Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    FTP Issue for NAT 1:1

    pfSense Packages
    2
    4
    2.2k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • H
      hsiang
      last edited by

      My configuration:
      Running 1.2-BETA-1 
      enable ftp-proxy at all interface - WAN, DMZ and LAN
      Server A is located at LAN using 1:1 NAT to a public IP address

      Senario
      1. When i try to FTP from Server A to an external FTP Server, I am able to authenticated however unable to put/get file from the server
      2. When i try using a workstation located at the same network however is NAT behind the LAN interface Gateway (without own public address), I am able to access to the external FTP Server.

      This is what I had done:
      1. Create a LAN firewall rule from Server A to External allow TCP any
      Or
      2. Remove the NAT 1:1 for Server A

      then only i am able to access to the external FTP server

      Is there any better solutions rather than option 1 and 2, option 2 is totally out.. I might need to live with option 1 if there isn't better solutions.

      Regards
      Hsiang

      1 Reply Last reply Reply Quote 0
      • S
        sullrich
        last edited by

        http://wiki.pfsense.com/wikka.php?wakka=FTPTroubleShooting

        1 Reply Last reply Reply Quote 0
        • H
          hsiang
          last edited by

          refering number 2 for Outgoing FTP,

          "If you have a restrictive ruleset (only allowing certain ports) then ensure that you have permitted traffic to 127.0.0.1 / ports 8000-8020"
          Where should i create this rule? at LAN interface?
          ie: any to 127.0.0.1 port TCP 8000-8020 allow

          1 Reply Last reply Reply Quote 0
          • S
            sullrich
            last edited by

            On the incoming interface, yes.  Most likely LAN.

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.