Solved

FTP Client & Server woes

Posted on 2013-12-13
13
441 Views
Last Modified: 2014-01-28
I am using a Netopia 3347 DSL Switch to connect to the internet. Behind that I have a Linsys VPN Firewall router.

Internet - Netopia - DMZ - Linksys - LAN

I have an exchange server and FTP server in the DMZ

Currently my workstations on the LAN can access most all web objects just fine. However, they can not access FTP.  Not the FTP server in the DMZ or any on the web.

Let's start with clients inability to access any ftp site first.

IPs

Public

68.XXX.XXX.105,6,7,8,9

Netopia DSL Switch

68.XXX.XXX.110
192.168.10.110

Netopia ipmaps .105 to .198  and .108 to .111

Exchange server 192.168.10.198  and 192.168.101.4 (dual nics)
FTP Server  192.168.10.111

Linksys

192.168.10.2
192.168.101.2

LAN - 192.168.101.

LAN workstations can see second NIC on exchange server.  Email sends & recieves just fine.

Lan workstations (typ. Win 7 64) can not connect to FTP sites.

My particular workstation has ports 20,21,990 open in firewall (TCP)  and I can not connect to ftp://ftpmdot.state.mi.us/ (as an example) with either firefox or blaze ftp.
0
Comment
Question by:hgj1357
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
13 Comments
 
LVL 5

Expert Comment

by:tercex11
ID: 39717877
Here are a few things to look at.

Go to a command prompt and try to telnet to port 21 on that site
e.g. "telnet ftpmdot.state.mi.us 21"
and see if it connects. If it does connect, then ftp is not blocked at the firewall and the router and you need to check the local PC. . If you cannot get out on the port, then check the log on the firewall and see if it is dropping or forwarding the packets. If it is not forwarding then it sounds like a firewall rule issue. Check the firewall and NAT rules. If you do not see the packets hitting the firewall then make sure you do not have a local firewall running on the PC that could be blocking you and causing the issue.

Good luck,
0
 
LVL 2

Author Comment

by:hgj1357
ID: 39717946
...Could not open a connection with the host, on port 21: Connect failed

Neither harware units have detailed logs of firewall activity.

How should the two be set up?  Should I pinhole 20,21 etc or should I not need to do that?
0
 
LVL 10

Expert Comment

by:remmett70
ID: 39717996
Can you FTP from your exchange server to your FTP server?  Since they are both on the DMZ
0
Salesforce Has Never Been Easier

Improve and reinforce salesforce training & adoption using WalkMe's digital adoption platform. Start saving on costly employee training by creating fast intuitive Walk-Thrus for Salesforce. Claim your Free Account Now

 
LVL 2

Author Comment

by:hgj1357
ID: 39718022
Yes.  Mail server can FTP to FTP server.
0
 
LVL 2

Author Comment

by:hgj1357
ID: 39718059
SHould I pinhole ports 20,21,990 across the netopia?  If so, what private side IP should I use?  The private side of the netopia? The wan ip of the linksys?
0
 
LVL 10

Expert Comment

by:remmett70
ID: 39718147
Try to FTP outside from the DMZ.

I would take one of the workstations, give it an 192.168.10.x and throw it in the DMZ, verify that it can FTP to both the internet and the FTP server while on the DMZ.  If it can, than it is the Linksys that is blocking.
0
 
LVL 83

Expert Comment

by:Dave Baldwin
ID: 39718169
The FTP protocol uses many ports besides 20 and 21.  When I use Firefox to connect to that page, the data is returned at port 30463.  These are called 'ephemeral ports'.  Here's an article about them:  http://en.wikipedia.org/wiki/Ephemeral_port  I can't find one that strictly applies to FTP.
0
 
LVL 2

Author Comment

by:hgj1357
ID: 39718287
From a remote PC (home) I can ping the FTP server. When I try to connect, I get close. I get prompted for username / password - which is good, but it fails on authentication.
0
 
LVL 2

Author Comment

by:hgj1357
ID: 39718290
..although I can telnet in.  So, I need to figure out the security on the cerebus server, but that's not the issue here. At least right now.
0
 
LVL 16

Expert Comment

by:AlexPace
ID: 39726916
From a remote PC (home) I can ping the FTP server. When I try to connect, I get close. I get prompted for username / password - which is good, but it fails on authentication.

This means you connected on port 21 but failed to open a data channel.  The data channel port is negotiated on the fly at runtime.  If you were using the DOS ftp.exe client then it was attempting to use an Active Mode data channel.  In active mode, the client machine sends its IP address to the server along with the port number where it will be waiting for the server to connect.  The port number is above 1024 and below 65K.  This often fails for two reasons: (1) the client sends a private IP address that the server can't reach like 192.168.x.x or 10.x.x.x and (2) many firewalls are configured by default to disallow inbound connections from some random machine out on the internet.  

Many firewalls can be configured to snoop the FTP control channel and watch for the command that asks for an Active Mode data channel.  When this happens, the firewall replaces the internal private address with a public address and then forwards the FTP server's inbound connection request to the correct client computer on the fly.  Once upon a time this was a high-end feature but now it is in consumer-level cable modems.
0
 
LVL 2

Accepted Solution

by:
hgj1357 earned 0 total points
ID: 39746397
I fixed the problem by using https on port 443
0
 
LVL 59

Expert Comment

by:LeeTutor
ID: 39814516
This question has been classified as abandoned and is closed as part of the Cleanup Program. See the recommendation for more details.
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Can’t delete a file 14 225
nipper studio 2 61
Cisco 3560 switches not seeing VTP V3 12 92
How to flash samsung galaxy s6 edge+(verizon) with t-mobile 4 35
INTRODUCTION The purpose of this document is to demonstrate the Installation and configuration of the Data Protection Manager product. Note that this demonstration was prepared on the basis of Windows OS is 2008 R2 and DPM 2010. DATA PROTECTI…
Hi there, This article summarizes what you need if you are going to set up your home or small business Network Attached Storage (NAS) to be accessible from the internet. Of course there are configuration differences based on your NAS or router ma…
This video Micro Tutorial explains how to clone a hard drive using a commercial software product for Windows systems called Casper from Future Systems Solutions (FSS). Cloning makes an exact, complete copy of one hard disk drive (HDD) onto another d…
Two types of users will appreciate AOMEI Backupper Pro: 1 - Those with PCIe drives (and haven't found cloning software that works on them). 2 - Those who want a fast clone of their boot drive (no re-boots needed) and it can clone your drive wh…

738 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question