Solved

How can I set up IIS 7.5 FTP Service to accept internal and external traffic using Passive (SSL/TLS)

Posted on 2011-03-09
3
1,179 Views
Last Modified: 2013-12-02
What I am trying to do is set up a FTP server that goes through ISA 2006.  I have it working from external sites using the proper configation of setting up specific ports on both the fiewall and IIS.  Both encryypted and unencrypted traffic work as expected. (BTW, I am not using the built in windows firewall).

My problem is when I try and connect from inside our network and use any passive connection.  It fails to give me a directory listing.  The reason for this is because you have to program in the outside IP address in the firewall config on IIS.  That tells IIS to use the outside IP address even though we are inside.

Is there the possibility to get this to work without having to send our users out the firewall and back into a DMZ port. (No I am not currently using a DMZ for this box)
0
Comment
Question by:EddieWieder
  • 2
3 Comments
 
LVL 34

Expert Comment

by:Dave_Dietz
ID: 35131023
If your network configuration is such that you have to use the "Firewall Configuration" options for FTP in IIS then your only real option to support internal users would be to create a second FTP site for your internal users pointing to the same content.

The Firewall Configuration options in FTP are only there to act as a band-aid for poorly behaving NAT and Firewall/router devices that can't properly support FTP connections.  If you have to use these they modify the underlying responses sent by the FTP service and generally render it inoperative for connections that don;t go through the errant device(s).

Dave Dietz
0
 

Accepted Solution

by:
EddieWieder earned 0 total points
ID: 35167755
Thanks for your response, however, I have figured it out.  For some reason when I left out the IP address in the FTP Site configuation but left in the port ranges on the FTP Server configuation and set up the ISA firewall rule(s) with these port ranges, all started to work.  I had tried this before but had no luck.  I think it might have been because I was not restarting the actual FTP service, but instead using iisreset instead.
0
 

Author Closing Comment

by:EddieWieder
ID: 35196695
After trial and error I finally figured out the issue.
Always restart the service in services.msc after making changes to either ports or firewall ip in the iis manager.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Join & Write a Comment

The use of stolen credentials is a hot commodity this year allowing threat actors to move laterally within the network in order to avoid breach detection.
Join Greg Farro and Ethan Banks from Packet Pushers (http://packetpushers.net/podcast/podcasts/pq-show-93-smart-network-monitoring-paessler-sponsored/) and Greg Ross from Paessler (https://www.paessler.com/prtg) for a discussion about smart network …
The Task Scheduler is a powerful tool that is built into Windows. It allows you to schedule tasks (actions) on a recurring basis, such as hourly, daily, weekly, monthly, at log on, at startup, on idle, etc. This video Micro Tutorial is a brief intro…
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.

757 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now