• pfsense and ftp servers...

    From Shurato@CAPCITY2 to All on Wed Sep 4 18:32:00 2024
    What port forwarding rules do you have in effect to allow FTP? I've got
    20,21 and my PASV range. The PASV ports are giving an error with filezilla
    or explorer, though.

    Error:
    Server sent passive reply with unroutable address. Passive mode failed.

    I've got the right ports set in the firewall and my ftp server, as well as
    the same IP address for all of the ftp server ports, which is also correct.

    This is the only thing (other than my google nest for some weird reason) that isn't working after installing pfsense. The friend that set it up for me
    also has problems with FTP on his system remotely, but not locally.

    --
    Shurato, Sysop Shurato's Heavenly Sphere (ssh, telnet, pop3, ftp,nntp,
    ,wss) (Ports 22,23,110,21,119,8080) (ssh login 'bbs' pass 'shsbbs').


    *** THE READER V4.50 [freeware]
    ---
    * Origin: Shurato's Heavenly Sphere telnet://shsbbs.net (618:300/50)
    * Synchronet * CAPCITY2 * capcity2.synchro.net * Telnet/SSH:2022/Rlogin/HTTP
  • From Shurato@CAPCITY2 to Shurato on Wed Sep 4 19:13:00 2024
    What port forwarding rules do you have in effect to allow FTP? I've got 20,21 and my PASV range. The PASV ports are giving an error with filezilla or explorer, though.

    Error: Server sent passive reply with unroutable address. Passive
    mode failed.

    I've got the right ports set in the firewall and my ftp server, as well as the same IP address for all of the ftp server ports, which is also correct.

    This is the only thing (other than my google nest for some weird reason) that isn't working after installing pfsense. The friend that set it
    up for me also has problems with FTP on his system remotely,
    but not locally.

    Nevermind, it's because I'm behind a VPN to avoid hairpinning. It's not allowing the PASV ports to come through my real IP. I've got logs showing
    that ftp connections have been made successfully and that files have been transfered.

    --
    Shurato, Sysop Shurato's Heavenly Sphere (ssh, telnet, pop3, ftp,nntp,
    ,wss) (Ports 22,23,110,21,119,8080) (ssh login 'bbs' pass 'shsbbs').


    *** THE READER V4.50 [freeware]
    ---
    * Origin: Shurato's Heavenly Sphere telnet://shsbbs.net (618:300/50)
    * Synchronet * CAPCITY2 * capcity2.synchro.net * Telnet/SSH:2022/Rlogin/HTTP
  • From digimaus@CAPCITY2 to Shurato on Thu Sep 5 00:27:47 2024
    Shurato wrote to All:
    Error:
    Server sent passive reply with unroutable address. Passive mode failed.

    That is because behind your firewall, you need to turn passive mode OFF (aka "active mode") to use your FTP server. Passive is meant to allow poeople to connect your NAT firewall to your FTP server. What passive mode does is reverse the roles--your computer becomes the server and the FTP servwer
    becomes the client--and yoiu do not need that -behind- your firewall.

    pfSense has the built-in "FTP" role in its port forwarding setup and it will handle both FTP ports--FTP uses ports 20 and 21--for you.

    Your friend is having the same exact issue.

    Both of you sorely need to read up on what you're doing wrong. The answers
    are out there and you need to find them.

    All of the questions you're asking about can be easily solved by a simple
    Web search. You seem to not to want to look up the answers yourself.

    I still can spend hours looking for arcane knowledge I need to fix something
    on my BBS. A lot of your questions are found in "Networking 101".

    Before you go any farther, read this:

    https://www.ncftp.com/ncftpd/doc/misc/ftp_and_firewalls.html

    You'll understand better why your FTP server is not working.

    I promise this all is not a "black box": everything you're experiencing is
    from a lack of experience and knowledge.

    It is very easy to do what you're doing with a little time spent researching and gaining knowledge.

    Now you've reminded me I need to finish setting up my FTP server. Not from
    a lack of knowledge but more from being lazy. XD

    -- digi




    --- MBSE BBS v1.1.0 (Linux-x86_64)
    * Origin: Outpost BBS * Johnson City, TN (618:618/1)
    * Synchronet * CAPCITY2 * capcity2.synchro.net * Telnet/SSH:2022/Rlogin/HTTP
  • From Shurato@CAPCITY2 to digimaus on Thu Sep 5 00:54:00 2024
    Shurato wrote to All:
    Error: Server sent passive reply with unroutable address. Passive
    mode failed.

    That is because behind your firewall, you need to turn passive mode OFF (aka "active mode") to use your FTP server. Passive is meant to allow poeople to connect your NAT firewall to your FTP server. What
    passive mode does is reverse the roles--your computer becomes the
    server and the FTP servwer becomes the client--and yoiu do not need
    that -behind- your firewall.

    Yeah, I realized all of that and corrected myself in the next post.

    --
    Shurato, Sysop Shurato's Heavenly Sphere (ssh, telnet, pop3, ftp,nntp,
    ,wss) (Ports 22,23,110,21,119,8080) (ssh login 'bbs' pass 'shsbbs').


    *** THE READER V4.50 [freeware]
    ---
    * Origin: Shurato's Heavenly Sphere telnet://shsbbs.net (618:300/50)
    * Synchronet * CAPCITY2 * capcity2.synchro.net * Telnet/SSH:2022/Rlogin/HTTP