FTP TLS

Status
Not open for further replies.

Shdw

Dabbler
Joined
Jan 5, 2014
Messages
21
So my FTP works great, no problem. As soon as I enable TLS it's a fiasco.

Ports 21, 22, and 990 are all forwarded to my server. I don't think I need 990, but some documentation suggested it so I forwarded it as well just to see.

In file zilla I get "Connection refused" when using SFTP as any user and root as well. The responses are:
Status: Connecting *#*$*#*
Response: fzSftp started
Command: open "<User>@<Server>" 22
Error: Connection refused
Error: Could not connect to the server

When trying explicit FTP over TLS I get :

Status: Connecting &#*$&#
Status: Connection established, waiting for welcome message...
Response: 220 ProFTPD 1.3.4d Server (<server name> FTP Server) [::ffff:<server local IP>]
Command: AUTH TLS
Response: 234 AUTH TLS successful
Status: Initializing TLS...
Error: GnuTLS error - 110: The TLS connection was non-properly terminated.
Status: Server did not properly shut down TLS connection
Error: Could not connect to server


Similar issues with implicit FTP over TLS as well as trying to use port 21, 22, or 990 for any method of connection. The errors, however, differ, when using non default ports. What am I doing wrong? All the videos/articles I read make it sound like you forward port 22 and click a check box. No, it's not my firewall. These reports are from mac, but I get the same reports from Windows 7 (with and without firewall enabled). So what is the next step?

Thank you in advance gentlemen!

PS For any of you following my post on the bug forum...a server board with 64 bit FreeNAS worked wonders. The boot process is nearly half what it was for the bs items my desktop board was loading. And no errors during the boot, unlike the verbose failures present on the desktop board. Wish I spoke with you all sooner! <3 tyty for helping this noobie see the light.
 

Shdw

Dabbler
Joined
Jan 5, 2014
Messages
21
Oh I'm using 9.2.0 release. If you need any server outputs let me know and I'll post them. Bare in mind I am not familiar with unix commands. So if it requires a command I'll need to know it.

Also the command ssh -l <user> <local ip> in mac terminal gave the same response as above:
ssh: connect to host <ip> port 22: Connection refused

I used users I created as well as attempted to log in as root, both were denied.
 
D

dlavigne

Guest
I'm not sure whether or not setting the Minimum and Maximum Passive Ports in Advanced Mode will fix that or not.
 

Shdw

Dabbler
Joined
Jan 5, 2014
Messages
21
I'm not sure whether or not setting the Minimum and Maximum Passive Ports in Advanced Mode will fix that or not.


I'm having no luck there. I'm having all kinds of problems with this apple router and forwarding. Now I'm going to warn you, this next question may very well make you want to go kill someone or scratch your eyes out...so apologies in advance.

Can I ignore the router and run my modem and server to a switch instead? Will the server protect itself without having any hardware firewall system or will I set myself up for a DEFCON 5 situation? I was debating running the server to the switch and then letting the switch also send information to the router. All of the computers at my home would remain behind the router, except the server. Which, I suspect is the most important item to keep behind a routers firewall...?
 

cyberjock

Inactive Account
Joined
Mar 25, 2012
Messages
19,526
ABORT!! ABORT!!! KILL IT WITH FIRE! KILL IT NOW!

Your server should be behind a firewall, period. That is, unless you want to be pwned. In which case please post your IP address!
 

Shdw

Dabbler
Joined
Jan 5, 2014
Messages
21
ABORT!! ABORT!!! KILL IT WITH FIRE! KILL IT NOW!

Your server should be behind a firewall, period. That is, unless you want to be pwned. In which case please post your IP address!



I had a feeling I would get that response haha! My IP is 66.856.7.3 ;)

Ok then do you know if anyone else has had issues behind an apple airport router? I've been looking around and am simply not having much luck. By the way thank you for all your informative posts regarding using server grade hardware. Wish I'd done that research before making my purchase, but thankfully I sold my desktop stuff off for nearly 90 percent purchase cost. So not too bad a hit!
 

cyberjock

Inactive Account
Joined
Mar 25, 2012
Messages
19,526
I'm so gonna l33t haxx0r that IP later! This is your warning!

To be honest, I don't think anyone has complained about the apple routers. From what I've read they have excellent range with wifi. I have no apple experience myself, so I can't help with that. I went to pfsense over a year ago and never looked back. Sorry.
 
Status
Not open for further replies.
Top