• RSS
  • Twitter
  • FaceBook

Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

FTP Publishing as well

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA 2006 Publishing] >> Server Publishing >> FTP Publishing as well Page: [1]
Login
Message << Older Topic   Newer Topic >>
FTP Publishing as well - 15.Aug.2008 12:42:18 AM   
ashlarzen

 

Posts: 2
Joined: 14.Aug.2008
Status: offline
Hi. On my ISA 2006 firewall I have a Non-Web Server publishing rule for FTP configured for external access with the following settings:

Action - Allow
Traffic - All standard settings, Filter set to read only
Traffic from - External (Have tried Anywhere)
To - IP address of IIS6.0 server, Requests come from ISA server
Networks - External listener
Schedule - Always

The problem I get is when I try to connect externally the username and password seem to ok but it seems to bum out straight after with a 550 error.

If I use the ftptest on the site http://www.g6ftpserver.com/en/ftptest I get the following:

* About to connect() to www.domain.com.au port 21
* Trying %IP Address%... connected
* Connected to www.domain.com.au (%IP Address%) port 21
< 220 Microsoft FTP Service

> USER ftp.access
< 331 Password required for ftp.access.

> PASS *****
< 230-Welcome
< 230 User ftp.access logged in.

> PWD
< 257 "/" is current directory.
* Entry path is '/'

> CLNT Testing from http://www.g6ftpserver.com/ftptest from IP 203.36.44.15
< 550 Access is denied.
* QUOT command failed with 550
* Connection #0 to host www.domain.com.au left intact

* Closing connection #0

With an FTP Client from home it does the same thing.

My IIS6.0 server has been configured text book style pretty much copying the docs online and I even created a 2008 with the new FTP server but got the same thing.

The ISA server logs for FTP only say Initiated Connection then straight after Closed Connection for the rule.

Maybe I have missed something on IIS. I have never setup FTP before so...

Help!
Post #: 1
RE: FTP Publishing as well - 17.Aug.2008 7:16:27 PM   
royh

 

Posts: 318
Joined: 23.Feb.2007
From: Lebanon
Status: offline
Hi,

Before getting into details, check out the following links to configure your ftp server the right way:

http://www.microsoft.com/technet/prodtechnol/WindowsServer2003/Library/IIS/0d2a9b2e-b697-4bb3-8a61-0fad73a1fa08.mspx?mfr=true

http://www.windowsnetworking.com/articles_tutorials/Creating-Configuring-FTP.html

HTH,



_____________________________

Roy Haddad,M.Sc
CCNA, MCSE 2003 Messaging & Security,C|EH
www.foxminds.com

(in reply to ashlarzen)
Post #: 2
RE: FTP Publishing as well - 26.Aug.2008 9:52:38 PM   
ashlarzen

 

Posts: 2
Joined: 14.Aug.2008
Status: offline
Hmmm I have checked both FTP sites you have posted but it seems all my IIS is setup correctly. Any other ideas? This is driving me absolutely crazy!!!

I don't know if I mentioned it before but I only need downloads from my site not uploading.

(in reply to royh)
Post #: 3
RE: FTP Publishing as well - 31.Aug.2008 7:07:07 PM   
royh

 

Posts: 318
Joined: 23.Feb.2007
From: Lebanon
Status: offline
Check out the rights and permissions on your ftp home folders...

Thanks -


_____________________________

Roy Haddad,M.Sc
CCNA, MCSE 2003 Messaging & Security,C|EH
www.foxminds.com

(in reply to ashlarzen)
Post #: 4
RE: FTP Publishing as well - 3.Sep.2008 2:29:10 AM   
studlyed

 

Posts: 4
Joined: 28.Jun.2006
Status: offline
Sorry this is kind of scatter brained, but i hope it makes some sense.
I prefer to test internally with the basic ftp command from the command line. And filezilla for the external. Internaly you shouldn't have to do anything with passive (which is why i like the dos one) and externally filezilla will show you what is going between the client and the server.

FYI:
My FTP works perfectly fine, and that site says the same thing for me.
> CLNT Testing from http://www.g6ftpserver.com/ftptest from IP 98.202.138.194
< 550 Access is denied.
I have never seen the CLNT command, so i tried it in DOS ftp, it's not a valid command

The fact that it says 230 User ftp.access logged in says to me that it is authenticating properly. If it was permissions on the root folder of the ftp it would say something like home directory inaccessable (access denied) or some non-sense like that.

I would probably start by making it work from internal before worrying about the external. Internal is easier.

Have you tried using FTP from the command line directly to the ftp server's ip address. What about FTP'ing right from the ftp server...ftp localhost and then ftp <internal server ip>
And right after logging in, put in dir. Does it bring up a listing of the files.

In your client, do you see something like


Command: PASV

Response: 227 Entering Passive Mode (98,202,138,194,5,189)

In the response, if you are connecting from the outside, make sure it shows your external address, if not, you might need to enable the FTP Filter add-in inside of ISA....if it's not enabled, i would enable it anyways.
When you try from the inside, do you try and connect directly to the ftp server or to the isa servers ip? External or internal ip?

I hope this helps out some.

(in reply to ashlarzen)
Post #: 5

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA 2006 Publishing] >> Server Publishing >> FTP Publishing as well Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts