Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

FTP traffic blocked - NAT / Firewall configured

Dear all,

i am struggeling a little bit with the 9.409.9 Version of Sophos UTM - inbound (destination nat) is defined to forward ftp traffic to a internal IP, FTP Server is up and running, firewall advanced - ftp is activated - firewall log shows the following entries, the interesting part here is the port change - any idea how this could be opened?

only idea until now was:

a) enable firewall - advanced - connection helper - ftp

b) add nat rule any -> ftp -> uplink ip address to internal ip 

c) add nat rule any -> high ports (1024-65535) -> uplink ip address to internal ip 

as soon as i disable c, the whole stuff is no longer working - i would not really want to forward all high ports to the ftp server, any hints?

17:49:12   TCP  
176.9.146.xxx : 21
130.180.7.xxx : 35909
 
[ACK PSH] len=92 ttl=63 tos=0x00
17:49:17 Default DROP TCP  
130.180.7.xxx : 36692
176.9.146.xxx : 36284
 
[SYN] len=52 ttl=55 tos=0x00 srcmac=84:c1:c1:76:a9:75 dstmac=00:50:56:00:c0:89
17:49:17 Default DROP TCP  
130.180.7.xxx : 36692
176.9.146.xxx : 36284
 
[SYN] len=52 ttl=55 tos=0x00 srcmac=84:c1:c1:76:a9:75 dstmac=00:50:56:00:c0:89
17:49:20 Default DROP TCP  
130.180.7.xxx : 36692
176.9.146.xxx : 36284
 
[SYN] len=52 ttl=55 tos=0x00 srcmac=84:c1:c1:76:a9:75 dstmac=00:50:56:00:c0:89
17:49:24 Default DROP TCP  
130.180.7.xxx : 36692
176.9.146.xxx : 36284
 
[SYN] len=52 ttl=55 tos=0x00 srcmac=84:c1:c1:76:a9:75 dstmac=00:50:56:00:c0:89


This thread was automatically locked due to age.
  • Hi Tobias,

    a. This helper is for internal users of external FTP servers.
    b. I assume you mean 'DNAT : Internet -> FTP -> External (Address) : to {FTP server}'
    c. This will prevent you from reaching the UTM via your public IP unless you have a separate IP for these FTP accesses.  If you have only a single IP, you will want to create a NoNAT rule for port 4444.

    You should be able to limit the range of ports that your FTP server gives to the clients.  Other than that, you're stuck with the 1024:65535 rule.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • perfect, thanks, this helps a lot ;)

Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?