Created on ‎04-17-2009 03:59 PM
config firewall vip
edit " Virtual_FTP"
set extip xx.xx.xx.xx
set extintf " wan1"
set portforward enable
set mappedip yy.yy.yy.yy
set extport 21
set mappedport 21
next
end
config firewall policy
edit 14
set srcintf " wan1"
set dstintf " internal1"
set srcaddr " FTPgroup"
set dstaddr " Virtual_FTP"
set action accept
set schedule " always"
set service " FTP"
set logtraffic enable
next
end
regards
/ Abel
Created on ‎04-18-2009 12:51 AM
your config seems to use Active Mode of FTP not passive because you must open passive ports range, if you use proftpd look PassivePorts entry in proftpd.confi' m using active/passive mode with this setup using vsftpd servers (not proftpd) i' m talking active/passive in the http://slacksite.com/other/ftp.html sense. (you can move from 1-65535 to 1024-65535 your source custom service ports but this is just a comment, not directly related to the thread) btw, maybe it' s forged to post here, but the ftp server you' ve posted seems to be a windoze one. not a proftpd one. ftp 213.177.64.21 Connected to 213.177.64.21. 220 Welcome to ContactOnline User' s area 504 Unknown auth method GSSAPI 504 Unknown auth method KERBEROS_V4 KERBEROS_V4 rejected as an authentication type Name (213.177.64.21:abel): anonymous 331 Guest login ok, send your complete e-mail address as password. Password: 530 Login incorrect - (anonymous), No Domain or User Class defined for User. Login failed. Remote system type is Windows_NT.
regards
/ Abel
Created on ‎04-20-2009 12:25 AM
Created on ‎04-21-2009 09:30 AM
| User | Count |
|---|---|
| 2686 | |
| 1412 | |
| 810 | |
| 704 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.