Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    cannot connect FTP using WinNC software on Pfsense

    Scheduled Pinned Locked Moved Firewalling
    8 Posts 3 Posters 742 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      mousevn
      last edited by

      I have learned 1 week but not yet.
      My Pfsense firewall blocks FTP connection by software but connects manually on the computer using ftp://xxx.xxx.xxx.xxx.
      I use Winnc software to connect to the FTP Server elsewhere
      in my rules to default to the internet does not block any port
      ask your help.

      1 Reply Last reply Reply Quote 0
      • DerelictD
        Derelict LAYER 8 Netgate
        last edited by Derelict

        There is nothing that will block outbound active or passive FTP connections in the default rules.

        If you are connecting to an outside FTP server in active mode, You will need to enable the FTP client proxy package.

        Try explicitly setting your FTP client to use passive mode before going there though.

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        M 1 Reply Last reply Reply Quote 0
        • GertjanG
          Gertjan
          last edited by

          Hi,

          You are using a FTP client on your LAN and want you connect to some FTP server on the Internet ?
          The other way around ?

          No "help me" PM's please. Use the forum, the community will thank you.
          Edit : and where are the logs ??

          1 Reply Last reply Reply Quote 0
          • M
            mousevn
            last edited by

            @Gertjan said in cannot connect FTP using WinNC software on Pfsense:

            Hi,
            You are using a FTP client on your LAN and want you connect to some FTP server on the Internet ?
            The other way around ?

            that's right

            1 Reply Last reply Reply Quote 0
            • M
              mousevn @Derelict
              last edited by

              @Derelict

              I installed the FTP client proxy and set up the following:
              Proxy Enable - Tick
              Local Interface - LAN
              IPv6 - no tick
              Anonymous - no tick
              Source - 192.168.10.1 (address of Pfsense device)
              Bind Port - 21
              Max Sessions - Blank
              Traffic Shaping - Blank
              Rewrite Port 20 - no tick
              Ide Timeout - Blank
              Log Connection - ticked

              but the software connected to the FTP server still cannot run
              1.jpg
              2.jpg
              winnc.jpg

              1 Reply Last reply Reply Quote 0
              • DerelictD
                Derelict LAYER 8 Netgate
                last edited by

                Did you even TRY passive mode like I suggested?

                Chattanooga, Tennessee, USA
                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                1 Reply Last reply Reply Quote 0
                • DerelictD
                  Derelict LAYER 8 Netgate
                  last edited by

                  Passive mode is what you want.

                  If you insist on active mode, you probably want the source address to be 192.168.1.14, not 192.168.10.1.

                  Note that whatever is upstream of you will also need to have some sort of active FTP proxy or ALG or simply pass everything received to the pfSense WAN.

                  Chattanooga, Tennessee, USA
                  A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                  DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                  Do Not Chat For Help! NO_WAN_EGRESS(TM)

                  M 1 Reply Last reply Reply Quote 0
                  • M
                    mousevn @Derelict
                    last edited by

                    @Derelict
                    thank you very much

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.