Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Can not access FTP port forward from internal network

    Scheduled Pinned Locked Moved 2.0-RC Snapshot Feedback and Problems - RETIRED
    4 Posts 3 Posters 2.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D Offline
      danijo76
      last edited by

      Hi,

      I am using PFSense 2.0-RC1 (i386) built on Mon Feb 28 18:12:00 EST 2011

      I am trying to publish an internal FTP-server.

      I have created the forward rules under "Firewall: NAT: Port Forward" and forward port 21 and ports 49100-49300 to the internal FTP-server. I have configured the FTP-server to limit the passive portrange to 49100-49300.

      From an external network I can connect to the FTP-server, and download/upload files, no problems, using passive FTP.

      But if I try to connect to the same IP from the internal network, ie using the DNS-name that points to the external interface on PFsense, I can login but not list files, the FTP-cilent just times out waiting for the file-listing.

      I can connect to the FTP-server's internal IP just fine, and I also have a webserver running on the same machine, and that port forward can be accessed from the internal network without problem.

      The FTP-server is ProFTPD Version: 1.3.1 on Debian 5.0.3

      I know split-dns is a solution, but I rather just get the port-forwards to work.

      1 Reply Last reply Reply Quote 0
      • stephenw10S Offline
        stephenw10 Netgate Administrator
        last edited by

        Have you enabled NAT reflection?

        Steve

        1 Reply Last reply Reply Quote 0
        • D Offline
          danijo76
          last edited by

          I tried enabling it for both rules, but that didn't help. Do I need to enable it somewhere else to?

          Also, under "System: Advanced: Firewall and NAT" , "Disable NAT Reflection for port forwards" is not checked.

          /DJ

          1 Reply Last reply Reply Quote 0
          • E Offline
            eri--
            last edited by

            I do not think ftp works correctly with nat reflection.
            Please create a dns entry for your internal LAN to resolve to the internal ip.

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.