SRX

last person joined: 4 days ago 

Ask questions and share experiences about the SRX Series, vSRX, and cSRX.
  • 1.  FTP passive mode difficulties

    Posted 09-27-2015 12:17
      |   view attached

    Hi again guys!

     

    I have some problems with passive FTP which I cannot understand

     

    I've tested with port 21 and default application junos-ftp and it works just fine but when changing listening port of the server and creating custom application with application-protocol ftp it does not work.

     

    custom control port is 45699 and the internal ip it dnated to is 10.0.0.2(which is actually another router, which shouldn't have anything to do with the problem I hope)

     

    when connecting to 45699 the filezilla client asks for username/password, connects but does not get listing saying "Server sent passive reply with unroutable address, using server address instead" and it hangs with "LIST", then it retries...

     

    with port 21 it works fine

     

    I captured session flow coming from outside IP under security traceoptions but not sure how to decipher the output.(files attached)

     

    I've searched the net but couldn't find similar scenarios.

     

    Could it be something with ALG not liking another ftp ports?

     

    server works fine on LAN

     

    Not sure where to begin troubleshooting now, please advise guys.Smiley Sad

     

    Thanks in advance

    Attachment(s)

    zip
    logs.zip   32 KB 1 version


  • 2.  RE: FTP passive mode difficulties

     
    Posted 09-27-2015 12:52

    Hello,

     

    Does your custom application contains following line?

     

    set applications application <your custom application name> application-protocol ftp

     

    If not, can you add it & test?

     

    Regards,

     

    Rushi



  • 3.  RE: FTP passive mode difficulties
    Best Answer

    Posted 09-28-2015 01:35

    Hi,

     

    as stated in my first post I had created custom application with "application-protocol ftp".

     

    regards.