Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    FTP traffic goes out WAN instead of WAN2, ignoring firewall rules

    Scheduled Pinned Locked Moved General pfSense Questions
    4 Posts 2 Posters 1.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      jjj
      last edited by

      We have "Disable the userland FTP-Proxy application" unchecked on the LAN, and the "TCP|LAN net||127.0.0.1|8000 - 8030||FTP Helper" rule at the top of the LAN interface then further down we have a send all IPs part of AliasX to go out WAN2 for port 21…. But all the FTP traffic goes out WAN1 instead.... What are we doing wrong?

      1 Reply Last reply Reply Quote 0
      • GruensFroeschliG
        GruensFroeschli
        last edited by

        This means that the connections is handled by the FTP-proxy (which can only make use of the primary WAN).
        Disable the FTP helper and it should work.

        We do what we must, because we can.

        Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

        1 Reply Last reply Reply Quote 0
        • J
          jjj
          last edited by

          Disabling the FTP-proxy breaks active FTP and some of the servers we connect to are active-only…..

          1 Reply Last reply Reply Quote 0
          • GruensFroeschliG
            GruensFroeschli
            last edited by

            In this case you cannot use policy routing and you will have to create static routes for all these servers pointing to the gateway of WAN2.

            We do what we must, because we can.

            Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.