Solved

FTP on ISA 2004

Posted on 2006-06-26
6
742 Views
Last Modified: 2013-11-29
I'm running ISA 2004 as a proxy server (Single NIC configuration).  

HTTP is working fine, but I'm having problems w/ FTP.  The filter is enabled.  The port #'s are configured as 20 to 21 in my firewall rule. I have the firewall client installed on the PC.  The server can access FTP sites as normal, but not the clients.

The clients cannot access any FTP sites using advanced clients (FileZilla, FTP Commander).  Using IE, they can access anonymous sites if folder view is disabled.  They can also access sites w/ an ID/PW, but only if I embed them into the URL.  

From a command prompt, I get: Port 1745 – “Initiated Connection”, followed by another identical entry, but the next one is “Closed Connection”.
From an FTP client in Normal Mode, I get the same.  
If I use an FTP client in Passive Mode, I get: Port 1745 – Denied Connection.    

I've set up and enabled an 'allow' rule for port 1745 to/from all networks and all users.  


 

 
0
Comment
Question by:appmis
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
6 Comments
 
LVL 9

Expert Comment

by:NYtechGuy
ID: 16987957

You also have to configure what ports are being used by passive FTP (PASV).  I am not sure how to do this in IIS, as I use a third party FTP program called Gene6 (http://gene6.com).  Frankly, its worth a look if you are interested - free trial and only $50 to purchase - and does SO MUCH more then the MS product.

Within the product you can configure what ports PASV uses, and what the PASV hostname/IP is.

THanks,

Justin
0
 

Author Comment

by:appmis
ID: 16993639
I'm trying to use Normal mode for FTP.  If I can get either to work, that would be progress.  I've tried 4 FTP clients (2 from Windows, 2 3rd party advanced clients).  When I bypass ISA they all work.  It's only when running behind ISA that they fail.  I put the info on passive mode in to be thorough, but it's not really the preferred method.  I'd like to use FTP w/ ISA w/o being restricted to a single client.  

0
 
LVL 9

Accepted Solution

by:
NYtechGuy earned 250 total points
ID: 16994042


appmis-

Here are a couple of helpful links, in case you haven't seen them.  Parent site looks like a great resource if you are using ISA.

I would suggest you 'whack' the FTP rules you have already created, and start from scratch with this step-by-step.



Publishing an FTP server on ISA Server:
http://www.isaserver.org/tutorials/Publishing_an_FTP_Server_on_ISA_Server.html

How the FTP server challenges firewall security
http://www.isaserver.org/articles/How_the_FTP_protocol_Challenges_Firewall_Security.html

0
 

Author Comment

by:appmis
ID: 16994442
I've read the bottom one before, but I'll check it out again.  Maybe something didn't click  The top one is for publishing a server to allow external clients inside.  I'm trying to get internal clients to the outside, though.  Thanks.  
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Short answer to this question: there is no effective WiFi manager in iOS devices as seen in Windows WiFi or Macbook OSx WiFi management, but this article will try and provide some amicable solutions to better suite your needs.
ADCs have gained traction within the last decade, largely due to increased demand for legacy load balancing appliances to handle more advanced application delivery requirements and improve application performance.
Viewers will learn how to connect to a wireless network using the network security key. They will also learn how to access the IP address and DNS server for connections that must be done manually. After setting up a router, find the network security…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

726 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question