Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    FTP not working. NAT rules setup like I did with other ports except using port 21 and it's not working.

    Scheduled Pinned Locked Moved Firewalling
    22 Posts 6 Posters 2.9k Views 6 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • DaddyGoD Offline
      DaddyGo @JLundberg
      last edited by DaddyGo

      @JLundberg

      @Gertjan "Btw : I won't says 'FTP' won't work. pfSense can do it - there is even a package that might help you. Can't say more, it's years that I left FTP usage. And that was a good thing."

      if you still want to use this obsolete procedure, just "sftp"
      this is the minimum

      or separate the things from a "web" ........................ "FTP" server
      or NAT behind and pushed up the port to a minimum of 30K

      BTW: the scanners, disrupt the port 21

      Cats bury it so they can't see it!
      (You know what I mean if you have a cat)

      1 Reply Last reply Reply Quote 0
      • DerelictD Offline
        Derelict LAYER 8 Netgate @JLundberg
        last edited by

        @JLundberg said in FTP not working. NAT rules setup like I did with other ports except using port 21 and it's not working.:

        @Derelict
        Are you saying I will need to make changes to my current FTP server settings? So, pfsense can't be set up to function just like the older SonicWall? I may have misunderstood and sorry if I did.

        I don't know how to explain it any clearer than I already did.

        The sonicwall might have had some ALG that overcame misconfiguration of the server like something that translated the passive address sent by the server to the WAN address. pfSense has no such ALG.

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        J 2 Replies Last reply Reply Quote 0
        • J Offline
          JLundberg
          last edited by

          I was hoping for a drop-in replacement (after correct setup) to replace the current SonicWall. pfsense seems to be more capable (not in my hands though... Crap I did want to spend my whole day here :(

          DerelictD DaddyGoD 2 Replies Last reply Reply Quote 0
          • DerelictD Offline
            Derelict LAYER 8 Netgate @JLundberg
            last edited by

            @JLundberg If there is ever a read-only Friday it is Friday, July 3. Second only to Friday December 23 probably.

            Chattanooga, Tennessee, USA
            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
            Do Not Chat For Help! NO_WAN_EGRESS(TM)

            1 Reply Last reply Reply Quote 0
            • DaddyGoD Offline
              DaddyGo @JLundberg
              last edited by

              @JLundberg

              SonicWall is not equal to pfSense ๐Ÿ˜‰
              therefore we use๐Ÿ˜€

              Cats bury it so they can't see it!
              (You know what I mean if you have a cat)

              1 Reply Last reply Reply Quote 0
              • J Offline
                JLundberg @Derelict
                last edited by

                @Derelict
                Understand. Yep I wanted to spend more time with my son. Single dad here. Thanks for your help. I'll continue to go over what you and the others have said.

                DaddyGoD 1 Reply Last reply Reply Quote 0
                • DaddyGoD Offline
                  DaddyGo @JLundberg
                  last edited by

                  @JLundberg

                  the best you can do......
                  " I wanted to spend more time with my son."

                  Have a nice weekend โœ‹

                  Cats bury it so they can't see it!
                  (You know what I mean if you have a cat)

                  1 Reply Last reply Reply Quote 1
                  • J Offline
                    JLundberg @Derelict
                    last edited by

                    @Derelict
                    Yes I know you are explaining it clearly and I thank you for that. I wish I had more training to understand the clear things spoken of. Thanks again. I'll do some searching to try and understand more on if there was something like an ALG that made the SonicWall FTP easier to set up (but overall the sonicwall not having all the abilities like pfsense)

                    I thank you.

                    1 Reply Last reply Reply Quote 0
                    • S Offline
                      serbus
                      last edited by serbus

                      Hello!

                      My experience with sonicwall tz's is that they dynamically open ports to support ftp.

                      "SonicWall overcomes this problem by actively scanning FTP traffic using DPI and dynamically opening ports required for clients to connect to the server. This way, only the Control port, TCP port 21, requires to be explicitly opened in the SonicWall."
                      https://www.sonicwall.com/support/knowledge-base/configuration-for-a-passive-mode-ftp-server-behind-the-sonicwall/170505318942162/

                      John

                      Lex parsimoniae

                      J 1 Reply Last reply Reply Quote 0
                      • J Offline
                        JLundberg @serbus
                        last edited by

                        @serbus
                        So I need to open explicitly open both or just 20 and leave my FTP NAT settings as they are?

                        S 1 Reply Last reply Reply Quote 0
                        • johnpozJ Online
                          johnpoz LAYER 8 Global Moderator
                          last edited by

                          @JLundberg said in FTP not working. NAT rules setup like I did with other ports except using port 21 and it's not working.:

                          So I need to open explicitly open both or just 20 and leave my FTP NAT

                          Port 20 never needs to be forwarded, it will only ever be a source port in an active session..

                          To correctly setup ftp behind a nat firewall, you need to understand how it works to be honest.

                          Here is a great write up..
                          https://slacksite.com/other/ftp.html

                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                          If you get confused: Listen to the Music Play
                          Please don't Chat/PM me for help, unless mod related
                          SG-4860 25.07.1 | Lab VMs 2.8.1, 25.07.1

                          1 Reply Last reply Reply Quote 0
                          • S Offline
                            serbus @JLundberg
                            last edited by

                            Hello!

                            FTP without the dynamic port forwarding was too much of a burden. I converted everything (Win servers, NAS, webops, clients, scripts, etc...) over to sftp. Security beyond basic src ip restrictions was never a concern for these particular ftp transfers, but the move to sftp was definitely on the todo list and the upgrades from sonicwalls -> netgates were the catalyst.

                            John

                            Lex parsimoniae

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.