Community discussions

MUM Europe 2020
 
dmitris
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 80
Joined: Mon Oct 09, 2017 1:08 pm

FTP NAT helper not working with FTPes?!

Thu Jan 16, 2020 8:30 pm

Hello,

I'm just curios, does Mikrotik ftp nat helper working when enryption is used and FTP configured to work in passv mode ?

At this moment i can reach server only when passv ports are dst-nated to host under ip>firewal>nat settings


BR,
Dmitris
 
Sob
Forum Guru
Forum Guru
Posts: 5031
Joined: Mon Apr 20, 2009 9:11 pm

Re: FTP NAT helper not working with FTPes?!

Thu Jan 16, 2020 9:10 pm

How could it? It works by examining packets of control connection, reading commands and responses, changing addresses and ports in them, using that info to recognize data connections. If control connection is enrypted, it can't do any of that.
People who quote full posts should be spanked with ethernet cable. Some exceptions for multi-topic threads may apply. Not intended as incentive for masochists.
 
dmitris
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 80
Joined: Mon Oct 09, 2017 1:08 pm

Re: FTP NAT helper not working with FTPes?!

Fri Jan 17, 2020 9:05 pm

Thank you Sob!

It's all what i want to know...


btw,
Juniper devices have ftps-extension alg which does work with such type of traffic and this is why i was so curious about mikrotik ftp helper.
https://kb.juniper.net/InfoCenter/index ... id=KB19444
 
Sob
Forum Guru
Forum Guru
Posts: 5031
Joined: Mon Apr 20, 2009 9:11 pm

Re: FTP NAT helper not working with FTPes?!

Fri Jan 17, 2020 11:51 pm

No, linked page is about something else. It says that previously, encrypted connections were blocked, because the helper was apparently too nosy and didn't like AUTH command. Now it doesn't do that. And it seems to be meant only for client use, because it says that only passive connections work (they are simple outgoing connections, no special treatment is necessary for them). But active ones (where server connects to client) still don't. And can't because for that it would have to be possible to read control connection.
People who quote full posts should be spanked with ethernet cable. Some exceptions for multi-topic threads may apply. Not intended as incentive for masochists.

Who is online

Users browsing this forum: anav, Bing [Bot], Google [Bot] and 46 guests