Home › Topics › Firewalls & NAT

Firewalls, NAT, and File Transfer

"It's the firewall." "The firewall hasn't changed." No category of software has a more complicated relationship with firewalls than file transfer. That exchange is where the relationship usually surfaces. FTP opens extra connections in directions firewalls distrust. NAT rewrites the addresses those connections depend on. Helpful middleboxes try to patch things up in ways that break encrypted sessions entirely. Half of all transfer support tickets are, underneath, firewall tickets. The firewall, for its part, drops the packet in silence and feels no need to explain.

This series makes the relationship manageable. It explains why transfer protocols fight firewalls in the first place and what the different kinds of NAT do to a transfer. It covers application helpers and gateways as friend and foe, and how to design rules that are both tight and transfer-friendly. It provides a playbook for the classic firewall symptoms. It also covers how to coordinate firewall changes with partners who have firewalls of their own. The passive-mode mechanics themselves live in our active-versus-passive series; here we design and troubleshoot around them. By the end, "it's the firewall" should be a diagnosis rather than a shrug.

Articles in This Series

  • Why File Transfer Protocols Fight Firewalls
    This article covers the multi-connection problem, stateful inspection in plain words, and NAT as address rewriting. It explains why SFTP on one port is calm while FTP and FTPS keep starting arguments.
  • NAT Types and What They Do to Transfers
    This article explains source NAT, port forwarding, double NAT, carrier-grade NAT, and hairpinning through each one's effect on a transfer. That includes the announced-address problem passive FTP is famous for.
  • Application Helpers and ALGs: Friend and Foe
    This article covers what FTP helpers actually do - rewrite addresses, open pinholes. It explains why they cannot help an encrypted control channel and sometimes break it, the symptoms, and when to turn them off.
  • Designing Transfer-Friendly Firewall Rules
    This article covers least-privilege rules per protocol, sizing the passive range, partner allowlists, and egress rules for outbound jobs. It also covers logging the rules that matter and documenting why each one exists.
  • A Firewall Troubleshooting Playbook for Transfers
    This article covers reproducing from both sides, reading firewall logs, and packet-capture spot checks. Its classic symptom table includes listing hangs, timeouts after login, and works inside but not outside.
  • Coordinating Firewall Changes with Partners
    This article covers the allowlist dance, address changes on either side, maintenance notices, and the shared connection sheet. It also covers testing a rule change without breaking the nightly feed.

Frequently Asked Questions

Which ports do I open for FTP, FTPS and SFTP?
SFTP needs one rule: TCP 22. Plain FTP and explicit FTPS need TCP 21 plus the server's passive data port range, a block of high ports you define and open deliberately; implicit FTPS uses 990 in place of 21. Port 20 matters only for active-mode FTP, which most firewalls now block. The articles in this series explain why the passive range exists and how to size and verify it.
Why does FTP fight firewalls when SFTP does not?
FTP negotiates a second connection for every transfer and listing, and it announces the address and port for that connection inside the session. NAT devices and firewalls must either read that announcement, which encryption prevents for FTPS, or have the passive range opened in advance. SFTP carries everything on the single SSH connection, so there is nothing to negotiate and nothing extra to open.

Explore More Topics

This series is part of the Sysax file transfer topic library. The library covers the protocols, security practices, automation techniques, and operational skills behind reliable file transfer. The library pairs well with the practical tools we build. Sysax Multi Server is a secure FTP, FTPS, SFTP, and HTTPS server for Windows. Sysax FTP Automation schedules and scripts secure transfers so the routine ones run themselves.