LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 01-11-2016, 03:57 PM   #1
mpdmlnz
LQ Newbie
 
Registered: Jan 2016
Posts: 2

Rep: Reputation: Disabled
Singular vsftpd active mode failure


I don't think anyone else has asked this, but please call me el stupido if I've missed it.

We have a vsftpd server that, for a specific client, is not initiating active mode when data needs to be exchanged. When I say specific client I mean a particular system (let's call it X), as I cannot replicate the issue when I use their same login credentials from multiple other systems.

From a network perspective, if I run tcpdump there is no sign of the SYN packet from ftp-data when communicating with system X. For the other connections that do work I see the expected bi-directional flow in to port 21 and out on port 20.

Has anyone ever seen this before? System X is an IBM mainframe, but the client is swearing black and blue "Change freeze!" (it stopped working on 2016-01-05, so Christmas) at suggestions that it's something on their side.
As I say, it was working and then it wasn't. On our server side it's an unchanged system since last year, file deliveries had been fine for weeks.

I'm lost. The session logs look entirely normal, and the setup and send from previous successful transfers appear identical to the now-failing ones. Any suggestions on where to look? Things to try?

Please don't suggest passive mode, as it will be weeks before the client and their big, blue IT outsource provider can make it happen.

Cheers
 
Old 01-13-2016, 03:03 AM   #2
Guttorm
Senior Member
 
Registered: Dec 2003
Location: Trondheim, Norway
Distribution: Debian and Ubuntu
Posts: 1,453

Rep: Reputation: 447Reputation: 447Reputation: 447Reputation: 447Reputation: 447
I would test active FTP from a client behind NAT. If you try from some typical network with 192.168.*.* or 10.*.*.* with all outgoing connections open and no incoming allowed, active FTP is tricky.

It can be solved using a firewall/ftp-proxy between the client and the server. Some firewalls have a setting for this. It can be called "FTP helper" or similar.

I searched, and found this:

http://www.devops-blog.net/iptables/...active-passive
 
1 members found this post helpful.
Old 01-20-2016, 06:03 PM   #3
mpdmlnz
LQ Newbie
 
Registered: Jan 2016
Posts: 2

Original Poster
Rep: Reputation: Disabled
In the end I just installed proftpd. Worked right out of the gate, no configuration required other than SELinux booleans. With zero diagnostic assistance available from the outsourced supplier ("We're in change freeze" was the response to any suggestion it might have been their end) and other processes held up by the lack of data, trying to do more trouble-shooting just wasn't happening.

I did ponder the NAT one but the time required to set up a test was more than I cared to spend. The client's system is definitely being NAT'd, but it has been behind NAT the entire time.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
VSFTPD question...active/passive mode lapzlinux Linux - Networking 4 08-06-2011 01:54 AM
vsftpd - problem with active connection roy-arne Linux - Server 5 01-19-2009 11:45 PM
view active vsftpd users TwistedP Linux - Newbie 1 03-31-2008 05:12 PM
Active FTP problem with vsftpd snowx Linux - Server 8 10-27-2007 08:18 AM
VSFTPD With Active Directory Authentication bigchump Linux - Software 1 07-07-2006 02:36 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 08:39 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration