<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: My Sonicwall won&#8217;t let me FTP! Error: FTP: PASV response bounce attack dropped</title>
	<atom:link href="http://www.asktheadmin.com/2008/07/my-sonicwall-wont-let-me-ftp-error-ftp-pasv-response-bounce-attack-dropped.html/feed" rel="self" type="application/rss+xml" />
	<link>http://www.asktheadmin.com/2008/07/my-sonicwall-wont-let-me-ftp-error-ftp-pasv-response-bounce-attack-dropped.html</link>
	<description></description>
	<lastBuildDate>Fri, 03 Feb 2012 06:08:50 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
	<item>
		<title>By: Frank</title>
		<link>http://www.asktheadmin.com/2008/07/my-sonicwall-wont-let-me-ftp-error-ftp-pasv-response-bounce-attack-dropped.html/comment-page-1#comment-13723</link>
		<dc:creator>Frank</dc:creator>
		<pubDate>Fri, 13 Aug 2010 15:16:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.asktheadmin.com/?p=1788#comment-13723</guid>
		<description>There are definitely better options than FTP out there - online file transfer services like Filesdirect (my personal fave) are easier to use and more secure.</description>
		<content:encoded><![CDATA[<p>There are definitely better options than FTP out there &#8211; online file transfer services like Filesdirect (my personal fave) are easier to use and more secure.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brian</title>
		<link>http://www.asktheadmin.com/2008/07/my-sonicwall-wont-let-me-ftp-error-ftp-pasv-response-bounce-attack-dropped.html/comment-page-1#comment-13719</link>
		<dc:creator>Brian</dc:creator>
		<pubDate>Wed, 11 Aug 2010 21:00:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.asktheadmin.com/?p=1788#comment-13719</guid>
		<description>Thank you for this information.  I set an FTP site for a project on an older, smaller network with a SonicWall.  I then had a handful of people trying to get the large files and all were running into this problem.  I looked through my SonicWall&#039;s log and saw the errors.  It was driving me batty!

I went through all the settings everywhere to get the Passive mode to work (easier than explaining active mode setup to non-tech users spread out geographically).  In a last ditch effort I Googled my error and came across this post.

THANK you!  You&#039;ve saved me and the users from the frustration of changing course to one of the other perfectly valid options listed by other commenters.</description>
		<content:encoded><![CDATA[<p>Thank you for this information.  I set an FTP site for a project on an older, smaller network with a SonicWall.  I then had a handful of people trying to get the large files and all were running into this problem.  I looked through my SonicWall&#8217;s log and saw the errors.  It was driving me batty!</p>
<p>I went through all the settings everywhere to get the Passive mode to work (easier than explaining active mode setup to non-tech users spread out geographically).  In a last ditch effort I Googled my error and came across this post.</p>
<p>THANK you!  You&#8217;ve saved me and the users from the frustration of changing course to one of the other perfectly valid options listed by other commenters.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Karl L. Gechlik &#124; AskTheAdmin.com</title>
		<link>http://www.asktheadmin.com/2008/07/my-sonicwall-wont-let-me-ftp-error-ftp-pasv-response-bounce-attack-dropped.html/comment-page-1#comment-9530</link>
		<dc:creator>Karl L. Gechlik &#124; AskTheAdmin.com</dc:creator>
		<pubDate>Wed, 04 Feb 2009 12:58:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.asktheadmin.com/?p=1788#comment-9530</guid>
		<description>After looking into active mode ftp - it is a great suggestion.. Thanks Clay.</description>
		<content:encoded><![CDATA[<p>After looking into active mode ftp &#8211; it is a great suggestion.. Thanks Clay.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Clay Maney</title>
		<link>http://www.asktheadmin.com/2008/07/my-sonicwall-wont-let-me-ftp-error-ftp-pasv-response-bounce-attack-dropped.html/comment-page-1#comment-9524</link>
		<dc:creator>Clay Maney</dc:creator>
		<pubDate>Tue, 03 Feb 2009 02:05:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.asktheadmin.com/?p=1788#comment-9524</guid>
		<description>The link is still bad, but the biggest reason to limit the use of FTP is because, most of the time, it is clear text.  That means your username and password are sent unencrypted across the Internet.  When possible, use FTP w/ SSL or SCP/SFTP to make sure your transactions are secure.

As for this post, I personally don&#039;t like SonicWall firewalls (slow, need reboots, etc.).  But, with that being said, by disabling bounce attack protection in a dedicated appliance, you&#039;re relying on an operating system that was originally created for easy file-sharing (Windows) to do the security job... this is not good practice.  

