Australia/Melbourne
// back to work
// case study · Nov 04, 2024LIVE

WatchGuard FTP Passive Mode Fix

Resolved FTP connectivity issues in a secured firewall environment.

Restored stable file transfers with correct firewall rule configuration.

0
drops post-fix
1d
to resolve
A firewall configuration fix that restored stable FTP transfers across a WatchGuard-protected network where passive-mode connections had been silently failing. FTP control connections were succeeding but data transfers timed out intermittently. The firewall's default policy was blocking the dynamic high-port range that passive mode negotiates, so any client attempting passive transfers was effectively offline. Added an explicit policy for the FTP-Proxy with the correct passive port range, validated against both the client and server endpoints, and tightened the rule to the minimum scope required for the affected hosts. Verified with packet captures on both sides. → Restored stable file transfers with correct firewall rule configuration.