, i can logging in, but can not transfer. For example command dir, ls... freezes on timeout.
Nothing changed. No networks, rules, filters, hw firewalls...
On isa 2004 everything worked.
What is on ISA 2006 different?
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
particular...-/
i guess, isa06 does not open dynamic port to active transfer:
when i create rule to open all port from ftp server, ftp command (dir) works!! - otherwise connect is denied
now i have next problem:
there are back-ends chaining firewalls isa04 behind
ftp does not work from them (even if back end is full open)
there is no answer from ftp server in the from-end - in the logs..?
tnx
On the front-end server isa2006 (FTPClient-FE) i have rule named FTP Out - Allow - FTP Protocol (no filter) - from Localhost, Internal - to External - All users
I try connect from FTPClient-FE to ftp server - active transfer denied
ISA Log:
ServerName 2007-11-20 14:51:46 TCP FTPClientIP-FE:41048 FTPServerIP:21 FTPClientIP-FE Local Host External Establish 0x0 FTP Out FTP 0 0 0 0 - - - - 12 2749847
ServerName 2007-11-20 14:52:02 TCP FTPServerIP:20 FTPClientIP-FE:41296 FTPServerIP External Local Host Denied 0xc004000d Default rule Unidentified IP Traffic 0 0 0 0 - - - - 0 0
ServerName 2007-11-20 14:52:04 TCP FTPServerIP:20 FTPClientIP-FE:41296 FTPServerIP External Local Host Denied 0xc004000d Default rule Unidentified IP Traffic 0 0 0 0 - - - - 0 0
ServerName 2007-11-20 14:52:09 TCP FTPServerIP:20 FTPClientIP-FE:41296 FTPServerIP External Local Host Denied 0xc004000d Default rule Unidentified IP Traffic 0 0 0 0 - - - - 0 0
ServerName 2007-11-20 14:52:26 TCP FTPClientIP-FE:41048 FTPServerIP:21 FTPClientIP-FE Local Host External Terminate 0x80074e20 FTP Out FTP 680 680 710 710 40000 40000 - - 12 2749847
On the same server (FTPClient-FE) i have created next rule named TEMP ftpserver - Allow - All outbound - from FTPServerIP - to Localhost, Internal - All users
I try again connect from FTPClient-FE to ftp server - active transfer ok
ISA Log:
ServerName 2007-11-20 15:05:47 TCP FTPClientIP-FE:46765 FTPServerIP:21 FTPClientIP-FE Local Host External Establish 0x0 FTP Out FTP 0 0 0 0 - - - - 12 2762403
ServerName 2007-11-20 15:06:08 TCP FTPServerIP:20 FTPClientIP-FE:46860 FTPServerIP External Local Host Establish 0x0 TEMP ftpserver Unidentified IP Traffic 0 0 0 0 - - - - 58517 2762638
ServerName 2007-11-20 15:06:08 TCP FTPServerIP:20 FTPClientIP-FE:46860 FTPServerIP External Local Host Terminate 0x80074e20 TEMP ftpserver Unidentified IP Traffic 257 257 128 128 - - - - 58517 2762638
ServerName 2007-11-20 15:06:16 TCP FTPServerIP:20 FTPClientIP-FE:46931 FTPServerIP External Local Host Establish 0x0 TEMP ftpserver Unidentified IP Traffic 0 0 0 0 - - - - 58521 2762752
ServerName 2007-11-20 15:06:16 TCP FTPServerIP:20 FTPClientIP-FE:46931 FTPServerIP External Local Host Terminate 0x80074e20 TEMP ftpserver Unidentified IP Traffic 452 452 128 128 - - - - 58521 2762752
ServerName 2007-11-20 15:06:22 TCP FTPClientIP-FE:46765 FTPServerIP:21 FTPClientIP-FE Local Host External Terminate 0x80074e20 FTP Out FTP 874 874 928 928 34000 34000 - - 12 2762403
On the next back-end server isa2004 (FTPClient-BE) i have created rule named TEMP All - Allow - All outbound - from All networks - to All networks - All users
I try connect from FTPClient-BE to ftp server - active transfer no answer
ISA Log on the front-end server (FTPClient-FE):
ServerName 2007-11-20 15:17:44 TCP FTPClientIP-BE:64131 FTPServerIP:21 FTPClientIP-BE Internal External Establish 0x0 FTP Out FTP 0 0 0 0 - - - - 27 2777351
ftp filter is not correct definitelly
i have tried reinstall isa server. No success result.
Immediatelly after new installation of isa2006 on the same server:
rule FTP (protocol FTP – from LocalHost – to External – All Users)
FTP access filter enable - result - FTP server unreachable (and this is fault!!)
FTP access filter disble - result - success log in, no result in active transfer (OK)
rule ALL (all outbound traffic – from All networks – to All networks – All Users)
FTP access filter enable - result - FTP server unreachable
FTP access filter disble - result - success log in, success active transfer (no possible to let open firewall)
Again: reinstall (including reinstalling ftp access filter) no success. It work without isa server.
Microsoft has just found the solution..:)
Problem:
Transmission Control Protocol (TCP) connections are reset when Receive Side Scaling is enabled in Microsoft Windows Server 2003 with Service Pack 2 (SP2). This problem occurs if you use Network Address Translation (NAT), if you use Windows Firewall, or if the host computer is configured to be an Internet Connection Sharing host server computer.
Solution:
Disable Receive Side Scaling
http://support.microsoft.c
Anyway, thank you keith.... best wishes
Business Accounts
Answer for Membership
by: keith_alabasterPosted on 2007-11-09 at 08:31:46ID: 20250716
Nothing is different from ISA2004 to ISA2006 in respect to FTP.
Confirm your rule allows ftp from internal & local host to external
right-click the ftp outbound rule - select configure ftp - uncheck the read-only box.