D-Link Forums

The Graveyard - Products No Longer Supported => D-Link NetDefend Firewalls => Topic started by: centaurcon on March 21, 2011, 04:56:31 PM

Title: DFL-800 FTP pasv setup
Post by: centaurcon on March 21, 2011, 04:56:31 PM
I am setting up a Filezilla server inside a DFL-800.  we are using FTPS and it works from a computer inside the network.

From outside, I get to the point were the client shows Initializing TLS...

The server says connected sending welcome message, but nothing ever arrives, including the certificate.

What am i missing?
Title: Re: DFL-800 FTP pasv setup
Post by: silver_surfer30 on March 24, 2011, 10:57:35 AM
Hello I find this explanation quite good.
Have a look at it.

http://geekswithblogs.net/Lance/archive/2005/08/23/50912.aspx

That should help solving the issue.

But that cause security breach. You need to be aware of it .
Title: Re: DFL-800 FTP pasv setup
Post by: centaurcon on March 24, 2011, 09:42:13 PM
Thanks for the reply Silver_surfer30, however the information in the post is information already known to me...

I have setup FTPS at another clients in the past, and it worked great.  Set it to use PASV as a connection and spesified a port range in filezilla server and forwarded the same ports from the NAT to the server.  Outside clients connected fine.

I am trying to get the same thing to work here.  However I can't quite seem to get it to work correctly.

in fact, I can't get any PASV connection to work through the NAT.  I can however get a standard Active FTP connection on port 21 to work, however as soon as I try to do something as simple as change the port, (at client, server and NAT firewall) then the system fails.  The FTP sever registeres a login, but the welcome message or directly listing is unable to be delivered.

It is very frustrating.
Title: Re: DFL-800 FTP pasv setup
Post by: xavierbt on March 26, 2011, 01:26:14 AM
Could you post your dfl-800 ftp server configuration ?
Title: Re: DFL-800 FTP pasv setup
Post by: chechito on April 05, 2011, 12:16:58 PM
for ftp traffic maybe try the ftp alg's