KWSupport

Kevin Weilbacher [SBS MVP] blog on SBS, WHS and other topics of interest!

Recent Posts

Tags

News

  • Check out the "Song of the Week" link!
    Xobni outlook add-in for your inbox

Community

Email Notifications

SBS Blogs

SBS2003 Links

Archives

FTP and ISA 2004

SBS 2003 SP1 Premium includes ISA 2004. After upgrading to SP1, I discovered that I could not do an FTP upload from any workstation - it was failing with a 500 access denied error.

Here's the fix:

On your SBS server, open up ISA Server Mgmt, click on Firewall Policy, and scroll down and locate the policy labeled 'SBS Internet Access Rule'. Right click on this rule, and then click on the option 'Configure FTP'.

In the popup window that opens, click to UNCHECK the 'read only' option, then click Apply, then OK.

THEN --- look towards the top of the ISA Firewall Policy window, and you will see two new buttons displayed: Apply and Discard. Be sure to click on Apply, otherwise the changes you just made will NOT be applied.

That's it.

Go back to your workstation, restart your FTP client utility and happy uploading!

Posted: Thu, Jun 2 2005 22:15 by kwsupport | with 37 comment(s)
Filed under:

Comments

kwsupport said:

Kevin you are the Man, Thank You
HA
# June 3, 2005 8:46 AM

TrackBack said:

Something I ran across before work: With ISA 2004, the FTP filter is a slightly different beast from...
# June 5, 2005 6:25 PM

kwsupport said:

Thanks

saved a lot of time!!

Danny.
# July 4, 2005 11:29 AM

kwsupport said:

this is very helpful, spent several decades learning about ftp permissions and scratching my head for a answers to this problem. thanks to the guy who posted the top comment! he is the man indeed.

chris.
# September 30, 2005 12:55 AM

kwsupport said:

thank you so much...this has been killing me for days now.
# November 21, 2005 5:06 PM

kwsupport said:

If I do not have ISA 2004 installed but met with the same problem, then how do i solve it? Please advice.

Thank you :)
# November 25, 2005 3:37 AM

kwsupport said:

I clicked to UNCHECK the 'read only' option, then Apply , but the problem already exists.
I should mention that when I connect to FTP from internal network by entring local name or local ip I have no Problem on uploading but when I use the registred name or from external (using ISA) I have read-only acess to my FTP folders.
# December 6, 2005 7:09 AM

Jeremy said:

Thank you! This was bugging the bejeebies out of me and was dead on the right answer.
# January 18, 2006 7:53 AM

Bob Hood said:

Hey, Kev:

Here's what one of my clients, Syd Lines, discovered.... there are actually FIVE places to uncheck Read-Only. Here's his post to our local SBS Users Group listserv.....

If you have clients who use manage or update websites from their offices, there is a surprise outcome in the SBS SP1 upgrade to watch out for. By default FTP protocol is blocked in both directions because all FTP files are made "read only." You have to go in and uncheck the "read only" box on the "Configure FTP" screen. This must be done for each ISA rule having an FTP component. Of special concern are those rules governing transfers from the network or the local host (server) out to the rest of the world.

After I upgraded the server at ITRC a couple of weeks ago, staff began complaining they couldn't make changes to the three website ITRC manages. The grumbling about the proxy server was rising by the minute. Initially I thought I could tweak just open outgoing FTP Port in ISA 2004. That didn't fix it. Next I tried tweaking the desktop firewall to allow Dreamweaver and FTP but found the settings had not change since I did the upgrade. I searched Microsoft and found no hints about this. Finally, one of our interns (Eric Rogers) tripped over an Internet blog with posting about this problem.

Here's how to fix it:

Open ISA Server Management, select Firewall Policy. Right click on the rules listed below, select Configure FTP. You will see the "Read only" checkbox on the screen. Uncheck it. (Probably only the rules for FTP outbound would be of concern for updating a website hosted out of the office, but some firewall rules govern transfers of files among machine on the LAN. I suppose they could affect the development environment in some organizations.)

The rules to look for (these are from my ISA 2004 firewall):

SBS Internet Access Rule (Internal to External)

SBS Protected Network Access (Internal to Internal)

Allow traffic from Internal Network to Local Host (Internal to Internal)

SBS FTP Server Access (Local Host to External)

SBS FTP Server Access (External to Local Host)
*****************
sydlines@itresourcecenter.org





# January 23, 2006 6:38 PM

Hubert said:

A real timesaver
Thx !!
# March 15, 2006 8:18 AM

Chris said:

Many thanks - this was causing some grief to say the least after recently upgrading.
# March 16, 2006 7:31 AM

Martin Robins said:

