Consult the documentation for the firewalls and NAT devices used at your site to determine how to set up those
devices appropriately for FTP transfers. See the next section for how to configure an Equalizer cluster for
responding to FTP requests from clients.
FTP Cluster Configuration
When configuring an FTP cluster on Equalizer, the following guidelines must be followed:
l The protocol for the cluster must be Layer 4 TCP.
l The start port parameter for the cluster must be set to port 21. (Note that port 20 is also used, but you do
not specify it when adding the cluster.)
l The spoof flag must be enabled for the cluster.
FTP data connections are automatically configured (internally) with a sticky time of one second. This is
necessary to support the passive mode FTP data connection that most web browsers use. This means that there
will be one sticky record kept for each FTP data connection. For an explanation of sticky records, see "Enabling
Sticky Connections" on page 303"Enabling Sticky Connections" on page 303
l FTP clusters occupy two internal virtual cluster slots, even though only one appears in the interface. This
permits Equalizer’s NAT subsystem to rewrite server-originated FTP data connections as they are
forwarded to the external network.
l You cannot enable the direct server return option on an FTP cluster.
Copyright © 2013 Coyote Point Systems. A subsidiary of Fortinet, Inc.
All Rights Reserved.
311
Equalizer Administration Guide
Kommentare zu diesen Handbüchern