Why not just switch to active mode ftp?</description>
		<content:encoded><![CDATA[<p>The link is still bad, but the biggest reason to limit the use of FTP is because, most of the time, it is clear text.  That means your username and password are sent unencrypted across the Internet.  When possible, use FTP w/ SSL or SCP/SFTP to make sure your transactions are secure.</p>
<p>As for this post, I personally don&#8217;t like SonicWall firewalls (slow, need reboots, etc.).  But, with that being said, by disabling bounce attack protection in a dedicated appliance, you&#8217;re relying on an operating system that was originally created for easy file-sharing (Windows) to do the security job&#8230; this is not good practice.  </p>
<p>Why not just switch to active mode ftp?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ray P.</title>
		<link>http://www.asktheadmin.com/2008/07/my-sonicwall-wont-let-me-ftp-error-ftp-pasv-response-bounce-attack-dropped.html/comment-page-1#comment-9236</link>
		<dc:creator>Ray P.</dc:creator>
		<pubDate>Mon, 22 Dec 2008 17:10:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.asktheadmin.com/?p=1788#comment-9236</guid>
		<description>Thank you for this information - it helped me troubleshoot a remote site for several users on a construction project we&#039;re working on.</description>
		<content:encoded><![CDATA[<p>Thank you for this information &#8211; it helped me troubleshoot a remote site for several users on a construction project we&#8217;re working on.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: No to all? The hidden option on Windows XP. &#124; Unit1</title>
		<link>http://www.asktheadmin.com/2008/07/my-sonicwall-wont-let-me-ftp-error-ftp-pasv-response-bounce-attack-dropped.html/comment-page-1#comment-8834</link>
		<dc:creator>No to all? The hidden option on Windows XP. &#124; Unit1</dc:creator>
		<pubDate>Sat, 01 Nov 2008 11:38:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.asktheadmin.com/?p=1788#comment-8834</guid>
		<description>[...] My Sonicwall won&#8217;t let me FTP! Error: FTP: PASV response bounce attack dropped [...]</description>
		<content:encoded><![CDATA[<p>[...] My Sonicwall won&#8217;t let me FTP! Error: FTP: PASV response bounce attack dropped [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alex</title>
		<link>http://www.asktheadmin.com/2008/07/my-sonicwall-wont-let-me-ftp-error-ftp-pasv-response-bounce-attack-dropped.html/comment-page-1#comment-7802</link>
		<dc:creator>Alex</dc:creator>
		<pubDate>Wed, 13 Aug 2008 23:22:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.asktheadmin.com/?p=1788#comment-7802</guid>
		<description>I found your site on technorati and read a few of your other posts. Keep up the good work. I just added your RSS feed to my Google News Reader. Looking forward to reading more from you down the road!</description>
		<content:encoded><![CDATA[<p>I found your site on technorati and read a few of your other posts. Keep up the good work. I just added your RSS feed to my Google News Reader. Looking forward to reading more from you down the road!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: JoeG</title>
		<link>http://www.asktheadmin.com/2008/07/my-sonicwall-wont-let-me-ftp-error-ftp-pasv-response-bounce-attack-dropped.html/comment-page-1#comment-7484</link>
		<dc:creator>JoeG</dc:creator>
		<pubDate>Thu, 31 Jul 2008 15:06:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.asktheadmin.com/?p=1788#comment-7484</guid>
		<description>I use FTP for all kinds of stuff, the number one is that I do not allow email attachments over 10MB. If someone needs to get a file to us or from us that is larger than 10MB they can drop it off or pick it up from the FTP server (which I don&#039;t have to backup, unlike the email server).

I would take Adrian&#039;s advice with a grain of salt (more like a baseball sized chunk than a grain really).</description>
		<content:encoded><![CDATA[<p>I use FTP for all kinds of stuff, the number one is that I do not allow email attachments over 10MB. If someone needs to get a file to us or from us that is larger than 10MB they can drop it off or pick it up from the FTP server (which I don&#8217;t have to backup, unlike the email server).</p>
<p>I would take Adrian&#8217;s advice with a grain of salt (more like a baseball sized chunk than a grain really).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Karl L. Gechlik &#124; AskTheAdmin.com</title>
		<link>http://www.asktheadmin.com/2008/07/my-sonicwall-wont-let-me-ftp-error-ftp-pasv-response-bounce-attack-dropped.html/comment-page-1#comment-7481</link>
		<dc:creator>Karl L. Gechlik &#124; AskTheAdmin.com</dc:creator>
		<pubDate>Thu, 31 Jul 2008 07:18:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.asktheadmin.com/?p=1788#comment-7481</guid>
		<description>I use FTP daily and SSL Ftp if I need something a little more secure. But yeah I agree with Peter why shouldn&#039;t I be using FTP Steven? 

