Configure Sophos UTM to work with Filezilla FTP Server
If you are running Sophos UTM at home and would like to use FileZilla FTP server, there are a few things that you need to setup to allow FTP communication with your internal server. ย My internal server at home is a Windows 2012 R2 box running as a VM inside of ESXi. ย Let’s take a look at how to configure sophos UTM to work with Filezilla FTP Server and pass traffic through.
Installing FileZilla
Below we have the installation of FileZilla on our Server. ย I am using a Windows 2012 R2 Standard box with patches, etc.
FileZilla and Windows Firewall config
There are a couple of things that we need to do to ensure that communication happens with the Windows firewall if you choose to leave it in play.
Set theย Passive mode settingsย toย use custom port range and set a range of ports of your choosing…in my case fromย 5600 toย 5650.
From the Windows Firewall side, we will create a couple of rules to encompass the FTP traffic and the passive ports. ย If you decide to turn off Windows firewall of course, you may skip the steps below.
Allowing the standard ports 21,22 here…
Allowing Passive ports here…
Sophos NAT rule configuration
On the Sophos side, we can simply add a DNAT rule to pass traffic destined for the outside WAN address for the FTP service to change the destination to our internal server IP address. ย You would setup your rule similar to the following:
As you can see, we have traffic coming fromย Any since we are going to allow FTP traffic from any outside IP address. ย The service isย FTP which you can use the built in service for this. ย Then select yourย External WAN address for theย Going to field.
We then need toย Change the destination to and here you will enter the IP address or network definition host that you have already built in this field. ย Keep the service as FTP. ย Be sure to select theย Automatic Firewall rule as this will take care of the corresponding firewall rule to allow FTP traffic to and from your host.
Once you have finished building your DNAT, hit theย Save button and your rule will look similar to the following:
Be sure to slide the little “green” slider to the right so that it turns green. ย This indicates the rule is now active.
Final Thoughts
For getting FileZilla working in Sophos UTM, there isn’t a whole lot of configuration that needs to be done. ย However, just make sure you have all of your rules in place including the Windows firewall rules if you choose to leave Windows firewall turned on.