Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Can't connect to FTP server behind pfsense

    Scheduled Pinned Locked Moved NAT
    18 Posts 6 Posters 2.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • H
      hhajj
      last edited by

      Hello
      I've set a Fillezilla FTP server behind pfsense and created a forward rule on the firewall to forward port 21 to the FTp server, But i'm trying to conncet from outside without any success

      1 Reply Last reply Reply Quote 0
      • KOMK
        KOM
        last edited by

        You also have to forward the passive port range.

        1 Reply Last reply Reply Quote 0
        • H
          hhajj
          last edited by

          will that be on a separate port forwarding rule?
          the passive ports are the destination ports?

          1 Reply Last reply Reply Quote 0
          • KOMK
            KOM
            last edited by

            Yes and yes.

            1 Reply Last reply Reply Quote 0
            • H
              hhajj
              last edited by

              look at the pictures of the settings, what is wrong?

              rule.PNG
              rule.PNG_thumb
              ![ftp server.PNG](/public/imported_attachments/1/ftp server.PNG)
              ![ftp server.PNG_thumb](/public/imported_attachments/1/ftp server.PNG_thumb)

              1 Reply Last reply Reply Quote 0
              • KOMK
                KOM
                last edited by

                Your destination ports are wrong.  You specifically asked me if the passive port assignments are for destination ports and I said Yes, then you use something totally different.

                Change Destination Port Range to Custom 65000 to 65050

                1 Reply Last reply Reply Quote 0
                • H
                  hhajj
                  last edited by

                  yes I tried it first but it didn't work!
                  any other suggestions

                  1 Reply Last reply Reply Quote 0
                  • D
                    doktornotor Banned
                    last edited by

                    The above is absolutely wrong. You need port forwards for BOTH the FTP data port AND the passive ports. What you have will never work.

                    1 Reply Last reply Reply Quote 0
                    • johnpozJ
                      johnpoz LAYER 8 Global Moderator
                      last edited by

                      dok is correct both your control channel (21), and your passive ports (65000 to 65050 in your screenshot) need to be forwarded.

                      Your also going to want to make sure your server is actually handing out the wan IP of pfsense.. Going to be pointless for the client if you hand it back your 192.168.88.44 address in the passive connection.

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.8, 24.11

                      1 Reply Last reply Reply Quote 0
                      • KOMK
                        KOM
                        last edited by

                        dok is correct both your control channel (21), and your passive ports (65000 to 65050 in your screenshot) need to be forwarded.

                        Funny, I thought I had already told him all that.

                        1 Reply Last reply Reply Quote 0
                        • johnpozJ
                          johnpoz LAYER 8 Global Moderator
                          last edited by

                          you did, as well as dok clearly state you need both..  And doesn't look like he has his filezilla even handing out its public IP, etc.

                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                          If you get confused: Listen to the Music Play
                          Please don't Chat/PM me for help, unless mod related
                          SG-4860 24.11 | Lab VMs 2.8, 24.11

                          1 Reply Last reply Reply Quote 0
                          • KOMK
                            KOM
                            last edited by

                            OK.  For a minute there, I thought I was speaking Chinese or something.

                            1 Reply Last reply Reply Quote 0
                            • H
                              hhajj
                              last edited by

                              the rules are already made!
                              it connects I see it on the log but it reaches a place where it loose the connection.

                              rules.PNG
                              rules.PNG_thumb

                              1 Reply Last reply Reply Quote 0
                              • D
                                doktornotor Banned
                                last edited by

                                Dude, wrong again. WTF is 21-71?!  ::) ::) ::)

                                (And, while here, FTP is not using UDP for anything.)

                                1 Reply Last reply Reply Quote 0
                                • H
                                  hhajj
                                  last edited by

                                  Fixed thanks guys.
                                  The 21-71 is generated by the system when I chose ftp but i changed it to the ports i want.
                                  my first time!
                                  Come on!
                                  ;)

                                  1 Reply Last reply Reply Quote 0
                                  • sahanS
                                    sahan
                                    last edited by

                                    same problem here

                                    GertjanG 1 Reply Last reply Reply Quote 0
                                    • GertjanG
                                      Gertjan @sahan
                                      last edited by

                                      @sahan said in Can't connect to FTP server behind pfsense:

                                      same problem here

                                      Can't be.
                                      No one fires up an FTP server any more these days. It's ancient technology.
                                      The Internet has been obliterated by the sheer number of how-to's (setting up an FTP server behind a firewall).

                                      Btw : this thread is more then 2 years old. It should be locked.

                                      edit : would be nice if some one woke up @doktornotor 👍

                                      No "help me" PM's please. Use the forum, the community will thank you.
                                      Edit : and where are the logs ??

                                      1 Reply Last reply Reply Quote 0
                                      • johnpozJ
                                        johnpoz LAYER 8 Global Moderator
                                        last edited by

                                        Your 3 posts have been your having issues with ftp - but you have yet to get 1 detail that could actually let us help you.

                                        Your ftp server is where? Where is your client? Are you active or passive?

                                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                                        If you get confused: Listen to the Music Play
                                        Please don't Chat/PM me for help, unless mod related
                                        SG-4860 24.11 | Lab VMs 2.8, 24.11

                                        1 Reply Last reply Reply Quote 0
                                        • First post
                                          Last post
                                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.