Solved

Cannot FTP out from PCs on network. Works ok from server

Posted on 2006-11-03
9
193 Views
Last Modified: 2010-03-18
ftp works ok from the server but none of our pc's will connect to any connection at all. The error is 'connection refused'.

Server:
Windows 2003 SBS
IIS 6.0
ISA 3.0

The server is setup as a proxy.
Any ideas what i need to be looking at to fix the issue? Is there a rule i need to setup somewhere in IIS or ISA?

0
Comment
Question by:BigCap
9 Comments
 
LVL 3

Expert Comment

by:tray_jones
ID: 17868193
check ISA for a deny on Outbound  port 21
0
 
LVL 51

Expert Comment

by:Keith Alabaster
ID: 17876073
Are you running the premium version of SBS with ISA?
If so, have you enabled a rule to let ftp go out? Needs to be from local host & internal to external

open the ISA gui, select monitoring - logging - click on start query.
Make an FTP attempt from a client, what do you see in the log?
0
 
LVL 32

Expert Comment

by:rsivanandan
ID: 17891217
Hey Keith,

  Jump in http://www.experts-exchange.com/Networking/Q_22051939.html

Cheers,
Rajesh
0
 

Author Comment

by:BigCap
ID: 17948610
The option to add a new rule or edit an exisiting rule doesn't exist.
I have the following protocol definition setup:

Name                               Defined by            Port Number             Protocol Type                 Direction
FTP download only            ISA Server                  21                            TCP                       Outbound

I read somewhere that ISA is configured differently on server that only have one NIC and are sat behind a firewall.
Is it called cached mode or something like? Could this have any bearing?

I logged onto my hardware firewall (Sonicnet) and setup a rule to allow all LAN traffice FTP access to the WAN.
Still the same message!!  surely it's got to be ISA or my firewall causing the issue??
0
Zoho SalesIQ

Hassle-free live chat software re-imagined for business growth. 2 users, always free.

 
LVL 51

Expert Comment

by:Keith Alabaster
ID: 17950058
Sorry, missed the ISA comment in your first post. There is no such thing as ISA 3.0, it will be ISA2000, ISA2004 or the new ISA2006 but I don't think ISA2006 ships with SBS yet. if you only have a single nic in the box, then no, you cannot change the protocols as it is acting as a Proxy only, not a firewall.

The ftp rule you have for port 21 is for when you use a full blown ftp client. Have you tried ftp within the web browser? make sure the IE proxy settings - advanced have all the settings pointed to the same port number.

0
 

Author Comment

by:BigCap
ID: 18242182
Hi all,

Thanks for your advice with this problem. I managed to get it sorted in the end.
It was down to our firewall (sonicwall TZ170SP) blocking the ftp traffic.

Basically the TZ170SP as default only allows 10 connections. Our web traffic is directed via a proxy server which would only mean it uses one of the connections but ftp traffic goes out directly and uses one of the remaining 9 connections.

The sessions should be released after use but the firewall wasn't doing it's job and was seeing all 10 concurrent connection in use and therefore preventing any further outbound connections.  A hard reset fixed the problem.
0
 
LVL 51

Expert Comment

by:Keith Alabaster
ID: 18660156
<<Have you tried ftp within the web browser? make sure the IE proxy settings - advanced have all the settings pointed to the same port number.>>

FTP through the web browser and with its proxy settings set cannot go direct to the firewall by definition but the important bit is that its working but yeah, PAQ it.
0
 
LVL 1

Accepted Solution

by:
kodiakbear earned 0 total points
ID: 18694110
Closed, 200 points refunded.
kb
Experts Exchange Moderator
0

Featured Post

Control application downtime with dependency maps

Visualize the interdependencies between application components better with Applications Manager's automated application discovery and dependency mapping feature. Resolve performance issues faster by quickly isolating problematic components.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Massive network latency 1 52
IPhone using PC internet 17 59
MPIO and Link Aggregation (LACP) difference for iSCSI Network ? 12 117
Vpn Server 2012 not working Draytek Vigor 2830 2 29
Are you one of those front-line IT Service Desk staff fielding calls, replying to emails, all-the-while working to resolve end-user technological nightmares? I am! That's why I have put together this brief overview of tools and techniques I use in o…
Trying to figure out group policy inheritance and which settings apply where can be a chore.  Here's a very simple summary I've written which might help.  Keep in mind, this is just a high-level conceptual overview where I try to avoid getting bogge…
This Micro Tutorial will teach you how to censor certain areas of your screen. The example in this video will show a little boy's face being blurred. This will be demonstrated using Adobe Premiere Pro CS6.
Many functions in Excel can make decisions. The most simple of these is the IF function: it returns a value depending on whether a condition you describe is true or false. Once you get the hang of using the IF function, you will find it easier to us…

920 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

17 Experts available now in Live!

Get 1:1 Help Now