Re: FTP server behind NAT using Kerio

From: Wolfgang Kueter (wolfgang@shconnect.de)
Date: 04/17/02


From: Wolfgang Kueter <wolfgang@shconnect.de>
Date: Wed, 17 Apr 2002 23:25:57 +0200

Mark wrote:

> Hi,
>
> I have a Windows 2000 FTP server running behind a Linksys DSL router.
> My router is configured to forward all port 21 requests to my server.
>
> I have Kerio 2.14 running on the server.

Unneccessary crap.

> Once the users have entered their usernames and passwords, Kerio flags
> the connection with an Outgoing Connection alert: IIS wants to reach
> someone through port 1069
> I tested it 5 times and I seem to get ports in the range of 1069 to
> 1103.
>
> Can somebody please explain to me exactly what is going on here? Is
> this NAT at work?

No, it is ftp at work.

> Can I open up a range of outgoing ports for IIS? What range would that
> be?

Random source ports. What abaout ftp-data? Who knows. Learn how ftp
functions.

Wolfgang

-- 
A foreign body and a foreign mind,
never welcome in the land of the blind.
Peter Gabriel, Not one of us, 1980



Relevant Pages

  • Re: passiver FTP auf windows server 2003
    ... aber nur bestimte Ports per TCP/IP ... Dies ist dann das Problem beim passiven FTP. ... Ich hoffe Du hast noch sowas wie eine Firewall vor dem Server stehen, ...
    (microsoft.public.de.german.windows.server.setup)
  • Re: ServU-deamon trojan warning with McAfee
    ... FTP FTP FTP. ... You did it to yourself by having FTP server on your SBS box without the ... > software didn't pick up this infection altough the DAT file included the ... > document what ports need to be opened and for what reason? ...
    (microsoft.public.backoffice.smallbiz2000)
  • About utility of a firewall with win2000 server
    ... I'm configuring a webserver. ... It will be used exclusively for web services (http and ftp). ... All the ports are opened as soon as an IP adress is affected? ... dans un datacenter. ...
    (microsoft.public.win2000.security)
  • Re: FTP Server Question
    ... >>understand why the server doesn't work when I disable UDP on the ports ... >>that you need both tcp and udp enabled and I've seen information that FTP ... I'm using non-standard ports with my server. ...
    (comp.security.firewalls)
  • Re: Whats a decent modem/router for tech savy user?
    ... It is not possible to route or deny traffic to specific ports based on the source IP address. ... But it wont route back inside the LAN - needs internal DNS server spoofing. ... Normally, this option should be Enabled, so that an Internet connection will be made automatically, whenever Internet-bound traffic is detected. ... Specifying a Default DMZ Server allows you to set up a computer or server that is available to anyone on the Internet for services that you haven't defined. ...
    (uk.telecom.broadband)