Solved

FTP on ISA 2004

Posted on 2006-06-26
6
740 Views
Last Modified: 2013-11-29
I'm running ISA 2004 as a proxy server (Single NIC configuration).  

HTTP is working fine, but I'm having problems w/ FTP.  The filter is enabled.  The port #'s are configured as 20 to 21 in my firewall rule. I have the firewall client installed on the PC.  The server can access FTP sites as normal, but not the clients.

The clients cannot access any FTP sites using advanced clients (FileZilla, FTP Commander).  Using IE, they can access anonymous sites if folder view is disabled.  They can also access sites w/ an ID/PW, but only if I embed them into the URL.  

From a command prompt, I get: Port 1745 – “Initiated Connection”, followed by another identical entry, but the next one is “Closed Connection”.
From an FTP client in Normal Mode, I get the same.  
If I use an FTP client in Passive Mode, I get: Port 1745 – Denied Connection.    

I've set up and enabled an 'allow' rule for port 1745 to/from all networks and all users.  


 

 
0
Comment
Question by:appmis
  • 2
  • 2
6 Comments
 
LVL 9

Expert Comment

by:NYtechGuy
ID: 16987957

You also have to configure what ports are being used by passive FTP (PASV).  I am not sure how to do this in IIS, as I use a third party FTP program called Gene6 (http://gene6.com).  Frankly, its worth a look if you are interested - free trial and only $50 to purchase - and does SO MUCH more then the MS product.

Within the product you can configure what ports PASV uses, and what the PASV hostname/IP is.

THanks,

Justin
0
 

Author Comment

by:appmis
ID: 16993639
I'm trying to use Normal mode for FTP.  If I can get either to work, that would be progress.  I've tried 4 FTP clients (2 from Windows, 2 3rd party advanced clients).  When I bypass ISA they all work.  It's only when running behind ISA that they fail.  I put the info on passive mode in to be thorough, but it's not really the preferred method.  I'd like to use FTP w/ ISA w/o being restricted to a single client.  

0
 
LVL 9

Accepted Solution

by:
NYtechGuy earned 250 total points
ID: 16994042


appmis-

Here are a couple of helpful links, in case you haven't seen them.  Parent site looks like a great resource if you are using ISA.

I would suggest you 'whack' the FTP rules you have already created, and start from scratch with this step-by-step.



Publishing an FTP server on ISA Server:
http://www.isaserver.org/tutorials/Publishing_an_FTP_Server_on_ISA_Server.html

How the FTP server challenges firewall security
http://www.isaserver.org/articles/How_the_FTP_protocol_Challenges_Firewall_Security.html

0
 

Author Comment

by:appmis
ID: 16994442
I've read the bottom one before, but I'll check it out again.  Maybe something didn't click  The top one is for publishing a server to allow external clients inside.  I'm trying to get internal clients to the outside, though.  Thanks.  
0

Featured Post

VMware Disaster Recovery and Data Protection

In this expert guide, you’ll learn about the components of a Modern Data Center. You will use cases for the value-added capabilities of Veeam®, including combining backup and replication for VMware disaster recovery and using replication for data center migration.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

When it comes to security, there are always trade-offs between security and convenience/ease of administration. This article examines some of the main pros and cons of using key authentication vs password authentication for hosting an SFTP server.
For many of us, the  holiday season kindles the natural urge to give back to our friends, family members and communities. While it's easy for friends to notice the impact of such deeds, understanding the contributions of businesses and enterprises i…
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

821 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question