by inthesands » Sep 09 04 7:34 pm
I had all IE's proxy set to use Wingate.
But, I also setup my pc to go direct, ie via NAT.
But I have figured it out, I could see in the Wingate Firewall log window, that a reply was coming back via port 1654. So I Setup Port Security in Extended Networking, to let any port from 1024 to 4096 to come into the Wingate (all was denied by fault). This works. If I allowed only 21, it wouldn't work. So I denied all again, and it fails, but the port the FTP server replied back on was a different port than 1654 (as above). Next time it came in at 1670, another time 1666.
In my case, I have the FTP in a DMZ. So I only want to allow ONLY ftp port 21 to go out, but this doesn't work. Open all out above 1024, and it does.