Celebrate National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

FTP on ISA 2004

Posted on 2006-06-26
6
Medium Priority
?
745 Views
Last Modified: 2013-11-29
I'm running ISA 2004 as a proxy server (Single NIC configuration).  

HTTP is working fine, but I'm having problems w/ FTP.  The filter is enabled.  The port #'s are configured as 20 to 21 in my firewall rule. I have the firewall client installed on the PC.  The server can access FTP sites as normal, but not the clients.

The clients cannot access any FTP sites using advanced clients (FileZilla, FTP Commander).  Using IE, they can access anonymous sites if folder view is disabled.  They can also access sites w/ an ID/PW, but only if I embed them into the URL.  

From a command prompt, I get: Port 1745 – “Initiated Connection”, followed by another identical entry, but the next one is “Closed Connection”.
From an FTP client in Normal Mode, I get the same.  
If I use an FTP client in Passive Mode, I get: Port 1745 – Denied Connection.    

I've set up and enabled an 'allow' rule for port 1745 to/from all networks and all users.  


 

 
0
Comment
Question by:appmis
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
6 Comments
 
LVL 9

Expert Comment

by:NYtechGuy
ID: 16987957

You also have to configure what ports are being used by passive FTP (PASV).  I am not sure how to do this in IIS, as I use a third party FTP program called Gene6 (http://gene6.com).  Frankly, its worth a look if you are interested - free trial and only $50 to purchase - and does SO MUCH more then the MS product.

Within the product you can configure what ports PASV uses, and what the PASV hostname/IP is.

THanks,

Justin
0
 

Author Comment

by:appmis
ID: 16993639
I'm trying to use Normal mode for FTP.  If I can get either to work, that would be progress.  I've tried 4 FTP clients (2 from Windows, 2 3rd party advanced clients).  When I bypass ISA they all work.  It's only when running behind ISA that they fail.  I put the info on passive mode in to be thorough, but it's not really the preferred method.  I'd like to use FTP w/ ISA w/o being restricted to a single client.  

0
 
LVL 9

Accepted Solution

by:
NYtechGuy earned 1000 total points
ID: 16994042


appmis-

Here are a couple of helpful links, in case you haven't seen them.  Parent site looks like a great resource if you are using ISA.

I would suggest you 'whack' the FTP rules you have already created, and start from scratch with this step-by-step.



Publishing an FTP server on ISA Server:
http://www.isaserver.org/tutorials/Publishing_an_FTP_Server_on_ISA_Server.html

How the FTP server challenges firewall security
http://www.isaserver.org/articles/How_the_FTP_protocol_Challenges_Firewall_Security.html

0
 

Author Comment

by:appmis
ID: 16994442
I've read the bottom one before, but I'll check it out again.  Maybe something didn't click  The top one is for publishing a server to allow external clients inside.  I'm trying to get internal clients to the outside, though.  Thanks.  
0

Featured Post

Threat Trends for MSPs to Watch

See the findings.
Despite its humble beginnings, phishing has come a long way since those first crudely constructed emails. Today, phishing sites can appear and disappear in the length of a coffee break, and it takes more than a little know-how to keep your clients secure.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Short answer to this question: there is no effective WiFi manager in iOS devices as seen in Windows WiFi or Macbook OSx WiFi management, but this article will try and provide some amicable solutions to better suite your needs.
This program is used to assist in finding and resolving common problems with wireless connections.
Internet Business Fax to Email Made Easy - With  eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, f…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…
Suggested Courses

730 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question