Re: [Proftpd-user] unstable performance connections hang/drop : aborting transfer: Data connection closed

Matus UHLAR - fantomas <[email protected]> Wed, 7 Sep 2022 13:22:11 +0200
Newsgroups gmane.network.proftpd.user
Message-ID <Yxh+4/[email protected]>
On 06.09.22 16:04, Simone Montagnani wrote:
>Maybe it's a mix of firewall and clients with proftpd , I dunno,

may be too many sessions on firewall.

> is there a way to force clients to connect in passive mode?

perhaps by disabling PORT/EPRT command but you could blokc some clients 
(iirc windows command line didn't support PASV for a long time)

however, passive mode is safer especially with SSL, because you can 
statically configure ports on your firewall to forward to FTP server without 
decrypting FTP stream


>Da: "Matus UHLAR - fantomas" <[email protected]>
>A: "proftp-user" <[email protected]>
>Inviato: Martedì, 6 settembre 2022 14:44:43
>Oggetto: Re: [Proftpd-user] unstable performance connections hang/drop : aborting transfer: Data connection closed
>
>On 06.09.22 13:39, Simone Montagnani wrote:
>>I'm writing in seek for help for an issue on one FTP server with Ubuntu 22 LTS and proftpd 1.3.7c just installed from scratch.
>>
>>This server is behind an Enterprise Firewall, and is being installed in place of an old Debian/vsftpd server , same public and private IP.
>>No problem with the old installation that worked for years.
>>
>>The problem is that FTP clients connections are unstable, after a random
>> time, and especially after some activity they just hang.
>
>this indicates firewall problem. Does this happen when you connecting
>without firewall?
>
>>I have not specified Masquerade Address at the moment, I tried just for a
>> brief time and I got the same errors.
>
>MasqueradeAddress is only needed if the firewall does not support FTP or you
>use ftps where you firewall can't see the content of control connection.
>You then need to explicitly forward set of passive ports to FTP server on
>the firewall and set those ports to PassivePorts directive.
>
>>aborting transfer: Data connection closed
>>
>>I can see in real time on the FTP server ports are opening regularly as
>> they should , at every command I make when logged in , even an "ls" open
>> all the ports in passive "style" .
>
>>I can reproduce the issue if I login and type for example "ls -l" manually
>> continuously for 20 times, I can see that all ports are opening between me
>> and the server, but after some random time is just stop with the last
>> command and stays there locked.
>>
>>I tried check firewall settings, I cannot find the problem there , FTP is
>> opening ports ok , so it's not a "blocking ftp active/passive issue", but
>> I cannot understand why everything was working fine before with the old
>> server and now it's so unstable.
>
>one of problems can be caused by using of EPSV/EPRT commands which need to
>be supported in firewall that may already support PASV/PORT.

-- 
Matus UHLAR - fantomas, [email protected] ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.
I don't have lysdexia. The Dog wouldn't allow that.


_______________________________________________
ProFTPD Users List   <[email protected]>
Unsubscribe problems?
http://www.proftpd.org/list-unsub.html