Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    SHould a FTP client be able to get out by default?

    Scheduled Pinned Locked Moved Firewalling
    7 Posts 5 Posters 2.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D Offline
      Disconnect
      last edited by

      Hello Gang,

      I have read that PFSense blocks all ports by default.

      When I use Filezilla, it seems to be able to get out with me having to create a rule to open port 21.

      Is this normal or did I mis-set something on my network?

      Thanks!

      1 Reply Last reply Reply Quote 0
      • X Offline
        XIII
        last edited by

        Outbound from internal (LAN) network to WAN (Internet) is allowed by default. there is a rule under for your lan inf, it says defualt lan to any, this means the LAN clients can access any and everything.

        Inbound is blocked by default, nothing is allowed in.

        What are you trying to do?

        -Chris Stutzman
        Sys0:2.0.1: AMD Sempron 140 @2.7 1024M RAM 100GHD
        Sys1:2.0.1: Intel P4 @2.66 1024M RAM 40GHD
        freedns.afraid.org - Free DNS dynamic DNS subdomain and domain hosting.
        Check out the pfSense Wiki

        1 Reply Last reply Reply Quote 0
        • D Offline
          Disconnect
          last edited by

          Well, my email required me opening a port, as did ping and DNS, figured everything was blocked.

          1 Reply Last reply Reply Quote 0
          • D Offline
            danswartz
            last edited by

            that makes no sense.  something must have gotten set wrong.

            1 Reply Last reply Reply Quote 0
            • K Offline
              kpa
              last edited by

              Talking about "opening a port" is inaccurate if direction of the connection is left out. Like said by others, pfSense by default blocks all incoming connections on WAN interface and allows all incoming connections (which are usually also outgoing connections to the internet from the point of the client) on LAN. You have to give us more details of what you're doing.

              1 Reply Last reply Reply Quote 0
              • D Offline
                Disconnect
                last edited by

                Ok, I am using an FTP client and connecting to sites on the internet to transfer files.

                When I used my email program to get emails, I had to open 995, to send 25, to get webpages with my browser 80, shouldn't I have had to set up a rule to open 21 before I should have been able to transfer files with my FTP client?

                Thanks.

                1 Reply Last reply Reply Quote 0
                • jimpJ Offline
                  jimp Rebel Alliance Developer Netgate
                  last edited by

                  If you enabled the FTP proxy, it adds a rule that lets FTP out.

                  Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                  Need help fast? Netgate Global Support!

                  Do not Chat/PM for help!

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.