Thanks for this; just spent 4 hrs chasing down the fact that I could FTP onto an XBox and write files to it whilst on the same side of the ISA, but got this message when on opposite sides!
Worst part is, nothing shows up in the logging to point out the problem either!
# March 25, 2006 8:47 AM

Doug said:

The solution will only work provided you dont have a rule which works against the ftp rule. For example, if you have an 'outbound internet allow' rule which is higher up in the list than the 'ftp access' rule you have created, then you must also remove the 'read only' tick from the check box on this rule, otherwise they will cancel each other out.
# April 11, 2006 9:34 AM

Mick said:

add me to the long list of people you've helped - fantastic
# May 19, 2006 7:57 AM

Jim Harrison said:

This also happens when the application is acting as a web proxy client.
For IE, this means "use folder view" and remove the proxy settings for FTP under Connections", LAN settings".
The ISA web proxy does not support any FTP commands that could change the upstream server contents.
# May 25, 2006 9:03 AM

Bill Gates said:

Useless information...
# June 18, 2006 9:09 PM

bazahang said:

i want to work with ftp in isa server2004
# June 24, 2006 2:15 AM

Randy said:

Thanks for this info. I was having trouble uploading via FTP in Dreamweaver. I followed all of the steps outlined here, and still could not upload. I went into the site settings and UNCHECKED the box for "Use passive FTP" and everything works great!

Thanks again for this tip!
# July 31, 2006 9:38 AM

Cory said:

I found this page somehow on google while searching for this problem. I can't cound on my hand how many KB articles on ISA and SBS I read with no answers to fix the problem as simple as this. Thanks.
# October 9, 2006 9:21 PM

Steve said:

Many many many thanks.  

# December 14, 2006 4:15 PM

Jim said:

Absolutely thanks.

But nobody wants to know WHY this is enabled to begin with? Why cripple FTP by default?

# January 2, 2007 12:54 PM

shawn said:

i have ISA server 2004, i can connect to remote FTP server and view but when i try upload , it gives me error 500, access denied, need premission to change folder. any idea ?

please advise !

# February 6, 2007 3:35 PM

Simon Angling said:

It took forever to find it but I had a lot of problems with ISA that ended in having to remove the FTP Access Filter.

Only after that could I get FTP to work.

# February 7, 2007 4:18 AM

Eulera said:

THANK YOU!!!

# March 29, 2007 3:29 AM

Paul Larkin said:

If I do not have ISA 2004 installed but met with the same problem, then how do i solve it? Please advice. Thank you :)
# May 16, 2007 1:51 AM

shidende said:

Thanks.

I do what Bob Hood said.

I had to go through every rule that has FTP protocol and remove The "Read Only". And now it works after the series of frustrations.

My Environment is Win2003, SP2, ISA2004.

Thanks Again.

Shidende

# August 17, 2007 7:44 AM

G.J. said:

Yes works with 2003 / isa 2004. Configure ftp through every rule... thanks

# August 28, 2007 8:01 AM

Keith Waldron said:

Checking *every* rule for the FTP check box is a key, one that I missed until these posts got me checking. Thanx!

# September 26, 2007 10:14 PM

Scott said:

I had to configure a number of different outbound rules to do this, now it works.  Thank you so much for the handy pointer.

# October 2, 2007 8:41 PM

Delano January said:

I connect and download files from an ftp site but when i try to output the results of an "ls" or "dir" command to my local file is seems like the transaction hangs. Please help?

# January 23, 2008 9:36 AM

abmiqbal said:

It Works !!!

Thanks

# April 24, 2008 3:28 AM

John Kurc said:

Spot on. I could not get this figured out. Thanks.

# May 7, 2008 3:42 PM

Dale Unroe said:

Thank you Bob Hood - that was exactly the oversight - didn't consider FTP would be affected by those other rules with larger scoped protocol listings

# September 18, 2008 1:08 PM

FTP and ISA 2004 - Upload Roadblock Take Down « Taking it Upwards with SBS - Dale aka Sisyphus’ Weblog said:

Pingback from  FTP and ISA 2004 - Upload Roadblock Take Down « Taking it Upwards with SBS - Dale aka Sisyphus’ Weblog

# September 18, 2008 1:27 PM

FTP and ISA 2004 - Upload Roadblock Take Down « Taking it Upwards with SBS - Dale aka Sisyphus’ Weblog said:

Pingback from  FTP and ISA 2004 - Upload Roadblock Take Down « Taking it Upwards with SBS - Dale aka Sisyphus’ Weblog

# September 18, 2008 1:39 PM

BMT said:

Make sure that you don't have disk quota on this will give the same error, even if you don't have ISA installed.

# October 24, 2008 11:36 AM

Michael said:

THANK YOU THANK YOU THANK YOU!

This one stumped me for the longest time - the read only checkbox. I think my head is smaller from hitting my head against the wall so many times :)

# August 14, 2009 5:19 PM