Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Force FTP to use a particular WAN Interface

    Scheduled Pinned Locked Moved Firewalling
    9 Posts 6 Posters 3.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      shaunf
      last edited by

      Hi,

      I am trying to create a rule which will force ftp connections to use a particular WAN interface but it still seems to use the default interface.

      screenshot attached

      Thanks
      shaun
      LAN.jpg
      LAN.jpg_thumb

      1 Reply Last reply Reply Quote 0
      • GruensFroeschliG
        GruensFroeschli
        last edited by

        Read up on wikipedia how FTP works.

        Port 21 is only the command port.
        There is always a second port in use over which data is being transfered.

        I'm not really sure if you can force all ftp traffic out a specific WAN with such a rule.

        I think the ftp-helper can solve this but since i dont use it i cannot help you on this.
        hoba is the ftp-helper specialist :)

        We do what we must, because we can.

        Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

        1 Reply Last reply Reply Quote 0
        • P
          Perry
          last edited by

          The only way i can think of goes like this :)
          Disable FTP helper on lan
          TCP Lan net * * 217.45.208.86 10000-65000            Passiv Ports
          TCP Lan net * * 217.45.208.86 21                          FTP

          /Perry
          doc.pfsense.org

          1 Reply Last reply Reply Quote 0
          • GruensFroeschliG
            GruensFroeschli
            last edited by

            Well yes that would work but….
            I dont think anyone would want to force everything above 10000 out the second WAN :D

            We do what we must, because we can.

            Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

            1 Reply Last reply Reply Quote 0
            • S
              shaunf
              last edited by

              Hi,

              FTP is working so no issues there…..i just need it to only use a specific WAN or WAN pool

              Thanks
              Shaun

              1 Reply Last reply Reply Quote 0
              • H
                hoba
                last edited by

                ftp can only be used with multiwan if the ftp helper is enabled. This will force all ftp connections to the main WAN though. No other option available currently, as ftp happens on multiple ports and the ports are depending on the ftp server's configuration.

                1 Reply Last reply Reply Quote 0
                • JeGrJ
                  JeGr LAYER 8 Moderator
                  last edited by

                  Any way one can modify binding the FTPhelper not to WAN but OPT1 instead? I have the faster line on OPT1 and the slower but synchronous line on WAN 'cause OVPN, too, only works on WAN for tunneling.

                  Anything one can do manually?

                  Don't forget to upvote 👍 those who kindly offered their time and brainpower to help you!

                  If you're interested, I'm available to discuss details of German-speaking paid support (for companies) if needed.

                  1 Reply Last reply Reply Quote 0
                  • C
                    cmb
                    last edited by

                    In 1.2 you're stuck using FTP only on the WAN interface, not any OPT WANs. You'll have to switch your OPT to WAN unfortunately.

                    Already been addressed in 1.3.

                    1 Reply Last reply Reply Quote 0
                    • JeGrJ
                      JeGr LAYER 8 Moderator
                      last edited by

                      Ouch. OK I'll leave this as "has to be done like it's done" until we are at 1.3beta/rc. But thanks for the message.

                      Don't forget to upvote 👍 those who kindly offered their time and brainpower to help you!

                      If you're interested, I'm available to discuss details of German-speaking paid support (for companies) if needed.

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.