Can I allow passive FTP ports through Azure Firewall ?

Cyril P 26 Reputation points
2022-07-27T10:41:41.133+00:00

Hello,

I have a Windows Server on Azure with a filezilla server installed.

This VM is behind an Azure Firewall. To access the FTP server I made a DNAT rule in the Firewall to NAT traffic from the public ip on port 22022 (that I use for FTPS) to the VM.

225232-image.png

I opened all the ports for passive FTP on the VM's NSG and on the Azure Firewall but only an active connection seems to work.

What could be the issue ?

Thank you for your help.

Azure Firewall
Azure Firewall
An Azure network security service that is used to protect Azure Virtual Network resources.
656 questions
0 comments No comments
{count} votes

Accepted answer
  1. ChaitanyaNaykodi-MSFT 25,856 Reputation points Microsoft Employee
    2022-07-28T00:10:45.53+00:00

    Hello @Cyril P , Thank you for reaching out.

    Azure Firewall can support both Active and Passive FTP simultaneously. Based on the documentation here can you please validate the configuration is correct and you have configured the FTP server to accept data and control channels from different source IP addresses and DNAT from Internet Source to VNet IP port 21 is open.

    Another approach to pinpoint the exact issue will be to bypass the Azure Firewall and see if passive FTP is working as expected, sometimes VM's OS firewall can be blocking the ports, which might cause this issue as well.

    Hope this helps! Please let me know if the issue still exists. Thank you!

    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.