FTPS behind NAT and Firewall

FTPS behind NAT and Firewall

Secure Home | Search | About
 Networking Firewalls    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
FTPS behind NAT and Firewall darkog 05-07-2008
Posted by darkog on May 7, 2008, 8:08 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hello, I am having trouble getting FTPS to work behind a NAT and
chained firewalls.

It's setup to use port 990 and a predetermined ranged in the >1024, i
will used 40001 to 40100 as an example here, that has been agreed
between us and the other company.

At the firewall console, I am not seeing any drops indicating that
there is any automatic FTP bounce prevention active.

The sessions works as follows.

- the client initiates a connection on port 990 and a random port in
the > 1024 range.
- the server issues a certificate
- the client accepts the trusted certficate
- then a second port is opened in the 40001 to 40100 range. .
- and the session begins and user is able to list directory listings
and transfer files.

When I try to make this work behind NAT, it breaks right at the point
where the client tried to get a directory listing.

When I do a traffic capture of a non-NAT session, i am seeing that
around packet 30 - 40, a SYN is sent to client , then communication
starts in the port range 40001 to 40100. When I capture in a NATed
session, I never see the that SYN.

Any help or suggestions would be appreciated.

Similar ThreadsPosted
Norton 2005 Internet Worm Protection (Firewall) or Windows XP native firewall? December 11, 2004, 11:19 am
[Newbie alert!] Is the Linksys BEFSX41 hardware Firewall/router a "real" firewall? March 25, 2005, 11:12 am
firewall synchronization not properly working on RainWall/CheckPoint's firewall cluster April 13, 2006, 10:24 am
SP2 Windows Firewall : Can the values of Firewall Settings be read from the Registry? November 6, 2007, 9:10 am
Firewall-1 Licensing Counting Each Interface of Firewall as a Separate Host February 13, 2008, 1:19 am
Firewall (cheap) that supports PPTP inbound to firewall July 30, 2004, 7:53 pm
Email Firewall - MXtreme Mail Firewall May 24, 2005, 11:15 am
If I Have a Firewall Router Do I Need a Software Firewall? October 24, 2005, 9:06 am
LavaSoft Firewall -vs- Outpost Pro Firewall November 16, 2005, 8:41 am
Windows XP firewall behind DSL-Router firewall ? December 20, 2005, 6:08 pm

The site map in XML format XML site map

Contact Us | Privacy Policy