Firewalls, NAT, and File Transfer
"It's the firewall." "The firewall hasn't changed." No category of software has a more complicated relationship with firewalls than file transfer. That exchange is where the relationship usually surfaces. FTP opens extra connections in directions firewalls distrust. NAT rewrites the addresses those connections depend on. Helpful middleboxes try to patch things up in ways that break encrypted sessions entirely. Half of all transfer support tickets are, underneath, firewall tickets. The firewall, for its part, drops the packet in silence and feels no need to explain.
This series makes the relationship manageable. It explains why transfer protocols fight firewalls in the first place and what the different kinds of NAT do to a transfer. It covers application helpers and gateways as friend and foe, and how to design rules that are both tight and transfer-friendly. It provides a playbook for the classic firewall symptoms. It also covers how to coordinate firewall changes with partners who have firewalls of their own. The passive-mode mechanics themselves live in our active-versus-passive series; here we design and troubleshoot around them. By the end, "it's the firewall" should be a diagnosis rather than a shrug.
Articles in This Series
- Why File Transfer Protocols Fight Firewalls
This article covers the multi-connection problem, stateful inspection in plain words, and NAT as address rewriting. It explains why SFTP on one port is calm while FTP and FTPS keep starting arguments. - NAT Types and What They Do to Transfers
This article explains source NAT, port forwarding, double NAT, carrier-grade NAT, and hairpinning through each one's effect on a transfer. That includes the announced-address problem passive FTP is famous for. - Application Helpers and ALGs: Friend and Foe
This article covers what FTP helpers actually do - rewrite addresses, open pinholes. It explains why they cannot help an encrypted control channel and sometimes break it, the symptoms, and when to turn them off. - Designing Transfer-Friendly Firewall Rules
This article covers least-privilege rules per protocol, sizing the passive range, partner allowlists, and egress rules for outbound jobs. It also covers logging the rules that matter and documenting why each one exists. - A Firewall Troubleshooting Playbook for Transfers
This article covers reproducing from both sides, reading firewall logs, and packet-capture spot checks. Its classic symptom table includes listing hangs, timeouts after login, and works inside but not outside. - Coordinating Firewall Changes with Partners
This article covers the allowlist dance, address changes on either side, maintenance notices, and the shared connection sheet. It also covers testing a rule change without breaking the nightly feed.
Frequently Asked Questions
Which ports do I open for FTP, FTPS and SFTP?
Why does FTP fight firewalls when SFTP does not?
Explore More Topics
This series is part of the Sysax file transfer topic library. The library covers the protocols, security practices, automation techniques, and operational skills behind reliable file transfer. The library pairs well with the practical tools we build. Sysax Multi Server is a secure FTP, FTPS, SFTP, and HTTPS server for Windows. Sysax FTP Automation schedules and scripts secure transfers so the routine ones run themselves.
