General discussion

Locked

FTP on NAT

By jnkomo ·
I have NAT confugured on a 1605 router, seperating a legacy network on an Equis mainframe from a Windows 2000 private network. There is no problem with users trying to NAT across the network.

However, when a user from the internal network(i.e.Private network)tries to FTP to the legacy network it works sometimes and not all the time.
What could be the problem?

Regards,

Joe

This conversation is currently closed to new comments.

5 total posts (Page 1 of 1)  
| Thread display: Collapse - | Expand +

All Comments

Collapse -

FTP on NAT

by LordInfidel In reply to FTP on NAT

You need to remember how FTP works. It has 2 modes, passive and normal.

Passive FTP, the client will initiate a connection from <=1024 to tcp 21. The client will also tell the server which port it is listening on

Then the server will make a connection from a port <=1024 to the port above 1024 the client machine is listening on.

With normal FTP it is basically the same. Except that the return connection from the server to the client will come from port 20 instead of over 1024.

So the first place I would look is to see how the firewall is set up. Then I would look on the client side and check to see what mode it is trying.

If you are using IE, it will by default try to use passive ftp.

I prefer normal ftp, because at least I can control the incoming source port instead od saying any new connections from anything over 1024 allow.

Collapse -

FTP on NAT

by jnkomo In reply to FTP on NAT

The question was auto-closed by TechRepublic

Collapse -

FTP on NAT

by mshavrov In reply to FTP on NAT

Who created config for your router? Do you have that person available? Possibly cause may be in big number of connections, pourly configured IOS firewall or IOS IDS, etc. You may send me your router config to have more detailed analysis (sure, delete all passwrd information and public IP addresses if any).

Collapse -

FTP on NAT

by jnkomo In reply to FTP on NAT

The question was auto-closed by TechRepublic

Collapse -

FTP on NAT

by jnkomo In reply to FTP on NAT

This question was auto closed due to inactivity

Back to Security Forum
5 total posts (Page 1 of 1)  

Related Discussions

Related Forums