<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Passive FTP Setup]]></title><description><![CDATA[<p dir="auto">I'm sure that everyone is sick of the FTP questions by now. I've been reading up on this for about 3 days and haven't found a solution that works. Here's my setup…</p>
<p dir="auto">I'm running v1.0.1.<br />
I have dual WAN's but I'm not doing any load balancing on them. The second WAN is simply a backup line and is only used in emergencies.<br />
I also have CARP setup and that is working fine. Every other protocol is working fine just not passive FTP.</p>
<p dir="auto">I have a CARP VIP setup for the web server that needs FTP.<br />
I then have 1:1 NAT pointing from the external VIP to the internal LAN IP of the server.<br />
The FTP-Proxy helper is disabled on all interfaces.</p>
<p dir="auto">In the firewall rules I have</p>
<p dir="auto">WAN    TCP    *    *    192.168.1.10 (servers ip)  FTP(21)    *<br />
    WAN    UDP    *    *    192.168.1.10                  20            *</p>
<p dir="auto">Active works fine at this point.</p>
<p dir="auto">I then setup MSFTP to use the passive ports  6100-6200 then added the following rule</p>
<p dir="auto">WAN    UDP    *    *    192.168.1.10  6100-6200    *</p>
<p dir="auto">I've tested the FTP from outside the local network and the active works fine but the passive freezes on the PASV command.<br />
I've tried turning the FTP-proxy app on and off and it seems to make no difference.</p>
<p dir="auto">What am I missing here? I am somewhat new to custom firewalling so please bear with me.  ???</p>
]]></description><link>https://forum.netgate.com/topic/5636/passive-ftp-setup</link><generator>RSS for Node</generator><lastBuildDate>Wed, 20 May 2026 01:02:04 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/5636.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 29 Aug 2007 20:52:16 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Passive FTP Setup on Sun, 02 Sep 2007 07:59:33 GMT]]></title><description><![CDATA[<p dir="auto">1.0.1 is not recommended for new installs. Try 1.2RC2. Also see http://devwiki.pfsense.org/FTPTroubleShooting</p>
]]></description><link>https://forum.netgate.com/post/159260</link><guid isPermaLink="true">https://forum.netgate.com/post/159260</guid><dc:creator><![CDATA[cmb]]></dc:creator><pubDate>Sun, 02 Sep 2007 07:59:33 GMT</pubDate></item><item><title><![CDATA[Reply to Passive FTP Setup on Fri, 31 Aug 2007 03:06:10 GMT]]></title><description><![CDATA[<p dir="auto">Any other thoughts?</p>
]]></description><link>https://forum.netgate.com/post/159218</link><guid isPermaLink="true">https://forum.netgate.com/post/159218</guid><dc:creator><![CDATA[ambientIT]]></dc:creator><pubDate>Fri, 31 Aug 2007 03:06:10 GMT</pubDate></item><item><title><![CDATA[Reply to Passive FTP Setup on Wed, 29 Aug 2007 22:48:26 GMT]]></title><description><![CDATA[<p dir="auto">I checked the logs and nothing is being blocked that I can see.</p>
]]></description><link>https://forum.netgate.com/post/159165</link><guid isPermaLink="true">https://forum.netgate.com/post/159165</guid><dc:creator><![CDATA[ambientIT]]></dc:creator><pubDate>Wed, 29 Aug 2007 22:48:26 GMT</pubDate></item><item><title><![CDATA[Reply to Passive FTP Setup on Wed, 29 Aug 2007 22:16:45 GMT]]></title><description><![CDATA[<p dir="auto">nope. i just looked it up. it's TCP<br />
–&gt; http://en.wikipedia.org/wiki/Ftp</p>
<p dir="auto">if you look at the firewall log. do you see anything blocked?</p>
]]></description><link>https://forum.netgate.com/post/159164</link><guid isPermaLink="true">https://forum.netgate.com/post/159164</guid><dc:creator><![CDATA[GruensFroeschli]]></dc:creator><pubDate>Wed, 29 Aug 2007 22:16:45 GMT</pubDate></item><item><title><![CDATA[Reply to Passive FTP Setup on Wed, 29 Aug 2007 22:09:46 GMT]]></title><description><![CDATA[<p dir="auto">I have also tried allowing TCP/UDP and it doesn't seem to help. From my limited knowledge I believe that the data ports only require UDP.</p>
]]></description><link>https://forum.netgate.com/post/159163</link><guid isPermaLink="true">https://forum.netgate.com/post/159163</guid><dc:creator><![CDATA[ambientIT]]></dc:creator><pubDate>Wed, 29 Aug 2007 22:09:46 GMT</pubDate></item><item><title><![CDATA[Reply to Passive FTP Setup on Wed, 29 Aug 2007 21:59:43 GMT]]></title><description><![CDATA[<p dir="auto">You allow only UDP. I'm not sure if it's that, but could it be that you need to put TCP there?</p>
]]></description><link>https://forum.netgate.com/post/159160</link><guid isPermaLink="true">https://forum.netgate.com/post/159160</guid><dc:creator><![CDATA[GruensFroeschli]]></dc:creator><pubDate>Wed, 29 Aug 2007 21:59:43 GMT</pubDate></item></channel></rss>