<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Active FTP from opt to LAN network]]></title><description><![CDATA[<p dir="auto">I'm trying to ftp from a host on one of my OPT interfaces to a host on the LAN interface.  Using active mode I can't get a data connection.  My logs show blocks from the source host on OPT to port 20 on my FTP server with a protocol listed of TCP:SA.  Rules allow full access between hosts.  The block reason is</p>
<p dir="auto">The rule that triggered this action is:</p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/1">@<bdi>1</bdi></a> scrub in on em0 all fragment reassemble<br />
<a class="plugin-mentions-user plugin-mentions-a" href="/user/1">@<bdi>1</bdi></a> block drop in log all label "Default deny rule"</p>
<p dir="auto">I've tried disabling the ftp proxy under system tunables, but it didn't make a difference.  Not sure if it really has any impact between interfaces?  I also tried setting my optimization setting down to conservative.</p>
<p dir="auto">Running the 2.0 release build from September 2011.</p>
<p dir="auto">thanks</p>
]]></description><link>https://forum.netgate.com/topic/41327/active-ftp-from-opt-to-lan-network</link><generator>RSS for Node</generator><lastBuildDate>Thu, 11 Jun 2026 22:38:19 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/41327.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 25 Jan 2012 18:09:26 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Active FTP from opt to LAN network on Wed, 25 Jan 2012 20:58:24 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/marcelloc">@<bdi>marcelloc</bdi></a>:</p>
<blockquote>
<p dir="auto">If you are not using ftp proxy, you need a rule to allow traffic com ftp server source prot 20 to client ip any port.</p>
</blockquote>
<p dir="auto">I have a rule allowing unrestricted access from the server to the client to and from any port</p>
<p dir="auto">TCP &lt;server ip=""&gt;* &lt;opt subnet=""&gt;* * none   allow fs1 to imaging &lt;/opt&gt;&lt;/server&gt;</p>
]]></description><link>https://forum.netgate.com/post/316494</link><guid isPermaLink="true">https://forum.netgate.com/post/316494</guid><dc:creator><![CDATA[cubsfan]]></dc:creator><pubDate>Wed, 25 Jan 2012 20:58:24 GMT</pubDate></item><item><title><![CDATA[Reply to Active FTP from opt to LAN network on Wed, 25 Jan 2012 20:06:23 GMT]]></title><description><![CDATA[<p dir="auto">If you are not using ftp proxy, you need a rule to allow traffic com ftp server source prot 20 to client ip any port.</p>
]]></description><link>https://forum.netgate.com/post/316488</link><guid isPermaLink="true">https://forum.netgate.com/post/316488</guid><dc:creator><![CDATA[marcelloc]]></dc:creator><pubDate>Wed, 25 Jan 2012 20:06:23 GMT</pubDate></item></channel></rss>