Networking Forums

Networking Forums > Computer Networking > Windows Networking > FTP Users behind NAT

Reply
Thread Tools Display Modes

FTP Users behind NAT

 
 
Michal Fryda
Guest
Posts: n/a

 
      11-09-2005, 11:38 AM
Hi !
Have a little problem witn win 2003 server NAT. All my users are behind NAT
and the problem is when they are trying to log to ftp server outside of
company.
They authenticate to it and when they suppose to receive list of directories
they are dosconected. When using passive FTP it works fine. Anyone knows
some solution ? There is not firewall on server.

Thanks a lot in advance.


 
Reply With Quote
 
 
 
 
Chris Priede
Guest
Posts: n/a

 
      11-09-2005, 01:54 PM
Hi,

Michal Fryda wrote:
> They authenticate to it and when they suppose to receive list of
> directories they are dosconected. When using passive FTP it works
> fine.


This is normal. By design, active FTP isn't intended to work with the
client behind NAT; if it ever does, it is only when the NAT routing software
in question specifically looks for FTP control messages passing through,
alters them, and automatically forwards ports.

> Anyone knows some solution ?


Use passive FTP. This is exactly why it was invented.


--
Chris Priede




 
Reply With Quote
 
MichalF
Guest
Posts: n/a

 
      11-09-2005, 02:09 PM
Well there must be way how to make it use active FTP

"Chris Priede" <(E-Mail Removed)> píše v diskusním příspěvku
news:(E-Mail Removed)...
> Hi,
>
> Michal Fryda wrote:
>> They authenticate to it and when they suppose to receive list of
>> directories they are dosconected. When using passive FTP it works
>> fine.

>
> This is normal. By design, active FTP isn't intended to work with the
> client behind NAT; if it ever does, it is only when the NAT routing
> software in question specifically looks for FTP control messages passing
> through, alters them, and automatically forwards ports.
>
>> Anyone knows some solution ?

>
> Use passive FTP. This is exactly why it was invented.
>
>
> --
> Chris Priede
>
>
>
>



 
Reply With Quote
 
Pierrot Robert
Guest
Posts: n/a

 
      11-09-2005, 02:31 PM
And why don't you want to use passive ftp ?

MichalF wrote:
> Well there must be way how to make it use active FTP
>



 
Reply With Quote
 
MichalF
Guest
Posts: n/a

 
      11-09-2005, 02:37 PM
Well i dont really have problem with that but not all of FTP servers support
passive connections. So thats why i need that . :-(


"Pierrot Robert" <mcthepro_at_hotmail.com> píše v diskusním příspěvku
news:(E-Mail Removed)...
> And why don't you want to use passive ftp ?
>
> MichalF wrote:
>> Well there must be way how to make it use active FTP
>>

>
>



 
Reply With Quote
 
Chris Priede
Guest
Posts: n/a

 
      11-09-2005, 03:07 PM
Hi,

MichalF wrote:
> Well there must be way how to make it use active FTP


Due to your insistence on not living with just passive FTP, I've looked at
the docs and it would appear that NAT in Windows 2003 RRAS has active FTP
translation support, but you have to enable it with:

netsh routing ip nat add ftp

This is documented here (watch out for long URL wrap):

http://www.microsoft.com/technet/pro...f4e9f04df.mspx

Hope that helps.

--
Chris Priede


 
Reply With Quote
 
Phillip Windell
Guest
Posts: n/a

 
      11-09-2005, 03:50 PM
"MichalF" <(E-Mail Removed)> wrote in message
news:eqgFV%(E-Mail Removed)...
> Well there must be way how to make it use active FTP


Most likely not.
NAT does have *limitations*
That is why "Passive" was invented.

Passive is the only way I have ever seen it work from behind a NAT Device
--
Phillip Windell [MCP, MVP, CCNA]
www.wandtv.com
-----------------------------------------------------
Understanding the ISA 2004 Access Rule Processing
http://www.isaserver.org/articles/IS...cessRules.html

Microsoft Internet Security & Acceleration Server: Guidance
http://www.microsoft.com/isaserver/t...dance/2004.asp
http://www.microsoft.com/isaserver/t...dance/2000.asp

Microsoft Internet Security & Acceleration Server: Partners
http://www.microsoft.com/isaserver/partners/default.asp
-----------------------------------------------------



 
Reply With Quote
 
MichalF
Guest
Posts: n/a

 
      11-10-2005, 07:44 AM
This works ! Thanks a lot !

"Chris Priede" <(E-Mail Removed)> píše v diskusním příspěvku
news:(E-Mail Removed)...
> Hi,
>
> MichalF wrote:
>> Well there must be way how to make it use active FTP

>
> Due to your insistence on not living with just passive FTP, I've looked at
> the docs and it would appear that NAT in Windows 2003 RRAS has active FTP
> translation support, but you have to enable it with:
>
> netsh routing ip nat add ftp
>
> This is documented here (watch out for long URL wrap):
>
> http://www.microsoft.com/technet/pro...f4e9f04df.mspx
>
> Hope that helps.
>
> --
> Chris Priede
>



 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
VPN Server - AD users OK - NT Users not OK Robert Nafty Windows Networking 3 07-16-2008 02:41 PM
new users cannot access via samba or netatalk, although both work fine for "old users" Christian Linux Networking 0 07-20-2004 06:20 PM
NIS Users and Local Users Dusty Linux Networking 1 11-22-2003 12:36 PM
PROFTPD: Some users cannot upload files, some users cannot get directory listing Marc Linux Networking 0 10-24-2003 06:18 AM
PROFTPD: Some users cannot upload files, some users cannot get directory listing Marc Linux Networking 1 10-24-2003 05:50 AM



1 2 3 4 5 6 7 8 9 10 11