Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

Fortigate FTPS - 425 Can't open data connection.

Posted on 2009-04-06
9
Medium Priority
?
10,353 Views
Last Modified: 2013-12-02
We have just replaced our ISA Firewall Cluster with two Fortigate 110C units.

The FTP server runs FileZilla FTP Server, configured to use FTPS (TCP 990) as the command port and 50000-51000 as the data ports.

I have setup the Virtual IP's to forward the 990 traffic to the server and created a firewall policy to allow 990,50000-51000.

When making a client connection I get the following:
Status:      Connecting to xxx.xxx.xxx.xxx:990...
Status:      Connection established, initializing TLS...
Status:      Verifying certificate...
Status:      TLS/SSL connection established, waiting for welcome message...
Response:      220-FileZilla Server version 0.9.27 beta
Response:      220 Welcome to xyz server
Command:      USER myusername
Response:      331 Password required for myusername
Command:      PASS **************
Response:      230 Logged on
Command:      PBSZ 0
Response:      200 PBSZ=0
Command:      PROT P
Response:      200 Protection level set to P
Status:      Connected
Status:      Retrieving directory listing...
Command:      PWD
Response:      257 "/" is current directory.
Command:      TYPE I
Response:      200 Type set to I
Command:      PASV
Response:      227 Entering Passive Mode (xxx,xxx,xxx,xxx,195,247)
Command:      LIST
Response:      425 Can't open data connection.
Error:      Failed to retrieve directory listing

From that log I can determine that the connection to the server via port 990 is successful and authenticates however the client can not connect to the data port 50167 (195*256+247)

Now what I am assuming is that the Fortigates are not allowing the connection because the data ports are not forwarded and I somehow have to tell the fortigate to allow the connection through (i thought it might be NAT so I enabled this option on the firewall policy but this made no difference) and i don't think forwarding the whole 50000-51000 range is the correct method either.

I also tried applying a protection profile that has no Anti-Virus etc applied to it but still didn't fix it.

Does anyone have any ideas where I'm going wrong?

I know FTPS is ugly and it wasn't my choice but I have to get it working none the less. It worked fine with the ISA cluster (YUCK!) so what the hell was ISA doing that I need to tell the fortigates to do?
0
Comment
Question by:ZeeBOBNZ
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
9 Comments
 
LVL 57

Expert Comment

by:giltjr
ID: 24082165
You will need to configure the Fortigate to allow inbound traffic to the ftp server for the whole port range.  If you are doing a static one-to-one NAT for the ftp server that should be all you need to do.  If you are doing port mapping, then you need to port map the whole range.

Also is the IP address in the 227 message actually reachable by the client?

If not:

Does the server and client support extended passive?   If so, use that.

If the client or the server does not support extended passive, then you will need to configure Filezilla to use the public IP address for passive connections.
0
 

Author Comment

by:ZeeBOBNZ
ID: 24082239
Hi,

Yes the 227 message does have the correct IP address.
I understand what you mean about the one-to-one NAT I just don't know how to configure this on the Fortigates...

Thanks
0
 
LVL 57

Expert Comment

by:giltjr
ID: 24082939
Which model do you have and what is the firmware/software level?
0
Looking for the Wi-Fi vendor that's right for you?

We know how difficult it can be to evaluate Wi-Fi vendors, so we created this helpful Wi-Fi Buyer's Guide to help you find the Wi-Fi vendor that's right for your business! Download the guide and get started on our checklist today!

 

Author Comment

by:ZeeBOBNZ
ID: 24083305
Fortigate 110C

FG110C-3.00-FW-build733-081122
0
 
LVL 57

Accepted Solution

by:
giltjr earned 1500 total points
ID: 24083424
It appears that Fortigate uses virtual IP (VIP) to setup static one-to-one NAT:

http://kc.forticare.com/default.asp?id=1765&SID=&Lang=1

Does this help?
0
 

Author Closing Comment

by:ZeeBOBNZ
ID: 31566935
Thanks for the link, i must have read that article about 10 times and missed the crucial instruction.

Thanks!
0
 

Expert Comment

by:aijazans
ID: 38884183
Dear all,

I am facing similar problem on my network.i Have done the above workaround but still facing the same problem..

Please help me
0
 
LVL 57

Expert Comment

by:giltjr
ID: 38884196
You will need to open your own question.
0

Featured Post

2017 Webroot Threat Report

MSPs: Get the facts you need to protect your clients.
The 2017 Webroot Threat Report provides a uniquely insightful global view into the analysis and discoveries made by the Webroot® Threat Intelligence Platform to provide insights on key trends and risks as seen by our users.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Please see preceding article here: http://www.experts-exchange.com/Networking/Operating_Systems/A_11209-Root-Bridge-Election.html Figure 1 After Root Bridge has been elected, then what?..... Let's start by defining a Root Port in la…
If, like me, you have a lot of Dell servers in the estate you manage this article should save you a little time. When attempting to login to iDrac on any server I would be presented with two errors. The first reads "Do you want to run this applicati…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Michael from AdRem Software outlines event notifications and Automatic Corrective Actions in network monitoring. Automatic Corrective Actions are scripts, which can automatically run upon discovery of a certain undesirable condition in your network.…
Suggested Courses

609 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question