troubleshooting Question

FTPS access from external and DMZ

Avatar of yccdadmins
yccdadmins asked on
Internet ProtocolsWindows Server 2008
7 Comments1 Solution746 ViewsLast Modified:
Greetings all,

After a great deal of effort I have set up an IIS 7.5 FTPS server in my DMZ.  I am using User Isolation to keep things a little more secure and each user has their own virtual server.

During the build I had to configure FTP Firewall Support.  I entered a port range and then the external address of my FTP server.  Everything works great from the outside now.  Problem is I need people on the inside to get vendor that was placed on the FTP site.  The plan was to have employees on the inside login to the FTP server (from the inside network) with the same ID and pull data that was placed by the vendors.

Employees can connect to the FTP server in the DMZ fine but I get the following error:

Error:      Connection timed out
Error:      Failed to retrieve directory listing

We had the same error when connecting from the outside but it was resolved by:

1. Using Active instead of Passive
2.  Putting the correct IP address in the FTP Firewall Support section of IIS - I had incorrectly put the DMZ address and when I put the external address fo the FTP server in everything went fine

So now we have the issue when connecting from the inside (can't list) but I can't change firewall settings beause it breaks the outside.

Anyone had this issue before or have a good article they know of?

We have a rule set in the Cisco ASA that basically duplicates the ports and access to the FTP server.
ASKER CERTIFIED SOLUTION
yccdadmins

Our community of experts have been thoroughly vetted for their expertise and industry experience.

Join our community to see this answer!
Unlock 1 Answer and 7 Comments.
Start Free Trial
Learn from the best

Network and collaborate with thousands of CTOs, CISOs, and IT Pros rooting for you and your success.

Andrew Hancock - VMware vExpert
See if this solution works for you by signing up for a 7 day free trial.
Unlock 1 Answer and 7 Comments.
Try for 7 days

”The time we save is the biggest benefit of E-E to our team. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange.

-Mike Kapnisakis, Warner Bros