Solved

Windows 2000 TCP/IP Filtering blocks FTP!

Posted on 2004-09-08
5
323 Views
Last Modified: 2012-05-05
Hi,

I have enabled TCP/IP Filtering feature of Windows 2000. I did following setting:

1. Permit all UDP Traffic
2. Permit all IP Traffic
3. Permit TCP Traffic on port 80, 20, 21, 25, 110, 53, 443

With this setup, everything works nicely except FTP. The customers are unable to ftp to their accounts. The can ftp to port 21 but when ftp client connect to random data port after login then the socket error pops-up which is obviously because that random port number is a disallowed ftp port.

My qeustions is, how do I configure tcp/ip filtering to allow FTP also.

Thank you.
0
Comment
Question by:azizparacha
  • 4
5 Comments
 
LVL 15

Expert Comment

by:adamdrayer
ID: 12010462
It seems your FTP server is setup in passive mode.  This requires the server to have random ports about 1024 open.  You need to change that to active mode to accomplish what you want:
http://slacksite.com/other/ftp.html
0
 
LVL 15

Accepted Solution

by:
adamdrayer earned 500 total points
ID: 12010513
you can also change the passiveftp range on IIS like so:
http://support.microsoft.com/?id=555022

0
 
LVL 15

Expert Comment

by:adamdrayer
ID: 12010597
some more info:
http://www.informit.com/articles/article.asp?p=101750&seqNum=8


It seems that this has to be set on the client side:

How to Change the Internet Explorer FTP Client Mode
------------------------------------------------------------------------------------
Start Internet Explorer.
On the Tools menu, click Internet Options.
Click the Advanced tab.
Under Browsing, click to clear the Enable folder view for FTP sites check box.
Click to select the Use Passive FTP (for firewall and DSL modem compatibility) check box.
Click OK.

and here:
http://www.informit.com/articles/article.asp?p=101750&seqNum=8
excerpt-
You can't configure IIS to switch off passive FTP port support, but in IIS 6 you can configure the port range used, which makes it easier to select a port range and configure your firewall service to pass through the passive FTP traffic.
0
 

Author Comment

by:azizparacha
ID: 12013934
Great help adamdrayer. I have limited passive port range, opened the range in tcp/ip filtering and everything now works just great.. Thanks a lot :+)
0
 
LVL 15

Expert Comment

by:adamdrayer
ID: 12015050
no problem.  thanks
0

Featured Post

Control application downtime with dependency maps

Visualize the interdependencies between application components better with Applications Manager's automated application discovery and dependency mapping feature. Resolve performance issues faster by quickly isolating problematic components.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

A brief overview to explain gateways, default gateways and static routes OR NO - you CANNOT have two default gateways on the same server, PC or other Windows-based network device. In simple terms a gateway is formed when a computer such as a serv…
Have you ever set up your wireless router at home or in the office to find that you little pop-up bubble in the bottom right-hand corner of Windows read "IP Conflict - One of more computers on the network have been assigned the following IP address"…
Internet Business Fax to Email Made Easy - With  eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, f…
Hi friends,  in this video  I'll show you how new windows 10 user can learn the using of windows 10. Thank you.

895 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now