FTP PASV not working

  • Hi All,

    I am runing Pfsense Version:2.2-RC (amd64) built on Fri Jan 16 11:53:08 CST 2015 i have users that regularly access FTP outside in the Internet and it seems that since i  moved to 2.2 RC its not working.

    The users are connecting  via NAT  , any known issue with current version?
    Please advice

  • LAYER 8 Global Moderator

    The ftp proxy/helper is not part of 2.2  Clients behind pfsense talking to ftp on say the public internet and using passive do not require any sort of helper/proxy in pfsense.  When you talk to server using passive, it tells you the IP to talk too. So unless your blocking outbound ports this would never be a problem.

    clients using active would require helper.  Since the ftp server makes the connection back to the client - so the helper would open the ports and quite often change the IP given by the client to the public one.

    Now if your running server behind pfsense and your clients are on the public internet - then yes you would need the helper..  Or you can manually setup the server to give its public IP not a local one, and use specific ports for the passive connection that you forward on pfsense.

    From other posts on the board and the bug report does not seem like helper will be back until atleast 2.2.1 if at all..

    See this thread https://forum.pfsense.org/index.php?topic=86703.0
    It has bug report url and info about how to work around it via firewall forwards, etc.

Log in to reply