
Originally Posted by
chirpy
Are you using an SPI firewall such as APF? If so, there's no need at all to open up ephemeral ports for PASV FTP, as they're allowed due to the existing port 21 connection. IF that is the case, there's also no need to specify the port range in the ftp daemon configuration since any unused ephemeral port will do.
If you're using a non-SPI firewall, do you actually login and then it freezes? If you cannot even login, then the problems are elsewhere since it doesn't enter PASV mode until you've authenticated (IIRC).