Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 10 of 10
  1. #1
    Member
    Join Date
    Mar 2005
    Posts
    6

    Default ProFTPD Passive Configuration

    Hello all.

    I seem to be having issues getting ProFTP to listen/communicate on passive ports.

    I've added

    PassivePorts 1025 1050

    to my proftpd.conf file

    and opened 1025 - 1050 on my filewall, however it dosnt seem to be working properly.

    I dont seem to find much on these forums or at the proftp wages either...

    Any suggestions/comments?

    Matt

  2. #2
    Member
    Join Date
    Sep 2004
    Posts
    422

    Default

    How many clients do you have ? You'd usually need more than 25 ports for passive usage, maybe twice the number of your clients would be a rule of thumb.

  3. #3
    Member
    Join Date
    Mar 2005
    Posts
    6

    Default

    I'm the only one connected...

  4. #4
    Member
    Join Date
    Mar 2005
    Posts
    6

    Default

    Cant seem to put my finger on it.

    netstat confirms pureftp (switched to pureftpd btw) is running properly and utilizing the correct ports.

    I can connect to the server, browse directories, and even download data. However, when I try to place data on the server, I get a 550 error. Normally 550 is no permissions, however I do have permissions, and if I remove the firewall it does allow me to upload data fine.

    I have 21,1025-1050 open.

    Should work fine or am I missing someting?

    Matt

  5. #5
    Member
    Join Date
    Sep 2004
    Posts
    422

    Default

    Try opening port 20 in your firewall as well - that may help.

  6. #6
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    Are you using an SPI firewall such as APF? If so, there's no need at all to open up ephemeral ports for PASV FTP, as they're allowed due to the existing port 21 connection. IF that is the case, there's also no need to specify the port range in the ftp daemon configuration since any unused ephemeral port will do.

    If you're using a non-SPI firewall, do you actually login and then it freezes? If you cannot even login, then the problems are elsewhere since it doesn't enter PASV mode until you've authenticated (IIRC).
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

  7. #7
    Member
    Join Date
    Mar 2005
    Posts
    6

    Default

    I figured it out.

    When I enabled "FTP Services" on the firewall, it turned on "FTP Proxy Services". No indication at all thats what it was. I blindly assumed "FTP Services" meant it was opening 20/21, then I added 1025-1050. Wasnt the case...

    All is well now.

    Thanks guys,

    Matt

  8. #8
    Member
    Join Date
    Nov 2003
    Posts
    129

    Default

    Quote Originally Posted by chirpy
    Are you using an SPI firewall such as APF? If so, there's no need at all to open up ephemeral ports for PASV FTP, as they're allowed due to the existing port 21 connection. IF that is the case, there's also no need to specify the port range in the ftp daemon configuration since any unused ephemeral port will do.

    If you're using a non-SPI firewall, do you actually login and then it freezes? If you cannot even login, then the problems are elsewhere since it doesn't enter PASV mode until you've authenticated (IIRC).
    Why is it that what you say simply doesnt work in this case ??
    I have diddled with this on numerous servers off and on for MONTHS ~ my solution at best is to open 35000_36000 in apf and open them and uncomment the pureftp conf to passive connections on 35000 36000 and ftp works as it should - if I remove those ftp runs like its a cobalt raq unit from 1990 HORRIBLE connections dropped ftps and all my customers complain.....
    Chirpy yer sposed to be the cpanel god man ~ what gives why do I see in thread after thread you say we shouldnt open these but it wont work any other way ~
    Lettuce get to the beef of this at last please can you enlighten me please.

  9. #9
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    I have never had to open a hole in the APF firewall for passive FTP. IF you are having to, you may be blocking static ports that you shouldn't be (i.e. 20 and 21). Also, do make sure you're using the latest APF as recent ones have been very buggy and I have had problems on some servers with the very latest release too. In those cases I've used a different SPI firewall script also without a hole in it.
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

  10. #10
    Member Vatoloco's Avatar
    Join Date
    Jun 2004
    Posts
    100

    Default

    Quote Originally Posted by chirpy
    I have never had to open a hole in the APF firewall for passive FTP. IF you are having to, you may be blocking static ports that you shouldn't be (i.e. 20 and 21). Also, do make sure you're using the latest APF as recent ones have been very buggy and I have had problems on some servers with the very latest release too. In those cases I've used a different SPI firewall script also without a hole in it.
    What issues could arise from blocking 21? I changed the default port for ProFTP awhile ago and when I setup APF I went through /etc/apf/conf.apf and removed all instances of 21 and replaced it with my custom port. I also had to unblock 35000_36000.

Similar Threads & Tags
Similar threads

  1. Configuration of PureFTPd or ProFTPd
    By mikesta in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 02-09-2009, 11:48 PM
  2. PureFTP Passive Mode
    By janus_atw in forum cPanel and WHM Discussions
    Replies: 10
    Last Post: 01-06-2008, 12:48 AM
  3. Pure-FTPD Passive
    By kris1351 in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 04-11-2006, 11:05 AM
  4. cPanel Backup: Passive or not ?
    By alex-info in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 04-16-2004, 08:47 PM
  5. FTP Passive mode
    By minalia in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 06-11-2003, 04:37 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube