OS X Server FTP serverFTP server that logs failed password attemptsFTP server (open source?) with paid supportWindows Server 2008 r2 FTP blocking outside connectionsIIS FTP Server works locally, but cannot connect from remotePassive FTP on Windows Server 2008 R2 using the IIS7 FTP-ServerConfigure Pure-FTP for Implicit FTPSFTP Theory - Manage firewall on the client's sidePassive FTP connecton not working on Windows Server 2012Only Cannot Access FTP Server from Outer Sub-net (error 425)Can connect to FTP on Windows Server 2016 locally but not remotely
How do I gain the trust of other PCs?
How can I maintain game balance while allowing my player to craft genuinely useful items?
TiKZ won't graph 1/sqrt(x)
How can this shape perfectly cover a cube?
Should I email my professor to clear up a (possibly very irrelevant) awkward misunderstanding?
Huge Heap Table and table compression on SQL Server 2016
Why can't I craft scaffolding in Minecraft 1.14?
Why is gun control associated with the socially liberal Democratic party?
How did space travel spread through the galaxy?
what is "dot" sign in the •NO?
How can the US president give an order to a civilian?
Is there a term for someone whose preferred policies are a mix of Left and Right?
Is swap gate equivalent to just exchanging the wire of the two qubits?
Numerical second order differentiation
How to make a villain when your PCs are villains?
What is this plant I saw for sale at a Romanian farmer's market?
2 Managed Packages in 1 Dev Org
Have Steve Rogers (Captain America) and a young Erik Lehnsherr (Magneto) interacted during WWII?
How did Avada Kedavra get its name?
What is the context for Napoleon's quote "[the Austrians] did not know the value of five minutes"?
How do I run a script as sudo at boot time on Ubuntu 18.04 Server?
How to know whether to write accidentals as sharps or flats?
How do I become a better writer when I hate reading?
How to prevent cables getting intertwined
OS X Server FTP server
FTP server that logs failed password attemptsFTP server (open source?) with paid supportWindows Server 2008 r2 FTP blocking outside connectionsIIS FTP Server works locally, but cannot connect from remotePassive FTP on Windows Server 2008 R2 using the IIS7 FTP-ServerConfigure Pure-FTP for Implicit FTPSFTP Theory - Manage firewall on the client's sidePassive FTP connecton not working on Windows Server 2012Only Cannot Access FTP Server from Outer Sub-net (error 425)Can connect to FTP on Windows Server 2016 locally but not remotely
.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty height:90px;width:728px;box-sizing:border-box;
I'm running an OS X Server with the following services turned on: Web, MySQL, DNS, AFP, Firewall. I'd like to also start FTP, and I did this, but I can't seem to make it work properly. I'm sure there is a way, but I can't find a way to make it work for me.
What I've done so far:
- activated the FTP service
- opened port 20-21 in the Firewall
- forwarded ports 20-21 from the router to the Server
I use Coda to connect to my FTPs (as I do a lot of web development). When I type in this server's address + credentials it tries to connect for about 2-3 minutes before actually succeeding, and when it does it lists the following directories: "Public" (with a shortcut icon), "Users" (with a shortcut icon) and a file named "???" which it tries to open right away. Doing [cmd + k] in Finder also results in a 2-3 minutes waiting.
Also, I have no idea where to create new users for the FTP (just for the FTP) and how to give them permissions to specific directories (without useless ones like "Users" or "Public").
I've come to the conclusion that the built-in FTP server might not be the best option for me, but I have no idea what I should try. Using a separate app is not the ideal scenario for me as I'm trying to avoid keeping extra apps open on my server.
mac-osx ftp mac-osx-server
migrated from stackoverflow.com Apr 25 '11 at 8:49
This question came from our site for professional and enthusiast programmers.
add a comment |
I'm running an OS X Server with the following services turned on: Web, MySQL, DNS, AFP, Firewall. I'd like to also start FTP, and I did this, but I can't seem to make it work properly. I'm sure there is a way, but I can't find a way to make it work for me.
What I've done so far:
- activated the FTP service
- opened port 20-21 in the Firewall
- forwarded ports 20-21 from the router to the Server
I use Coda to connect to my FTPs (as I do a lot of web development). When I type in this server's address + credentials it tries to connect for about 2-3 minutes before actually succeeding, and when it does it lists the following directories: "Public" (with a shortcut icon), "Users" (with a shortcut icon) and a file named "???" which it tries to open right away. Doing [cmd + k] in Finder also results in a 2-3 minutes waiting.
Also, I have no idea where to create new users for the FTP (just for the FTP) and how to give them permissions to specific directories (without useless ones like "Users" or "Public").
I've come to the conclusion that the built-in FTP server might not be the best option for me, but I have no idea what I should try. Using a separate app is not the ideal scenario for me as I'm trying to avoid keeping extra apps open on my server.
mac-osx ftp mac-osx-server
migrated from stackoverflow.com Apr 25 '11 at 8:49
This question came from our site for professional and enthusiast programmers.
Don't use FTP except for anonymous downloads. It is insecure!
– gavinb
Apr 25 '11 at 8:00
add a comment |
I'm running an OS X Server with the following services turned on: Web, MySQL, DNS, AFP, Firewall. I'd like to also start FTP, and I did this, but I can't seem to make it work properly. I'm sure there is a way, but I can't find a way to make it work for me.
What I've done so far:
- activated the FTP service
- opened port 20-21 in the Firewall
- forwarded ports 20-21 from the router to the Server
I use Coda to connect to my FTPs (as I do a lot of web development). When I type in this server's address + credentials it tries to connect for about 2-3 minutes before actually succeeding, and when it does it lists the following directories: "Public" (with a shortcut icon), "Users" (with a shortcut icon) and a file named "???" which it tries to open right away. Doing [cmd + k] in Finder also results in a 2-3 minutes waiting.
Also, I have no idea where to create new users for the FTP (just for the FTP) and how to give them permissions to specific directories (without useless ones like "Users" or "Public").
I've come to the conclusion that the built-in FTP server might not be the best option for me, but I have no idea what I should try. Using a separate app is not the ideal scenario for me as I'm trying to avoid keeping extra apps open on my server.
mac-osx ftp mac-osx-server
I'm running an OS X Server with the following services turned on: Web, MySQL, DNS, AFP, Firewall. I'd like to also start FTP, and I did this, but I can't seem to make it work properly. I'm sure there is a way, but I can't find a way to make it work for me.
What I've done so far:
- activated the FTP service
- opened port 20-21 in the Firewall
- forwarded ports 20-21 from the router to the Server
I use Coda to connect to my FTPs (as I do a lot of web development). When I type in this server's address + credentials it tries to connect for about 2-3 minutes before actually succeeding, and when it does it lists the following directories: "Public" (with a shortcut icon), "Users" (with a shortcut icon) and a file named "???" which it tries to open right away. Doing [cmd + k] in Finder also results in a 2-3 minutes waiting.
Also, I have no idea where to create new users for the FTP (just for the FTP) and how to give them permissions to specific directories (without useless ones like "Users" or "Public").
I've come to the conclusion that the built-in FTP server might not be the best option for me, but I have no idea what I should try. Using a separate app is not the ideal scenario for me as I'm trying to avoid keeping extra apps open on my server.
mac-osx ftp mac-osx-server
mac-osx ftp mac-osx-server
asked Apr 25 '11 at 7:49
Sorin Buturugeanu
migrated from stackoverflow.com Apr 25 '11 at 8:49
This question came from our site for professional and enthusiast programmers.
migrated from stackoverflow.com Apr 25 '11 at 8:49
This question came from our site for professional and enthusiast programmers.
Don't use FTP except for anonymous downloads. It is insecure!
– gavinb
Apr 25 '11 at 8:00
add a comment |
Don't use FTP except for anonymous downloads. It is insecure!
– gavinb
Apr 25 '11 at 8:00
Don't use FTP except for anonymous downloads. It is insecure!
– gavinb
Apr 25 '11 at 8:00
Don't use FTP except for anonymous downloads. It is insecure!
– gavinb
Apr 25 '11 at 8:00
add a comment |
3 Answers
3
active
oldest
votes
FTP is definitelly service which you don't want to run. If you really need it, install ProFTPd instead of built-in wuftpd service. It allows to have separate account from the other OSX services, virtual hosts etc
add a comment |
I would recommend using SFTP (SSH File Transfer Protocol). FTP is a very insecure protocol. Coda supports SFTP, and if you have SSH set up, you already have SFTP set up in most cases
add a comment |
I'll add my votes to everyone else's to use something better than FTP. In addition to its security problems (plaintext passwords!), it has a lot of trouble with firewalls and network address translating (NAT) routers. In general, active-mode FTP will work with NAT and/or firewalls on the server end, and passive-mode FTP will work with NAT and/or firewalls on the client side, and if you have NAT and/or firewalls on both ends (very common these days) FTP probably won't work in any mode.
Actually, that's a bit of an overstatement, since some NAT routers are smart enough to rewrite FTP connections on the fly to avoid problems (naturally, this feature tends not to be documented anywhere, so you can't tell if your router does without trying it), and it's usually possible to jigger a server-side packet-filtering firewall to keep it from causing trouble...
To rig the server firewall, see Apple's KB #HT4000 for instructions to set the server's passive port range and set the firewall to let those ports through (note: the suggested port range is rather large. It's entirely reasonable to use a smaller range, just as long as the FTP service and firewall are configured for the same range).
If your router doesn't support FTP rewriting, you might be able to fake it with some additional configuration: configure your router to port-forward the entire passive port range to the server (you'll definitely want to use a smaller port range if you're doing this). Then figure out your public IP address (the address on the WAN side of your router), and the range of addresses on your internal network (in CIDR notation), and add appropriate "passive address" directives to /Library/FTPServer/Configuration/ftpaccess. For instance, if your router's public IP was 203.0.113.117, internal range is 192.168.1.0/24, and the server's internal address was 192.168.1.10, it'd look like this:
passive address 192.168.1.10 192.168.1.0/24
passive address 203.0.113.117 0.0.0.0/0
Finally, if you want to allow uploads to the FTP server, you'll need to add "upload" directives for the folders you want to allow uploads to (by default, they're only allowed to /Library/FTPServer/FTPRoot/uploads, which doesn't exist unless you create it).
BTW, while the implementation details (e.g. ftpaccess directives) above are specific to the wuftpd server Apple uses, the NAT and firewall issues (and possible solutions) are going to be the same for any other FTP server you might want to use. Basically, the FTP protocol itself is not designed to work with modern network setups, and there's not much the implementation can to do fix/mitigate this.
add a comment |
Your Answer
StackExchange.ready(function()
var channelOptions =
tags: "".split(" "),
id: "2"
;
initTagRenderer("".split(" "), "".split(" "), channelOptions);
StackExchange.using("externalEditor", function()
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled)
StackExchange.using("snippets", function()
createEditor();
);
else
createEditor();
);
function createEditor()
StackExchange.prepareEditor(
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader:
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
,
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
);
);
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f263059%2fos-x-server-ftp-server%23new-answer', 'question_page');
);
Post as a guest
Required, but never shown
3 Answers
3
active
oldest
votes
3 Answers
3
active
oldest
votes
active
oldest
votes
active
oldest
votes
FTP is definitelly service which you don't want to run. If you really need it, install ProFTPd instead of built-in wuftpd service. It allows to have separate account from the other OSX services, virtual hosts etc
add a comment |
FTP is definitelly service which you don't want to run. If you really need it, install ProFTPd instead of built-in wuftpd service. It allows to have separate account from the other OSX services, virtual hosts etc
add a comment |
FTP is definitelly service which you don't want to run. If you really need it, install ProFTPd instead of built-in wuftpd service. It allows to have separate account from the other OSX services, virtual hosts etc
FTP is definitelly service which you don't want to run. If you really need it, install ProFTPd instead of built-in wuftpd service. It allows to have separate account from the other OSX services, virtual hosts etc
answered Apr 25 '11 at 10:36
BobCBobC
41238
41238
add a comment |
add a comment |
I would recommend using SFTP (SSH File Transfer Protocol). FTP is a very insecure protocol. Coda supports SFTP, and if you have SSH set up, you already have SFTP set up in most cases
add a comment |
I would recommend using SFTP (SSH File Transfer Protocol). FTP is a very insecure protocol. Coda supports SFTP, and if you have SSH set up, you already have SFTP set up in most cases
add a comment |
I would recommend using SFTP (SSH File Transfer Protocol). FTP is a very insecure protocol. Coda supports SFTP, and if you have SSH set up, you already have SFTP set up in most cases
I would recommend using SFTP (SSH File Transfer Protocol). FTP is a very insecure protocol. Coda supports SFTP, and if you have SSH set up, you already have SFTP set up in most cases
answered Apr 25 '11 at 13:00
Dan McClainDan McClain
5,91911724
5,91911724
add a comment |
add a comment |
I'll add my votes to everyone else's to use something better than FTP. In addition to its security problems (plaintext passwords!), it has a lot of trouble with firewalls and network address translating (NAT) routers. In general, active-mode FTP will work with NAT and/or firewalls on the server end, and passive-mode FTP will work with NAT and/or firewalls on the client side, and if you have NAT and/or firewalls on both ends (very common these days) FTP probably won't work in any mode.
Actually, that's a bit of an overstatement, since some NAT routers are smart enough to rewrite FTP connections on the fly to avoid problems (naturally, this feature tends not to be documented anywhere, so you can't tell if your router does without trying it), and it's usually possible to jigger a server-side packet-filtering firewall to keep it from causing trouble...
To rig the server firewall, see Apple's KB #HT4000 for instructions to set the server's passive port range and set the firewall to let those ports through (note: the suggested port range is rather large. It's entirely reasonable to use a smaller range, just as long as the FTP service and firewall are configured for the same range).
If your router doesn't support FTP rewriting, you might be able to fake it with some additional configuration: configure your router to port-forward the entire passive port range to the server (you'll definitely want to use a smaller port range if you're doing this). Then figure out your public IP address (the address on the WAN side of your router), and the range of addresses on your internal network (in CIDR notation), and add appropriate "passive address" directives to /Library/FTPServer/Configuration/ftpaccess. For instance, if your router's public IP was 203.0.113.117, internal range is 192.168.1.0/24, and the server's internal address was 192.168.1.10, it'd look like this:
passive address 192.168.1.10 192.168.1.0/24
passive address 203.0.113.117 0.0.0.0/0
Finally, if you want to allow uploads to the FTP server, you'll need to add "upload" directives for the folders you want to allow uploads to (by default, they're only allowed to /Library/FTPServer/FTPRoot/uploads, which doesn't exist unless you create it).
BTW, while the implementation details (e.g. ftpaccess directives) above are specific to the wuftpd server Apple uses, the NAT and firewall issues (and possible solutions) are going to be the same for any other FTP server you might want to use. Basically, the FTP protocol itself is not designed to work with modern network setups, and there's not much the implementation can to do fix/mitigate this.
add a comment |
I'll add my votes to everyone else's to use something better than FTP. In addition to its security problems (plaintext passwords!), it has a lot of trouble with firewalls and network address translating (NAT) routers. In general, active-mode FTP will work with NAT and/or firewalls on the server end, and passive-mode FTP will work with NAT and/or firewalls on the client side, and if you have NAT and/or firewalls on both ends (very common these days) FTP probably won't work in any mode.
Actually, that's a bit of an overstatement, since some NAT routers are smart enough to rewrite FTP connections on the fly to avoid problems (naturally, this feature tends not to be documented anywhere, so you can't tell if your router does without trying it), and it's usually possible to jigger a server-side packet-filtering firewall to keep it from causing trouble...
To rig the server firewall, see Apple's KB #HT4000 for instructions to set the server's passive port range and set the firewall to let those ports through (note: the suggested port range is rather large. It's entirely reasonable to use a smaller range, just as long as the FTP service and firewall are configured for the same range).
If your router doesn't support FTP rewriting, you might be able to fake it with some additional configuration: configure your router to port-forward the entire passive port range to the server (you'll definitely want to use a smaller port range if you're doing this). Then figure out your public IP address (the address on the WAN side of your router), and the range of addresses on your internal network (in CIDR notation), and add appropriate "passive address" directives to /Library/FTPServer/Configuration/ftpaccess. For instance, if your router's public IP was 203.0.113.117, internal range is 192.168.1.0/24, and the server's internal address was 192.168.1.10, it'd look like this:
passive address 192.168.1.10 192.168.1.0/24
passive address 203.0.113.117 0.0.0.0/0
Finally, if you want to allow uploads to the FTP server, you'll need to add "upload" directives for the folders you want to allow uploads to (by default, they're only allowed to /Library/FTPServer/FTPRoot/uploads, which doesn't exist unless you create it).
BTW, while the implementation details (e.g. ftpaccess directives) above are specific to the wuftpd server Apple uses, the NAT and firewall issues (and possible solutions) are going to be the same for any other FTP server you might want to use. Basically, the FTP protocol itself is not designed to work with modern network setups, and there's not much the implementation can to do fix/mitigate this.
add a comment |
I'll add my votes to everyone else's to use something better than FTP. In addition to its security problems (plaintext passwords!), it has a lot of trouble with firewalls and network address translating (NAT) routers. In general, active-mode FTP will work with NAT and/or firewalls on the server end, and passive-mode FTP will work with NAT and/or firewalls on the client side, and if you have NAT and/or firewalls on both ends (very common these days) FTP probably won't work in any mode.
