Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    configure PfSense ftp

    General pfSense Questions
    4
    5
    89
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      tafovizo last edited by

      Hello. How to configure an exit from the local network (client) to an ftp server on the Internet on PfSense?

      Gertjan JKnott 2 Replies Last reply Reply Quote 0
      • Gertjan
        Gertjan @tafovizo last edited by Gertjan

        @tafovizo said in configure PfSense ftp:

        Hello. How to configure an exit from the local network (client) to an ftp server on the Internet on PfSense?

        The default LAN rule handles outgoing FTP just fine, that is a device on LAN using and FTP client, accessing a FTP server on the net.

        Edit : that is, most FTP servers are hosted on the Internet using a NON RFC1918 IP, and the visiting clients are mostly behind a router like pfSense.
        Read something like https://www.deskshare.com/resources/articles/ftp-how-to.aspx why you really want to ditch FTP where it belong : the national museum of ancient technologies.

        No "help me" PM's please. Use the forum.

        T 1 Reply Last reply Reply Quote 0
        • JKnott
          JKnott @tafovizo last edited by

          @tafovizo

          What are you using for a FTP client? FTP has a problem with NAT in active mode. Some clients might still use active mode, which will fail with NAT. Browsers use passive mode, which works fine with NAT.

          PfSense running on Qotom mini PC
          i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
          UniFi AC-Lite access point

          I haven't lost my mind. It's around here...somewhere...

          1 Reply Last reply Reply Quote 0
          • stephenw10
            stephenw10 Netgate Administrator last edited by

            Yes, if the server is using active mode or your outbound rules are only passing port 21, blocking the passive mode data ports, then you need the ftp client proxy.

            https://docs.netgate.com/pfsense/en/latest/nat/ftp-without-a-proxy.html#client-behind-pfsense

            Steve

            1 Reply Last reply Reply Quote 0
            • T
              tafovizo @Gertjan last edited by

              @Gertjan said in configure PfSense ftp:

              @tafovizo said in configure PfSense ftp:

              Hello. How to configure an exit from the local network (client) to an ftp server on the Internet on PfSense?

              The default LAN rule handles outgoing FTP just fine, that is a device on LAN using and FTP client, accessing a FTP server on the net.

              Edit : that is, most FTP servers are hosted on the Internet using a NON RFC1918 IP, and the visiting clients are mostly behind a router like pfSense.
              Read something like https://www.deskshare.com/resources/articles/ftp-how-to.aspx why you really want to ditch FTP where it belong : the national museum of ancient technologies.

              Thank you ;)

              1 Reply Last reply Reply Quote 0
              • First post
                Last post