Solved

Filezilla server started to give 425 error on EPSV connections

Posted on 2013-06-19
4
1,296 Views
Last Modified: 2013-09-18
Hi,

We've had Filezilla FTP server running on our server for years now without any problems.

We recently moved from a self hosted environment to a virtual one and P2V'd our FTP server.

Ever since then one customer can't FTP files to us.

They have a program that collates xml files, zips them and sends them to us.

I've noticed in the log file that they are issuing an EPSV command (twice) then an EPRT (which I thought we should be ignoring?)

They then get as far as trying to open the data channel and it fails with a 425 error.

I've asked the company hosting the servers to investigate their firewall and they can't see anything that could be causing this.

They have also opened all ports from the customers IP to this server and the transfer still fails.

Can anyone offer any thoughts? All other FTP connections work fine.

(003548) 19/06/2013 09:53:54 - (not logged in) (195.69.xxx.xx)> Connected, sending welcome message...
(003548) 19/06/2013 09:53:54 - (not logged in) (195.69.xxx.xx)> 220-FileZilla Server version 0.9.23 beta
(003548) 19/06/2013 09:53:54 - (not logged in) (195.69.xxx.xx)> 220 Welcome to our FTP Server
(003548) 19/06/2013 09:53:54 - (not logged in) (195.69.xxx.xx)> USER xxxx
(003548) 19/06/2013 09:53:54 - (not logged in) (195.69.xxx.xx)> 331 Password required for xxxx
(003548) 19/06/2013 09:53:54 - (not logged in) (195.69.xxx.xx)> PASS xxxx
(003548) 19/06/2013 09:53:54 - ftpusername (195.69.xxx.xx)> 230 Logged on
(003548) 19/06/2013 09:53:54 - ftpusername (195.69.xxx.xx)> CWD ToCompanyName
(003548) 19/06/2013 09:53:54 - ftpusername (195.69.xxx.xx)> 250 CWD successful. "/ToCompanyName" is current directory.
(003548) 19/06/2013 09:53:54 - ftpusername (195.69.xxx.xx)> TYPE I
(003548) 19/06/2013 09:53:54 - ftpusername (195.69.xxx.xx)> 200 Type set to I
(003548) 19/06/2013 09:53:54 - ftpusername (195.69.xxx.xx)> EPSV ALL
(003548) 19/06/2013 09:53:54 - ftpusername (195.69.xxx.xx)> 229 Entering Extended Passive Mode (|||1816|)
(003548) 19/06/2013 09:53:54 - ftpusername (195.69.xxx.xx)> EPSV
(003548) 19/06/2013 09:53:54 - ftpusername (195.69.xxx.xx)> 229 Entering Extended Passive Mode (|||1817|)
(003548) 19/06/2013 09:54:16 - ftpusername (195.69.xxx.xx)> EPRT |1|195.69.xxx.xx|2765|
(003548) 19/06/2013 09:54:16 - ftpusername (195.69.xxx.xx)> 200 Port command successful
(003548) 19/06/2013 09:54:16 - ftpusername (195.69.xxx.xx)> STOR LAAD3_alice.willoughby_20130619_095354.zip
(003548) 19/06/2013 09:54:16 - ftpusername (195.69.xxx.xx)> 150 Opening data channel for file transfer.
(003548) 19/06/2013 09:54:26 - ftpusername (195.69.xxx.xx)> 425 Can't open data connection.
(003548) 19/06/2013 10:04:26 - ftpusername (195.69.xxx.xx)> 421 Connection timed out.
(003548) 19/06/2013 10:04:26 - ftpusername (195.69.xxx.xx)> disconnected.
0
Comment
Question by:Letterpart
  • 2
4 Comments
 
LVL 7

Assisted Solution

by:dec0mpile
dec0mpile earned 250 total points
ID: 39259894
Are you using active or passive mode?

Filezilla uses passive mode by default, but for some environments active mode is required (Was there some changes made in your environment?).  

Switch to active mode to test this possibility if you are in passive:

In FileZilla, click on Edit | Settings.

Under Connection, click on FTP and choose Active as the Transfer Mode.

Under Connection, under FTP, click on Active mode and choose “Ask your operating system for the external IP address” (the default setting).

Under Connection, under FTP, click on Passive mode and choose “Fall back to active mode” (this is an optional setting).
0
 
LVL 16

Accepted Solution

by:
AlexPace earned 250 total points
ID: 39260265
This should be easy enough to debug... Just make yourself a test login account and try to connect using EPSV (extended passive mode) for the data channel..  If you get the same behavior then the issue is with the virtual host.  If it works for you then the problem is mostly likely the other client's firewall.  

Another thing you could do is look in the logs and see if anyone else is using EPSV or if your other clients are all using PASV (tradition passive mode) and PORT (active mode) for their data channels.
0
 
LVL 1

Author Comment

by:Letterpart
ID: 39501909
We've got no further with this but going to close the question and split the points between you as I appreciate your help and input.

Thanks.
0
 
LVL 1

Author Closing Comment

by:Letterpart
ID: 39501917
As per my other reply. We have not made any progress with this and are still waiting for the customers IT department to contact us.

So going to close the question down and award points between you as I appreciate your help and input.

Thanks.
0

Featured Post

Free Tool: Port Scanner

Check which ports are open to the outside world. Helps make sure that your firewall rules are working as intended.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Port forwarding in Cisco RV215w 2 60
Sonicwall routing between VPNs 5 59
Restrict RDP Remote Access through SonicWall 3 121
Botnet detection help me please 21 133
This is a guide to setting up a new WHM/cPanel Server to be used for web hosting accounts. It is intended for web hosting company administrators and dedicated server owners. For under $99 per month (considering normal rate of Big Data Cetnters like …
Have you ever sent email via ColdFusion and thought of tracking this mail to capture the exact date and time when the message was opened ?  If yes, then this article is for you ! First we need a table user_email with columns user_id , email , sub…
Established in 1997, Technology Architects has become one of the most reputable technology solutions companies in the country. TA have been providing businesses with cost effective state-of-the-art solutions and unparalleled service that is designed…

839 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question