Tools

FTP Active Mode is not working in Serv-U, getting an error: "530 Only client IP address allowed for PORT command."

This article describes an issue when the FTP Active Mode is not working in Serv-U, getting an error: "530 Only client IP address allowed for PORT command."

First published date

6/25/2020 5:28 PM

Last published date

6/25/2020 5:28 PM

Overview

In Serv-U, FTPs use multiple connections on multiple ports to perform file transfers. When used, the control channel the firewall reads is encrypted. So firewall technicians find they need to open up ranges of high inbound TCP ports for FTPS to work in passive mode. SolarWinds does not recommend the use of active mode FTPS transfers. Most clients select passive mode transfers for FTPS by default.

 

In this issue, a Xerox copier a used to connect in Serv-U, to transfer a scanned PDF via standard FTP. After Upgrading Serv-U to the latest version, this suddenly broken and getting error messages:

[21] Thu 18Jun20 09:34:59 - (262390) 530 Only client IP address allowed for PORT command.
[20] Thu 18Jun20 09:34:59 - (262390) NLST
[21] Thu 18Jun20 09:34:59 - (262390) 150 Opening ASCII mode data connection for /bin/ls.
[21] Thu 18Jun20 09:34:59 - (262390) 426 Data connection not specified.  A PORT/EPRT or PASV/EPSV command must be issued before executing this operation.


The machine does not have the capability of switching to passive mode.

Product section

Serv-U Managed File Transfer & Serv-U FTP Server

Cause

Bug in Serv-U product reported in CUST-68003.
 

Resolution

1. This error determine that customer use PORT FTP command with IP different from the origin HOST IP. To Allow this behavior customer require to explicitly allow such IP (which is different from the host IP) at the IP Access rules.
a. To add, navigate to Groups where affected user is associated or in the User's account.
b. Configure IP Access Rules, set Allow: *.*.*.* 

c. Save.

 

2. If Step 1 did not work, the workaround is to switch off the option "Block "FTP_bounce" attacks and FXP (server-to-server transfers)." The option is residing at Global->Limits&Settings->FTP Settings tab->Global Properties button -> Advanced options: