Hosting FTP Server under Wingate Firewall

Use this forum to post questions relating to WinGate, feature requests, technical or configuration problems

Moderator: Qbik Staff

Hosting FTP Server under Wingate Firewall

Postby trinh78 » Jun 09 06 5:23 pm

Hi,

We are using Wingate 6.1.1
We just deployed FTP on win 2k3. We set Redirect port 20-21 to win 2k3 in ENS port security.

User could get through authentication process only. After that, it showed up the warning message:

"200 Type set to A. 500 Invalid PORT Command. 500 'LPRT 6,16,0,0,0,0,0,0,0,0,67,0,0,0,0,0,90,94,2,6,222': command not understood "

I am able to connect to FTP server in local.

What should I do to figure out this problem?
trinh78
 
Posts: 20
Joined: Oct 14 03 2:42 pm

Postby genie » Jun 09 06 5:57 pm

First of all, you do not have to redirect port 20 - it might confuse QBIK application handler.

Now, what client did you use? Normal command line FTP client?
genie
Qbik Staff
 
Posts: 1788
Joined: Sep 30 03 10:29 am

Postby genie » Jun 09 06 6:02 pm

One more thing - where did this "long port" command come from? Did you use different clients for connecting from behind Wingate and from the outside?
genie
Qbik Staff
 
Posts: 1788
Joined: Sep 30 03 10:29 am

Postby trinh78 » Jun 09 06 6:04 pm

okay, I deleted redirect port 20 already.

I use both IE and FTP command line.
trinh78
 
Posts: 20
Joined: Oct 14 03 2:42 pm

Postby trinh78 » Jun 09 06 6:07 pm

genie wrote:One more thing - where did this "long port" command come from? Did you use different clients for connecting from behind Wingate and from the outside?


Of course, I did.

I tried one computer that has same subnet with Win2k3 server and one PC from the Internet (in other country).
trinh78
 
Posts: 20
Joined: Oct 14 03 2:42 pm

Postby genie » Jun 09 06 6:12 pm

Do you have IPv6 enabled on your remote client machine?
genie
Qbik Staff
 
Posts: 1788
Joined: Sep 30 03 10:29 am

Postby trinh78 » Jun 09 06 6:38 pm

genie wrote:Do you have IPv6 enabled on your remote client machine?


Absolute no,

One more thing, win2k3 is AD. Did it cause problem?
trinh78
 
Posts: 20
Joined: Oct 14 03 2:42 pm

Postby genie » Jun 09 06 7:07 pm

Nope - it shouldn't. What FTP server are you using?
genie
Qbik Staff
 
Posts: 1788
Joined: Sep 30 03 10:29 am

Postby trinh78 » Jun 09 06 7:27 pm

Sorry ! What are you mean?
trinh78
 
Posts: 20
Joined: Oct 14 03 2:42 pm

Postby genie » Jun 09 06 7:30 pm

I mean what FTP server software have you installed? Is it IIS?
genie
Qbik Staff
 
Posts: 1788
Joined: Sep 30 03 10:29 am

Postby genie » Jun 09 06 7:35 pm

For the sake of testing, can you, please, try to connect from a remote client using IE as an FTP but set:
In IE-> Tools -> Internet Option -> Advanced,
Folder view for FTP to false?
genie
Qbik Staff
 
Posts: 1788
Joined: Sep 30 03 10:29 am

Postby trinh78 » Jun 09 06 8:08 pm

Yes, I use IIS. But problem still be in being even though I alrealy set 'False' for the Option,'Enable folder view for FPT sites',as you sugest!
trinh78
 
Posts: 20
Joined: Oct 14 03 2:42 pm

Postby genie » Jun 10 06 12:06 am

One quick question - when you added this redirection on port 21, did you tick the checkbox "Do not translate source IP address"?
genie
Qbik Staff
 
Posts: 1788
Joined: Sep 30 03 10:29 am

Postby trinh78 » Jun 10 06 9:27 pm

genie wrote:One quick question - when you added this redirection on port 21, did you tick the checkbox "Do not translate source IP address"?


Sorry for late response,

I already stick "Do not translate source IP address"

I didn't only host FTP but aslo Web server through wingate by using Redirecting method. WEB SERVER is working properly but FTP is still some problem.

I will follow up and let you know the result.

Anyway, thanks for your kind support.
trinh78
 
Posts: 20
Joined: Oct 14 03 2:42 pm

Postby genie » Jun 10 06 10:42 pm

From what I see there are two separate kind of troubles:
1. Wingate does not support long port commands - we would probably add this support shortly but the current driver cannot process it
2. The server opted for using long port command rather than original port - I am not really literate in ISS configuration but is there anything that forces it to use simple port/passive modes only?
genie
Qbik Staff
 
Posts: 1788
Joined: Sep 30 03 10:29 am

Postby trinh78 » Jun 12 06 7:37 pm

genie wrote:From what I see there are two separate kind of troubles:
1. Wingate does not support long port commands - we would probably add this support shortly but the current driver cannot process it
2. The server opted for using long port command rather than original port - I am not really literate in ISS configuration but is there anything that forces it to use simple port/passive modes only?


Now, I'm using Passive Mode for FTP session. It's working fine now.

Thanks and regards,
trinh78
 
Posts: 20
Joined: Oct 14 03 2:42 pm


Return to WinGate

Who is online

Users browsing this forum: Bing [Bot] and 12 guests