Actually, that's a bit of an overstatement, since some NAT routers are smart enough to rewrite FTP connections on the fly to avoid problems (naturally, this feature tends not to be documented anywhere, so you can't tell if your router does without trying it), and it's usually possible to jigger a server-side packet-filtering firewall to keep it from causing trouble...
To rig the server firewall, see Apple's KB #HT4000 for instructions to set the server's passive port range and set the firewall to let those ports through (note: the suggested port range is rather large. It's entirely reasonable to use a smaller range, just as long as the FTP service and firewall are configured for the same range).
If your router doesn't support FTP rewriting, you might be able to fake it with some additional configuration: configure your router to port-forward the entire passive port range to the server (you'll definitely want to use a smaller port range if you're doing this). Then figure out your public IP address (the address on the WAN side of your router), and the range of addresses on your internal network (in CIDR notation), and add appropriate "passive address" directives to /Library/FTPServer/Configuration/ftpaccess. For instance, if your router's public IP was 203.0.113.117, internal range is 192.168.1.0/24, and the server's internal address was 192.168.1.10, it'd look like this:
passive address 192.168.1.10 192.168.1.0/24
passive address 203.0.113.117 0.0.0.0/0
Finally, if you want to allow uploads to the FTP server, you'll need to add "upload" directives for the folders you want to allow uploads to (by default, they're only allowed to /Library/FTPServer/FTPRoot/uploads, which doesn't exist unless you create it).
BTW, while the implementation details (e.g. ftpaccess directives) above are specific to the wuftpd server Apple uses, the NAT and firewall issues (and possible solutions) are going to be the same for any other FTP server you might want to use. Basically, the FTP protocol itself is not designed to work with modern network setups, and there's not much the implementation can to do fix/mitigate this.
I'll add my votes to everyone else's to use something better than FTP. In addition to its security problems (plaintext passwords!), it has a lot of trouble with firewalls and network address translating (NAT) routers. In general, active-mode FTP will work with NAT and/or firewalls on the server end, and passive-mode FTP will work with NAT and/or firewalls on the client side, and if you have NAT and/or firewalls on both ends (very common these days) FTP probably won't work in any mode.
Actually, that's a bit of an overstatement, since some NAT routers are smart enough to rewrite FTP connections on the fly to avoid problems (naturally, this feature tends not to be documented anywhere, so you can't tell if your router does without trying it), and it's usually possible to jigger a server-side packet-filtering firewall to keep it from causing trouble...
To rig the server firewall, see Apple's KB #HT4000 for instructions to set the server's passive port range and set the firewall to let those ports through (note: the suggested port range is rather large. It's entirely reasonable to use a smaller range, just as long as the FTP service and firewall are configured for the same range).
If your router doesn't support FTP rewriting, you might be able to fake it with some additional configuration: configure your router to port-forward the entire passive port range to the server (you'll definitely want to use a smaller port range if you're doing this). Then figure out your public IP address (the address on the WAN side of your router), and the range of addresses on your internal network (in CIDR notation), and add appropriate "passive address" directives to /Library/FTPServer/Configuration/ftpaccess. For instance, if your router's public IP was 203.0.113.117, internal range is 192.168.1.0/24, and the server's internal address was 192.168.1.10, it'd look like this:
passive address 192.168.1.10 192.168.1.0/24
passive address 203.0.113.117 0.0.0.0/0
Finally, if you want to allow uploads to the FTP server, you'll need to add "upload" directives for the folders you want to allow uploads to (by default, they're only allowed to /Library/FTPServer/FTPRoot/uploads, which doesn't exist unless you create it).
BTW, while the implementation details (e.g. ftpaccess directives) above are specific to the wuftpd server Apple uses, the NAT and firewall issues (and possible solutions) are going to be the same for any other FTP server you might want to use. Basically, the FTP protocol itself is not designed to work with modern network setups, and there's not much the implementation can to do fix/mitigate this.
answered Apr 25 '11 at 17:28
Gordon DavissonGordon Davisson
9,32622127
9,32622127
add a comment |
add a comment |
Thanks for contributing an answer to Server Fault!
- Please be sure to answer the question. Provide details and share your research!
But avoid …
- Asking for help, clarification, or responding to other answers.
- Making statements based on opinion; back them up with references or personal experience.
To learn more, see our tips on writing great answers.
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f263059%2fos-x-server-ftp-server%23new-answer', 'question_page');
);
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Don't use FTP except for anonymous downloads. It is insecure!
– gavinb
Apr 25 '11 at 8:00