I get a 404 on that link as well - is this some sort of viral link that is supposed to make me search around for your post/answer?</description>
		<content:encoded><![CDATA[<p>I use FTP daily and SSL Ftp if I need something a little more secure. But yeah I agree with Peter why shouldn&#8217;t I be using FTP Steven? </p>
<p>I get a 404 on that link as well &#8211; is this some sort of viral link that is supposed to make me search around for your post/answer?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Peter</title>
		<link>http://www.asktheadmin.com/2008/07/my-sonicwall-wont-let-me-ftp-error-ftp-pasv-response-bounce-attack-dropped.html/comment-page-1#comment-7480</link>
		<dc:creator>Peter</dc:creator>
		<pubDate>Thu, 31 Jul 2008 06:43:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.asktheadmin.com/?p=1788#comment-7480</guid>
		<description>Adrian - Um, why not use FTP?  FTP is a great tool for moving larger files.  (Maybe you say why in your link but it&#039;s not working.)</description>
		<content:encoded><![CDATA[<p>Adrian &#8211; Um, why not use FTP?  FTP is a great tool for moving larger files.  (Maybe you say why in your link but it&#8217;s not working.)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adrian</title>
		<link>http://www.asktheadmin.com/2008/07/my-sonicwall-wont-let-me-ftp-error-ftp-pasv-response-bounce-attack-dropped.html/comment-page-1#comment-7470</link>
		<dc:creator>Adrian</dc:creator>
		<pubDate>Wed, 30 Jul 2008 20:28:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.asktheadmin.com/?p=1788#comment-7470</guid>
		<description>I think the real question here is why use FTP?

http://stevenf.com/archive/dont-use-ftp.php</description>
		<content:encoded><![CDATA[<p>I think the real question here is why use FTP?</p>
<p><a href="http://stevenf.com/archive/dont-use-ftp.php" rel="nofollow">http://stevenf.com/archive/dont-use-ftp.php</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: El Di Pablo</title>
		<link>http://www.asktheadmin.com/2008/07/my-sonicwall-wont-let-me-ftp-error-ftp-pasv-response-bounce-attack-dropped.html/comment-page-1#comment-7462</link>
		<dc:creator>El Di Pablo</dc:creator>
		<pubDate>Wed, 30 Jul 2008 18:21:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.asktheadmin.com/?p=1788#comment-7462</guid>
		<description>Cool, I will check that out. We happen to use Sonicwall pretty extensively.

-EDP</description>
		<content:encoded><![CDATA[<p>Cool, I will check that out. We happen to use Sonicwall pretty extensively.</p>
<p>-EDP</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: chexxer</title>
		<link>http://www.asktheadmin.com/2008/07/my-sonicwall-wont-let-me-ftp-error-ftp-pasv-response-bounce-attack-dropped.html/comment-page-1#comment-7461</link>
		<dc:creator>chexxer</dc:creator>
		<pubDate>Wed, 30 Jul 2008 18:02:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.asktheadmin.com/?p=1788#comment-7461</guid>
		<description>It looks like the low end hardware firewalls are now being initially configured to limit what can get out, and you have to make adjustments for what you need, outside of the manufacturers default settings.

Smoothwall Express 3.0 (Free)when first installing does have about three initial set-ups you can select, and as far as I can remember one blocks everything, one allows the main ports, I think the other one was let everything through. I selected the main ports settings, and then had to add a couple of special email ports and the time ports to the allow list.

At first I didn&#039;t realize what was wrong, but the logs in Smoothwall Express help you to see what&#039;s getting blocked .

I suppose the problem with going this route is having the inclination to install it (it&#039;s not that hard) and having an old computer, putting a minimum of two NIC&#039;s in and having the space to park it.

If anyone is interested in going this route, for version 3.0 you need a minimum of about a 300Mhz Pentium, 128MB ram and about 6.4Gb disk, with keyboard and CD drive required just for the installation. you use your web browser for any configuration, monitoring, etc after installation. Go to Smoothwall.org to download the free ISO version, just need to burn a CD.  

You could go the mini ITX route to keep it quite small like the Sonicwall but the box would be a bit OTT for a firewall.

I use a Shuttle box that was a bit OTT, just so I could fit it in a cupboard where my mains, telephone, tv and network distribution is.</description>
		<content:encoded><![CDATA[<p>It looks like the low end hardware firewalls are now being initially configured to limit what can get out, and you have to make adjustments for what you need, outside of the manufacturers default settings.</p>
<p>Smoothwall Express 3.0 (Free)when first installing does have about three initial set-ups you can select, and as far as I can remember one blocks everything, one allows the main ports, I think the other one was let everything through. I selected the main ports settings, and then had to add a couple of special email ports and the time ports to the allow list.</p>
<p>At first I didn&#8217;t realize what was wrong, but the logs in Smoothwall Express help you to see what&#8217;s getting blocked .</p>
<p>I suppose the problem with going this route is having the inclination to install it (it&#8217;s not that hard) and having an old computer, putting a minimum of two NIC&#8217;s in and having the space to park it.</p>
<p>If anyone is interested in going this route, for version 3.0 you need a minimum of about a 300Mhz Pentium, 128MB ram and about 6.4Gb disk, with keyboard and CD drive required just for the installation. you use your web browser for any configuration, monitoring, etc after installation. Go to Smoothwall.org to download the free ISO version, just need to burn a CD.  </p>
<p>You could go the mini ITX route to keep it quite small like the Sonicwall but the box would be a bit OTT for a firewall.</p>
<p>I use a Shuttle box that was a bit OTT, just so I could fit it in a cupboard where my mains, telephone, tv and network distribution is.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk
Page Caching using disk (enhanced)

Served from: www.asktheadmin.com @ 2012-02-10 01:48:20 -->
