Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

FTP Server (Passive Mode) on WAN Interface via DNAT - WAN -> Local Server - stuck with SYN_RECV on local server.

Hi All,

I think I need a little help.

1. Used DNAT rule to route public ip to private ftp server - service FTP.

2. set advanced-firewall ftpbounce-prevention data 

3. On my local network I can login to my ftp server via "ftp public_ip" I can login and upload data.

4. When running from a truly remote device outside my network "ftp public_ip" results in a timeout.

On the device - private linux ftp server. I can see the inbound SYN_RECV but it doesn't do anything with it from then. So the original public ftp request times out.

Is there a setting i am missing to get it to correctly respond from my private ftp server to the public ftp client. I have tried setting the masquerade FTP server address as both the private ip address for translation by my existing rule or as the public ip address. No joy.

Many thanks to anyone that can help.



This thread was automatically locked due to age.
Parents Reply Children
No Data