Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    FTP problem since RC3 –> RC3e and now also 1.0 RELEASE

    Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
    23 Posts 8 Posters 10.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      msatter
      last edited by

      ??? ??? ??? ??? ???The mentioned work arround worked one time and then it stopped working  ??? ??? ??? ??? ???

      I am going back to RC2 again for the second time  till this problem is resolved.

      Greetings, Marcel

      1 Reply Last reply Reply Quote 0
      • H
        hoba
        last edited by

        The workaround works fine, even after more than 1 day now at my office setup (dual wan setup utilizing policybasedrouting and a loadbalance anything rule at the bottom with 2 internal subnets, LAN and DMZ). I can use ftp in active and passive mode to different servers. I just checked and verified this once again. After applying the workaround reset states just to make sure. Also move the rule to the very top of your rules on each interface where you need it (usually internal interfaces).

        1 Reply Last reply Reply Quote 0
        • S
          sullrich
          last edited by

          @msatter:

          ??? ??? ??? ??? ???The mentioned work arround worked one time and then it stopped working  ??? ??? ??? ??? ???

          I am going back to RC2 again for the second time  till this problem is resolved.

          Greetings, Marcel

          The problem IS solved, you really need to listed to hoba!

          1 Reply Last reply Reply Quote 0
          • M
            msatter
            last edited by

            Course I am listening to Hoba and I tried it two times and it just won't "budge". When I am looking at the status no UDP is showing up internal and external there is UDP connection on FTP when I connect to a external FTP.

            I am using aliasses for the source and the ports in the rules (ports 20 and 21) to reach my internal FTP server. I even removed all my loadbalancing and also in the rules.

            I don't have a loadbalance anything rule only the build in block anything rule at the end you don't see in the list only in the comment underneath.

            I am now on RC2 on a USB stick and my HDD contains 1.0 release so I can experiment with different setting after boot-up from stick or HDD.

            I don't know what is going wrong and I put all the lines in place as suggested however no result after it worked for one time.

            Greetings, Marcel

            edit: I can HTTP the server, I can SSH the server, I have a connect FTP to the server however no LIST-ing of the files

            1 Reply Last reply Reply Quote 0
            • R
              rsw686
              last edited by

              I had problems with FTP before RC3, however with the 1.0-RELEASE it works great. Start over from scratch. Add the FTP rule and make sure you uncheck disable FTP helper on the WAN interface. It will just work.

              1 Reply Last reply Reply Quote 0
              • H
                hoba
                last edited by

                @msatter:

                I am using aliasses for the source and the ports in the rules (ports 20 and 21) to reach my internal FTP server. I even removed all my loadbalancing and also in the rules.

                ftp happens on more than these 2 ports. In case you have a restrictive ruleset you need to allow connections to the ftphelper to open additionally needed ports.

                1 Reply Last reply Reply Quote 0
                • M
                  msatter
                  last edited by

                  !!!!!!!!WORKARROUND!!!!!!!!!!!

                  Finally solved after skipping RC3 and almost REL 1.0 I found the trouble maker and now I can connect!!!!!!

                  It was in Ticket 15066 / 15067 I now deactivated the block all to DMZ (the other subnet) rule on the the LAN (sorry, I am really restrictive in my rules).

                  I can now proceed with implementing the firewall because this "not working as expected" part of the pfSense firewall drove me almost nuts because Hoba and Sullrich kept telling me that it should work as expected.

                  One happy pfSense user, Marcel

                  Check-in Number:  15067
                  Date: 2006-Oct-17 17:28:17 (local)
                  2006-Oct-17 21:28:17 (UTC)
                  User: sullrich
                  Branch:
                  Comment: Woops, we need the ftp anchor BEFORE the user rules, and the inital PASS rules AFTER.

                  This controls the initial port 21 connetion and once that is allowed through the ftp rules installed by pftpx should bypass USER_RULES.
                  Tickets:
                  Inspections:
                  Files:
                  pfSense/etc/inc/filter.inc      1.922 -> 1.923     4 inserted, 3 deleted

                  1 Reply Last reply Reply Quote 0
                  • S
                    sullrich
                    last edited by

                    This bug has been fixed.  A new release will be forthcoming in the next couple weeks.

                    1 Reply Last reply Reply Quote 0
                    • T
                      techatdd
                      last edited by

                      @hoba:

                      The workaround works fine, even after more than 1 day now at my office setup (dual wan setup utilizing policybasedrouting and a loadbalance anything rule at the bottom with 2 internal subnets, LAN and DMZ). I can use ftp in active and passive mode to different servers. I just checked and verified this once again. After applying the workaround reset states just to make sure. Also move the rule to the very top of your rules on each interface where you need it (usually internal interfaces).

                      Really strange,
                      I have also a dual WAN config with standart gateway for most things (except port 80) on opt1 and problems with external ftp servers.
                      I applied the workaround on http://cvstrac.pfsense.com/tktview?tn=1138,6 and now active ftp works as it should but with passive ftp I get no directory listing form external ftp server.
                      Is there an other workaround for this  ;)
                      Greetings,
                      techatdd

                      1 Reply Last reply Reply Quote 0
                      • T
                        Tomba
                        last edited by

                        Hoba tx a lot. You made my day :D Couldn't understand why it wouldn't work after RC3…

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.