cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1311
Views
0
Helpful
1
Replies

SSL VPN Port forwarding for FTP

melcara
Level 1
Level 1

I would like to enable port forwarding for FTP. I know how to port forward for the control sessoin port 21, but will the port forwarding feature also know to handle the DATA session correctly?

1 Reply 1

Jason Gervia
Cisco Employee
Cisco Employee

Cody,


The port forwarding application has no inspection to dynamically forward ports.

For active FTP, it won't work, as the DATA connection is initiated from the server back to the client, and the port forwarding application can't handle that.

For passive FTP, the port fowarding application doesn't know what random high port was chosen by the server.

Now, if your ftp server allows you to configure which port range to use for passive ftp (which I'm not sure of, it's not a standard feature AFAIK), you could in theory then statically port forward the individual ports in that range to the server to allow communication.

--Jason

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: