Solved

Filezilla server started to give 425 error on EPSV connections

Posted on 2013-06-19
4
1,226 Views
Last Modified: 2013-09-18
Hi,

We've had Filezilla FTP server running on our server for years now without any problems.

We recently moved from a self hosted environment to a virtual one and P2V'd our FTP server.

Ever since then one customer can't FTP files to us.

They have a program that collates xml files, zips them and sends them to us.

I've noticed in the log file that they are issuing an EPSV command (twice) then an EPRT (which I thought we should be ignoring?)

They then get as far as trying to open the data channel and it fails with a 425 error.

I've asked the company hosting the servers to investigate their firewall and they can't see anything that could be causing this.

They have also opened all ports from the customers IP to this server and the transfer still fails.

Can anyone offer any thoughts? All other FTP connections work fine.

(003548) 19/06/2013 09:53:54 - (not logged in) (195.69.xxx.xx)> Connected, sending welcome message...
(003548) 19/06/2013 09:53:54 - (not logged in) (195.69.xxx.xx)> 220-FileZilla Server version 0.9.23 beta
(003548) 19/06/2013 09:53:54 - (not logged in) (195.69.xxx.xx)> 220 Welcome to our FTP Server
(003548) 19/06/2013 09:53:54 - (not logged in) (195.69.xxx.xx)> USER xxxx
(003548) 19/06/2013 09:53:54 - (not logged in) (195.69.xxx.xx)> 331 Password required for xxxx
(003548) 19/06/2013 09:53:54 - (not logged in) (195.69.xxx.xx)> PASS xxxx
(003548) 19/06/2013 09:53:54 - ftpusername (195.69.xxx.xx)> 230 Logged on
(003548) 19/06/2013 09:53:54 - ftpusername (195.69.xxx.xx)> CWD ToCompanyName
(003548) 19/06/2013 09:53:54 - ftpusername (195.69.xxx.xx)> 250 CWD successful. "/ToCompanyName" is current directory.
(003548) 19/06/2013 09:53:54 - ftpusername (195.69.xxx.xx)> TYPE I
(003548) 19/06/2013 09:53:54 - ftpusername (195.69.xxx.xx)> 200 Type set to I
(003548) 19/06/2013 09:53:54 - ftpusername (195.69.xxx.xx)> EPSV ALL
(003548) 19/06/2013 09:53:54 - ftpusername (195.69.xxx.xx)> 229 Entering Extended Passive Mode (|||1816|)
(003548) 19/06/2013 09:53:54 - ftpusername (195.69.xxx.xx)> EPSV
(003548) 19/06/2013 09:53:54 - ftpusername (195.69.xxx.xx)> 229 Entering Extended Passive Mode (|||1817|)
(003548) 19/06/2013 09:54:16 - ftpusername (195.69.xxx.xx)> EPRT |1|195.69.xxx.xx|2765|
(003548) 19/06/2013 09:54:16 - ftpusername (195.69.xxx.xx)> 200 Port command successful
(003548) 19/06/2013 09:54:16 - ftpusername (195.69.xxx.xx)> STOR LAAD3_alice.willoughby_20130619_095354.zip
(003548) 19/06/2013 09:54:16 - ftpusername (195.69.xxx.xx)> 150 Opening data channel for file transfer.
(003548) 19/06/2013 09:54:26 - ftpusername (195.69.xxx.xx)> 425 Can't open data connection.
(003548) 19/06/2013 10:04:26 - ftpusername (195.69.xxx.xx)> 421 Connection timed out.
(003548) 19/06/2013 10:04:26 - ftpusername (195.69.xxx.xx)> disconnected.
0
Comment
Question by:Letterpart
  • 2
4 Comments
 
LVL 7

Assisted Solution

by:dec0mpile
dec0mpile earned 250 total points
ID: 39259894
Are you using active or passive mode?

Filezilla uses passive mode by default, but for some environments active mode is required (Was there some changes made in your environment?).  

Switch to active mode to test this possibility if you are in passive:

In FileZilla, click on Edit | Settings.

Under Connection, click on FTP and choose Active as the Transfer Mode.

Under Connection, under FTP, click on Active mode and choose “Ask your operating system for the external IP address” (the default setting).

Under Connection, under FTP, click on Passive mode and choose “Fall back to active mode” (this is an optional setting).
0
 
LVL 16

Accepted Solution

by:
AlexPace earned 250 total points
ID: 39260265
This should be easy enough to debug... Just make yourself a test login account and try to connect using EPSV (extended passive mode) for the data channel..  If you get the same behavior then the issue is with the virtual host.  If it works for you then the problem is mostly likely the other client's firewall.  

Another thing you could do is look in the logs and see if anyone else is using EPSV or if your other clients are all using PASV (tradition passive mode) and PORT (active mode) for their data channels.
0
 
LVL 1

Author Comment

by:Letterpart
ID: 39501909
We've got no further with this but going to close the question and split the points between you as I appreciate your help and input.

Thanks.
0
 
LVL 1

Author Closing Comment

by:Letterpart
ID: 39501917
As per my other reply. We have not made any progress with this and are still waiting for the customers IT department to contact us.

So going to close the question down and award points between you as I appreciate your help and input.

Thanks.
0

Featured Post

Get up to 2TB FREE CLOUD per backup license!

An exclusive Black Friday offer just for Expert Exchange audience! Buy any of our top-rated backup solutions & get up to 2TB free cloud per system! Perform local & cloud backup in the same step, and restore instantly—anytime, anywhere. Grab this deal now before it disappears!

Join & Write a Comment

Optimal Xbox 360 connectivity requires "OPEN NAT". If you use Juniper Netscreen or SSG firewall products in a home setting, the following steps will allow you get rid of the dreaded warning screen below and achieve the best online gaming environment…
Periodically we have to update or add SSL certificates for customers. Depending upon your hosting plan you may be responsible for the installation and/or key generation. In the wake of Heartbleed many sites were forced to re-key. We will concen…
It is a freely distributed piece of software for such tasks as photo retouching, image composition and image authoring. It works on many operating systems, in many languages.
Polish reports in Access so they look terrific. Take yourself to another level. Equations, Back Color, Alternate Back Color. Write easy VBA Code. Tighten space to use less pages. Launch report from a menu, considering criteria only when it is filled…

744 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now