SonicWall - how to Setup Control Port 20021 Data port range 25000-25500

We have a SonicWall TZ 210 and are installing   FTP on a few of our Workstations for our Bank.

Our Bank tech support wants me to open the above Control port and data port range.

I normally run the Public Server Wizard for forwarding outside traffic like Security Cameras or HVAC controls but I think what they want is the Firewall to allow traffic WAN to LAN on the Control port and data port mentioned above.

Am I thinking about this in the right way ?
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Aaron TomoskyDirector of Solutions ConsultingCommented:
Yes use the public server wizard and then just edit the created service groups to have those ports
azpeteAuthor Commented:
I should have added more in the question.

We want to open the above control port and data range for the entire LAN. (From Wan)

By default all LAN to WAN traffic and services are "ALLOW" and all WAN to LAN are "DENY"
Is it possible to modify the WAN to LAN to "ALLOW" that control Port and Data RANGE
Aaron TomoskyDirector of Solutions ConsultingCommented:
That will only work if you have 1 to 1 wan to lan up mapping.
SolarWinds® VoIP and Network Quality Manager(VNQM)

WAN and VoIP monitoring tools that can help with troubleshooting via an intuitive web interface. Review quality of service data, including jitter, latency, packet loss, and MOS. Troubleshoot call performance and correlate call issues with WAN performance for Cisco and Avaya calls

azpeteAuthor Commented:
Aaron, I understand and have done the 1 to 1 mapping via the Wizard many times for many clients on all models of SonicWalls.
  If the bank  said ,
"hey firewall guy, set up a public SFTP  PC on your LAN"   the public server wiz does that in 20 seconds.  But thats not the case.  We want to setup 5 or so PCs with SFTP software applications, and the bank just repeats the mantra " open your firewalls control port and data range ( to the numbers above)  My assumption may be wrong but shouldnt it be that you can say " Sure..., DENY all WAN to LAN services ( that are not initiated by the LAN" BUT add a rule that says " EXCEPT services for this control port and data range ???
Aaron TomoskyDirector of Solutions ConsultingCommented:
Yes you can put an allow rule above the deny rule. They get processed in order. However I would strongly suggest this is not a good idea
azpeteAuthor Commented:
I agree that the rule would be a big hole but ( besides the 1 to 1)  how would you answer the banks direction to "open the control port  and that data range on the firewall but not to a specific PC ?
Aaron TomoskyDirector of Solutions ConsultingCommented:
You can't, you can open it on all pcs with 1 to 1 nat.
azpeteAuthor Commented:
i dont know what that means        " open it on all pcs with 1 to 1 nat"  can you explain ?
Aaron TomoskyDirector of Solutions ConsultingCommented:
If you have 1 to 1 nat, then each wan ip maps to a lan ip. So you can add a firewall rule that states for those services from wan to lan, allow it. If that's not what they want then I really don't understand their request.
azpeteAuthor Commented:
I agree, either the bank tech support statement is incomplete or misleading or my concept of opening wan to lan ports is too shallow.  I will be in contact with the bank and see if I can get more information. They may simply want a public server but are unwilling to say so directly.  Stand by and I will get more info
Do you block outgoing communication? If not, then you have nothing to do.  Some companies do, in which case it would be applicable to open ports for outbound communication.

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
azpeteAuthor Commented:
By default , SonicWall has a "ALLOW all services from LAN to WAN" rule .  I assume that means that a LAN PC can open communications on ANY port and ANY data range.  Since the bank appears to be saying we are not setting up a public server then I think we will be ok with no changes to the SonicWall.  

I I have sent such a statement to the Banks tech support folks and am looking forward to their reply.

  I suspect that a CISCO PIX or other brands of firewalls default to DENY all services from LAN to WAN and the admin must specifically open the ones they want.
Exactly. Some companies also prefer to block everything and only allow what should be necessary for work. You are in the clear.
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Hardware Firewalls

From novice to tech pro — start learning today.