06-20-2003 12:17 PM - edited 02-20-2020 10:48 PM
We have been running into the problem with vendors that we initiate FTP sessions to. We do not allow inbound access and passive connections will not work with their FTP server. They use Microsoft FTP servers and they have port security setup on them. We have tried the ftp Quote command but it still does not work. They are willing to work with us but do not know what changes would allow us to make passive connections without compromising their security.
06-25-2003 09:47 AM
Generally speaking, the FTP server and its network is more secure with Active FTP because only one port needs to be opened inbound to the FTP server. (21) Passive requires some range of upper ports to be opened. (1024-5000 by default for IIS)
Microsoft IIS/FTP supports Active FTP. What firewall is on your side?
06-26-2003 10:16 AM
I have a Cisco pix 520.
06-26-2003 04:45 PM
Since you have a Pix 520, the fixup for FTP will take care of the port negotiation on your side. I suggest you have them enable Active FTP to provide the highest security on their side while providing the functionality for your FTP clients.
What kind of firewall is on their side?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide