Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    FTP not working. NAT rules setup like I did with other ports except using port 21 and it's not working.

    Scheduled Pinned Locked Moved Firewalling
    22 Posts 6 Posters 2.9k Views 6 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • johnpozJ Online
      johnpoz LAYER 8 Global Moderator
      last edited by

      @JLundberg said in FTP not working. NAT rules setup like I did with other ports except using port 21 and it's not working.:

      So I need to open explicitly open both or just 20 and leave my FTP NAT

      Port 20 never needs to be forwarded, it will only ever be a source port in an active session..

      To correctly setup ftp behind a nat firewall, you need to understand how it works to be honest.

      Here is a great write up..
      https://slacksite.com/other/ftp.html

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 25.07.1 | Lab VMs 2.8.1, 25.07.1

      1 Reply Last reply Reply Quote 0
      • S Offline
        serbus @JLundberg
        last edited by

        Hello!

        FTP without the dynamic port forwarding was too much of a burden. I converted everything (Win servers, NAS, webops, clients, scripts, etc...) over to sftp. Security beyond basic src ip restrictions was never a concern for these particular ftp transfers, but the move to sftp was definitely on the todo list and the upgrades from sonicwalls -> netgates were the catalyst.

        John

        Lex parsimoniae

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.