Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Accessing an FTP Server SOLVED

    Scheduled Pinned Locked Moved Firewalling
    4 Posts 2 Posters 947 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      mark99
      last edited by

      Hello all,
      I don't get It  :(

      Here is my Network:

      www –-- router 192.168.33.2 -----
                                                        |
                                                  192.168.33.254
                                                  pfsense -----------------------192.168.44.1
                                                        |                                            |
                                                      Lan1 192.168.33.0/24              |
                                                                                                  LAN 2 192.168.44.0/25
                                                                                                                  |
                                                                                                                FTP Server 192.168.44.200

      I am able to access the ftp server from my LAN1 but I think I have too many ports open.

      Firewall rule at the LAN1 interface:
      Proto:          IPv4
      Source:        *
      Port:            *
      Destination: 192.168.44.200
      Gateway:    *
      Queue:        none

      If I restrict the ports to 21 the system doesn't list the folder entries at the ftp servers,
      because higher prots get blockt trough the firewall (the log shows it)


      I want to  access the FTP Server from the www.
      The router 192.168.33.2 forwards the Port 21 to the pfsense system 192.168.33.254
      but I dont't get it, how to tell pfsense to forward that port to the ftp server.

      I tried Firewall -> Nat -> Port Forward

      IF:                Interface in LAN 1 (192.168.33.254)
      Port:            TCP
      Src. addr:      *
      Src. ports:    21 (FTP)
      Dest. addr.:  192.168.33.2
      Dest. port:    21 (FTP)
      NAT IP:        192.168.44.200
      NAT Ports:    21 (FTP)

      Could you please have a look at it and give me a hint?

      Thank you

      ![Bildschirmfoto 2015-02-10 um 21.16.57.png](/public/imported_attachments/1/Bildschirmfoto 2015-02-10 um 21.16.57.png)
      ![Bildschirmfoto 2015-02-10 um 21.34.40.png](/public/imported_attachments/1/Bildschirmfoto 2015-02-10 um 21.34.40.png)
      ![Bildschirmfoto 2015-02-10 um 21.16.57.png_thumb](/public/imported_attachments/1/Bildschirmfoto 2015-02-10 um 21.16.57.png_thumb)
      ![Bildschirmfoto 2015-02-10 um 21.34.40.png_thumb](/public/imported_attachments/1/Bildschirmfoto 2015-02-10 um 21.34.40.png_thumb)

      1 Reply Last reply Reply Quote 0
      • M
        mark99
        last edited by

        I am still testing.
        Now I cann connect to my ftp Server with the attached rules.

        The FTP Client is able to connect but doesn't show the contens of the directory.
        Something is missing.  :-[

        ![Bildschirmfoto 2015-02-10 um 22.17.35.png](/public/imported_attachments/1/Bildschirmfoto 2015-02-10 um 22.17.35.png)
        ![Bildschirmfoto 2015-02-10 um 22.17.35.png_thumb](/public/imported_attachments/1/Bildschirmfoto 2015-02-10 um 22.17.35.png_thumb)

        1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator
          last edited by

          2.2 no longer has a ftp helper/proxy.  Depending on what type of connection your doing either active or passive and what IP your ftp server gives your going to have to make adjustments to the rules.

          https://doc.pfsense.org/index.php/FTP_without_a_Proxy

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.8, 24.11

          1 Reply Last reply Reply Quote 0
          • M
            mark99
            last edited by

            Thank you johnpoz,

            that was it.
            With a sftp server it works fine.

            Markus

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.