IIS
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsSystem AdministrationIIS

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
Stop making mediocre tutorials.The best tutorials are video! Camtasia Studio makes it easy to create engaging, buzz-building screen videos at any size, in any popular format. Download the free trial!
  #1  
Old April 22nd, 2005, 11:21 AM
ProTrooper ProTrooper is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Apr 2005
Posts: 12 ProTrooper User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 4 h 4 m 16 sec
Reputation Power: 0
Required FTP ports

Hey,
I have a quick question. For a temporary firewall I just want to use TCP/IP filtering. I blocked all ports but TCP 80, 20, and 21. The http web hosting works fine but when I try to connect to the ftp it will not allow me. Are there any UDP, IP or other TCP ports I need to allow to let the ftp server work?

Thanks for the help.

Reply With Quote
  #2  
Old April 22nd, 2005, 12:04 PM
ProTrooper ProTrooper is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Apr 2005
Posts: 12 ProTrooper User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 4 h 4 m 16 sec
Reputation Power: 0
Update:
The required port I am looking for allows local connections. It will allow people to connect outside of the network but not internally. Thanks.

Reply With Quote
  #3  
Old April 24th, 2005, 11:56 AM
Doug G Doug G is offline
Grumpier Old Moderator
Dev Shed God 12th Plane (10500 - 10999 posts)
 
Join Date: Jun 2003
Posts: 10,717 Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level) 
Time spent in forums: 1 Month 40 m 34 sec
Reputation Power: 688
You should be able to connect via FTP if port 21 is open.
__________________
======
Doug G
======
"Hide, hide witch! The good folk come to burn thee. Their keen enjoyment hid behind their gothic mask of duty." -Mark Clifton

Reply With Quote
  #4  
Old April 25th, 2005, 09:41 AM
ProTrooper ProTrooper is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Apr 2005
Posts: 12 ProTrooper User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 4 h 4 m 16 sec
Reputation Power: 0
We should but for some reason that's not the case. The server log has us connected and disconnects after a timeout. So that means TCP/IP filtering is blocking outgoing traffic on some other port, right?

Thanks for the help.

Reply With Quote
  #5  
Old April 26th, 2005, 10:49 AM
juniperr juniperr is offline
network dude
Dev Shed Intermediate (1500 - 1999 posts)
 
Join Date: Dec 2003
Posts: 1,679 juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level) 
Time spent in forums: 1 Week 6 Days 21 h 55 m 2 sec
Reputation Power: 85
If you are connecting to a passive ftp server then you will need to allow the internal boxes to connect to that ftp server on the random ports. passive ftp servers have the users make the data connection on random ports instead of the standard ftp server making the connection to the client on ports 20 and 21 this is to allow the firewalls to not allow connections from outside in but allows the client to make the connection and the firewall allow only the responses in that is why standard ip based firewalls suxxors and you will never get this to work without a layer 4 firewall. if the ftp server is an active server apposed to a passive turn off passive mode on the client it will then use 20 and 21.

avtive and passive ftp servers

if you are using IIS FTP server it is passive and there is a reg hack to force it to use certain ports so you can open the firewall for them.

Last edited by juniperr : April 26th, 2005 at 10:57 AM.

Reply With Quote
  #6  
Old April 27th, 2005, 09:42 AM
ProTrooper ProTrooper is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Apr 2005
Posts: 12 ProTrooper User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 4 h 4 m 16 sec
Reputation Power: 0
Thanks Juniperr, that's exactly it. I disabled "use passive" in internet explorer and it worked fine. How do big web servers secure passive ftp ports? What are the drawbacks to active?

Thanks again for the help.

Reply With Quote
  #7  
Old April 27th, 2005, 11:55 AM
juniperr juniperr is offline
network dude
Dev Shed Intermediate (1500 - 1999 posts)
 
Join Date: Dec 2003
Posts: 1,679 juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level) 
Time spent in forums: 1 Week 6 Days 21 h 55 m 2 sec
Reputation Power: 85
The biggest problem with active FTP is that lets say I am hosting an FTP server that is active only and you are at work and want to download using ftp from my ftp server, in order for you to get there your admin would have to allow ports 20 and 21 in and out as well in active mode the server is the one to make the connection to the client which posses a security problem as you dont ever want someone outside your network to be able to start a session into your network. Any good firewall today is connection aware it will allow nothing in except responses (it does this by looking at the TCP connection info or by timers for UDP since it is not connection oriented) so passive mode FTP was adopted this basicly works by the server telling the client to start a new data session on a random port (which a range can be specified) the ftp server will open and listen on that port and the client will then initiate the session so the firewall is not an issue anymore. In my network I use FTP over SSL in passive mode I configured my server to only tell clients to use certain ports then I open my firewall to accomidate these ports only, connections are not able to be made on these ports unless the server told the client to use them and it starts listening on them then they shut back down when the session is over.

Reply With Quote
  #8  
Old April 28th, 2005, 10:46 AM
Doug G Doug G is offline
Grumpier Old Moderator
Dev Shed God 12th Plane (10500 - 10999 posts)
 
Join Date: Jun 2003
Posts: 10,717 Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level) 
Time spent in forums: 1 Month 40 m 34 sec
Reputation Power: 688
Thanks for the article link juniperr

Reply With Quote
  #9  
Old April 28th, 2005, 04:29 PM
juniperr juniperr is offline
network dude
Dev Shed Intermediate (1500 - 1999 posts)
 
Join Date: Dec 2003
Posts: 1,679 juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level) 
Time spent in forums: 1 Week 6 Days 21 h 55 m 2 sec
Reputation Power: 85
Nice simple article that can explain it way better then I ever could LOL! your welcome.

Reply With Quote
  #10  
Old May 4th, 2005, 09:23 AM
ProTrooper ProTrooper is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Apr 2005
Posts: 12 ProTrooper User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 4 h 4 m 16 sec
Reputation Power: 0
Thanks for the help. I'm not going to ask you to tell me how, but do you know where I can find out how to set my server up like that? Right now I am just using IPSec, so the ports are either open or closed. Thanks again for all the help juniperr. This forum has been the most helpful.

Reply With Quote
  #11  
Old May 5th, 2005, 07:13 AM
juniperr juniperr is offline
network dude
Dev Shed Intermediate (1500 - 1999 posts)
 
Join Date: Dec 2003
Posts: 1,679 juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level)juniperr User rank is Second Lieutenant (5000 - 10000 Reputation Level) 
Time spent in forums: 1 Week 6 Days 21 h 55 m 2 sec
Reputation Power: 85
Just like most of microsofts products they work but not very well LOL! go here and get a real FTP server if you would like to have FTP over SSL or a FTP server that is very flexible and easy to manage..

http://www.g6ftpserver.com/

Reply With Quote
  #12  
Old May 5th, 2005, 10:49 AM
ProTrooper ProTrooper is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Apr 2005
Posts: 12 ProTrooper User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 4 h 4 m 16 sec
Reputation Power: 0
Thanks, juniperr. I like how their site looks strangly similar to Microsoft's.

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationIIS > Required FTP ports


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support |