Intermittent Passive FTP connection via Azure Firewall

Simon Bennetts 66 Reputation points
2025-06-19T08:19:04.9533333+00:00

Hi

I've set up an FTP server on a Windows 2022 vm on vnet4. The VM has a number of private addresses as it's used for HTTPS and FTP. It also currently has an unused public IP.

I have an Azure firewall on vnet3. The firewall policy has DNAT rules enabled on the initial port and the range of ports enabled on the FTP server.

I also have Network rules set up to pass the specific ports to the correct private IP of my VM.

My problem is the connectivity is extremely intermittent. When using FileZilla, I can refresh the connection multiple times and around 50% of the time I can connect and retrieve the directory listing correctly and the other 50%, I am getting connectivity issues:

Command: EPSV
Response: 229 Entering Extended Passive Mode (|||5233)
Command: LIST
Response: 150 Opening BINARY mode data connection.
Response: 550 The network connection was aborted by the local system
Error: Failed to retrieve directory listing

The fact it works 50% of the time suggests things are configured correctly but there's someone not quite right. If I use FileZilla on the VM (and change the firewall IP), it connects 100% of the time which makes me think it's a firewall or connectivity issue rather than a problem with the VM.

Any ideas?

Thanks

Simon

Azure Firewall
Azure Firewall

An Azure network security service that is used to protect Azure Virtual Network resources.


3 answers

Sort by: Most helpful
  1. Simon Bennetts 66 Reputation points
    2025-06-20T14:04:11.6433333+00:00

    For anyone looking for a solution to this problem, it seems to be related to the fact Passive FTP establishes different connections for control and data channels. Inbound connections on Azure Firewall are SNATed to one of the firewall private IP addresses to ensure symmetric routing. FTP might fail when data and control channels use different source IP addresses, depending on your FTP server configuration.

    Microsoft are aware of the issue (https://docs.azure.cn/en-us/firewall/firewall-known-issues) but it needs upvoting to try to get something done about it.

    Preserving the original source IP address is being investigated. In the meantime, you can configure your FTP server to accept data and control channels from different source IP addresses.

    Seems a very simple thing to offer - FTP behind Azure Firewall.

    https://feedback.azure.com/d365community/idea/590626a0-8fd7-ef11-95f5-6045bd80c60

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments

  2. Alex Burlachenko 25,370 Reputation points MVP Volunteer Moderator
    2025-06-20T07:18:41.63+00:00

    Hi Simon, thanks for posting this tricky one ))

    check if u enabled 'ftp helper' in azure firewall. its a sneaky little feature that helps with passive ftp quirks. without it, the data channel ports might get blocked randomly. Make sure ur nat rules match exactly what filezilla expects. sometimes the port ranges in azure need to be 1-2 ports wider than u think. seen this bite people before.

    when passive ftp acts up, its usually the firewall dropping data channel connections. try this - crank up filezilla's logging to 'debug' mode. ull see exactly which ports its trying to use when it fails. then u can hunt down the missing rule )) some ftp servers freak out if client switches between ipv4 and ipv6. force filezilla to use ipv4 only in settings. works wonders sometimes.

    worth looking into network security groups too. they might be blocking return traffic even if azure firewall allows it. classic azure networking layers ))

    btw... if u wanna go to an cool option, active ftp mode usually survives bad firewall configs better. not ideal but, it gets the job done when ur desperate %)

    let us know if the ftp helper thing fixes it! microsoft put that in there exactly for cases like urs. their networking team actually did something smart for once :))

    this might help in other tools too, whenever passive transfers fail randomly, its 90% firewall dropping data channels. same fix applies to aws, gcp, whatever. just different menus to click through )

    hope u get those files flowing smoothly soon..

    rgds,

    Alex

    Was this answer helpful?


  3. Ganesh Patapati 12,170 Reputation points Microsoft External Staff Moderator
    2025-06-19T09:36:08.1266667+00:00

    Hello Simon Bennetts

    Ensure that your FTP server is configured to support Passive FTP. If you’re using FileZilla, explicitly set it to use Passive mode since this is typically the preferred method in a firewall setup.

    You mentioned that DNAT rules and Network rules are set up. Double-check if your network rules allow for the full range of data ports your FTP server may be using. Ensure there’s no mismatch between the ports specified on the FTP server and those allowed in the firewall rules.

    NOTE: It’s also important to make sure your Azure Firewall is using a single public IP address for FTP traffic. The use of multiple public IP addresses could cause issues since Passive FTP requires consistent source IP addresses for both data and control channels. You could consider configuring your NAT gateway to use a single public IP.

    Refer: https://learn.microsoft.com/en-us/azure/firewall/ftp-support?source=recommendations

    User's image

    FTP server with passive mode will not be supported as per the document.

    Passive FTP over the internet is currently unsupported because the data path traffic (from the internet client via Azure Firewall) can potentially use a different IP address (due to the load balancer). For security reasons, it’s not recommended to change the FTP server settings to accept control and data plane traffic from different source IP addresses.

    As an alternate method,

    Azure Load Balancer does support FTP in passive mode, but there’s a catch: it doesn’t natively support port ranges in a single rule. That means if your FTP server uses a passive port range (e.g., 50000–51000), you’ll need to manually create individual load balancing rules for each port in that range

    Please refer this article: https://learn.microsoft.com/en-us/answers/questions/103061/passive-ftp-need-port-range-in-load-balancer-rule


    If the above is unclear or you are unsure about something, please add a comment below.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.