Opened 14 years ago

Last modified 6 years ago

#844 closed Bug report

Failure to establish TLS connection behind NAT gateway

Reported by: peter_daum Owned by: Alexander Schuch
Priority: normal Component: FileZilla Client
Keywords: Cc: peter_daum, Alexander Schuch, easiconseil, mortemorte
Component version: Operating system type:
Operating system version:

Description

FileZilla (2.2.12c) can't establish a TLS connection to
a PureFTPd
server (possibliy other servers, too?) when it (the
FileZilla client)
is sitting behind a NAT gateway.
The problem already arises during the TLS connection
negotiation
(so this is _not_ a "classical" firewall issue with
tracking the data connections!).

The conversation looks like this:

  • Client connects to server
  • Server responds with ready
  • Client sends "AUTH TLS"
  • Server responds with OK
  • Client sends some (scrambled) request
  • Server responds with (scrambled) response (obviously OK,

since there is no indication of any failure in the log)

  • Both parties wait for something that doesn't happen
  • ... eventually, FileZilla times out and starts all

over again
The connection does not get to the point, where the TLS
encryption
for the control channel is succesfully established
(this would show
up in the log files)

Whe the FileZilla client has a "real" IP address, it
can cooperate with
the same server. Other clients (I tested "lftp") have
no problem to
establish the TLS connection through the NAT gateway.

Attached is a packet dump of the network traffic (
which due to the
encryption is not really enlightening)

Attachments (1)

capture.txt (6.4 KB) - added by peter_daum 14 years ago.
captured network traffic

Download all attachments as: .zip

Change History (5)

Changed 14 years ago by peter_daum

Attachment: capture.txt added

captured network traffic

comment:1 Changed 14 years ago by easiconseil

I make tests and the bug occure with Titan FTP Server v3 and
v4 and BlackMoon FTP Server v3.0.4.1723.

I use FileZilla 2.2.12c behind a Bewan Booster 32g router.

comment:2 Changed 14 years ago by mortemorte

I confirm this issuse with a Serv-U ftp version 5 and 6.
Old filezilla 2.2.11 works.

comment:3 Changed 11 years ago by Alexander Schuch

As this bug report is quite old and lots has changed in the client... please try latest FileZilla 3 and check if it works there. And please report back so that the bug can be fixed in case it still is there.

comment:4 Changed 11 years ago by sf-robot

This Tracker item was closed automatically by the system. It was
previously set to a Pending status, and the original submitter
did not respond within 14 days (the time period specified by
the administrator of this Tracker).

Note: See TracTickets for help on using tickets.