Telkom and PASV FTP

  • Thread starter Thread starter melse
  • Start date Start date
M

melse

Guest
Since I have a Telkom ADSL connection (HomeDSL 192 kbps) I am experiencing problems with passive FTP (with my previous ISP overseas everything worked fime).
As long as I connect with my FTP client to a FTP server in active mode, I get normal download speeds (15-20 kB/s). However, when I connect to a server which is in pasv mode, download speed drops to about 5 kB/s.
Does Telkom cap the speed of high port ranges??

The same problem with the FTP server I run myself: in active mode normal upload speed for the clients, in pasv mode (set to port range 50000-50100) the speeds is 3 or 4 times lower.

Does Telkom cap the speed of high port ranges??
Why??
 
if your FTP application uses ports other than the standard FTP ports (tcp 20 and 21) then it WILL be shaped. Telkom clearly states that its normal ADSL is shaped so that HTTP, SMTP and FTP take priority, so any other applications that use other ports will be shaped. Just because you're running an FTP app it doesn't mean it wont be shaped if you're using non-standard FTP ports.

Edit: Just correcting myself, it's not Telkom that shapes your data, it's your ISP.
 
Last edited:
Well, that's new information for me. But why do they do that? To reduce p2p network load?
(in that case, can't people just run there p2p programs on these "allowed" ports, if shaping down this sort of network traffic is the goal of Telkom?)
 
You cannot run P2P software on the well-known port numbers which range from 1-1024 It's the way TCP/IP works, you can read-up on it if you'd like but if you have any I.T experience whatsoever you should know this by now. TCP/IP is not so easily "cheated", like you want to run FTP on ports OTHER than 20/21. Think for yourself what the security implications would be? In your world, you want ANY program to use ANY port number....cool....so then firewalls would never work and proxies would never work either because they control traffic via PORTS, which means they won't be able to stop hackers, virusses or spyware.

If you want to use FTP, it HAS to (and this is simply how things are) use ports 20 and 21. If you use file transferring programs that use other ports it will NEVER be considered FTP...it's then called P2P...and Telkom shapes it so that people don't abuse the bandwidth, so that other might also have a chance at using the net.

For your reference (because it doesn't look like you know), the following apps use the following ports:

HTTP: 80
SMTP: 25
POP: 110
Telnet: 23
FTP: 20/21

ALL OTHER PORTS ARE SHAPED! Even if you're using a program called "FTP DELUXE SUPER PROGRAM" and it uses ports OTHER than 20/21 ---- Guess what......IT'S NOT FTP!
 
Last edited:
Ha ha, I have some IT experience :-)
But from your posting I understand: Telkom does not just shape ports others than the usual ones, but also checks the type of traffic and shapes based on that (or not).
BTW, where do you have this information on Telkoms policy from?
 
NO telkom can only shape traffic based on ports...geesh...do you honestly think they scan each and every freaking packet that people transmit? honestly...I don't know why you keep asking these questions...I don't think you've got any networking knowledge at all based on what you're asking the whole time. Just another point of correction...it's NOT telkom that shapes your traffic...it's your ISP!!! That's why you get "shaped" accounts and "unshaped" accounts and you can find all the policies you want on the ISP's website.

This is my last post in this thread because it's like talking to a brick wall.

In fact....you should stop posting as well and phone your ISP and repeat to them the following : "Hi, my name is (insert name here), I would like to run P2P software the whole time and would rather like to have an unshaped account because I didn't know the difference between unshaped and shaped at the time of my original account creation"
 
Mr Anderson said:
Even if you're using a program called "FTP DELUXE SUPER PROGRAM" and it uses ports OTHER than 20/21 ---- Guess what......IT'S NOT FTP!

With respect there are several inaccuracies in your post.

The FTP protocol uses TWO connections - a CONTROL connection and a DATA connection. The latter is used for 1. directory lists and 2. file transfers. The control connection by convention will run on port 21. The data connection is set up in one of 2 ways:

1. Active. Here the client issues a PORT command on the control connection, instructing the server to connect back to the client on an IP/port combination and then LISTENS on that port. The data connection is server ---> client.

2. Passive. Here the client issues a PASV command on the control connection, the server responds with an IP/port combination at ITS end and listens on that port. The client then makes an outbound connection to the server on the given port. The data connection is client ---> server.

In BOTH cases the port used for the second ( data ) connection is typically a high numbered port ( ie: NOT 20, with 21 already in use anyway for the control connection ). This is quite permissible in the FTP rfc's.

In terms of you comments on packet inspection, there are vendors who sell devices that do deep-packet inspection. I have no idea if any ISP here uses them.

If you were to write your own p2p program you could make it run on the low ( < 1024) ports if you so wished - TCP/IP itself is not going to stop you ( some unix systems by default block LISTENING on these ports by default for security but you can change this ).

You can also run an FTP server not on port 21 - as long as whoever is connecting to you knows the port it will work fine.

My suspicion about melse's issue is that it has to do with the direction of the connect - ie: client ---> server or vice versa.
 
Peter_J said:
1. Active. Here the client issues a PORT command on the control connection, instructing the server to connect back to the client on an IP/port combination and then LISTENS on that port. The data connection is server ---> client.

2. Passive. Here the client issues a PASV command on the control connection, the server responds with an IP/port combination at ITS end and listens on that port. The client then makes an outbound connection to the server on the given port. The data connection is client ---> server.
I've always wondered what the difference is.

Is one better/more reliable than the other?
My experience is that passive mode seems to work better and is more reliable.

Some recent experience with webonline (local) in that active mode does just not work, there are constant time out and connection problems. Passive mode works perfectly, everytime. This with the ftp client on telkom ADSL.
Webonline support says that both should work equally as good.
 
Sig_ZA said:
Is one better/more reliable than the other?
My experience is that passive mode seems to work better and is more reliable.

In theory there is no difference because it is just about which end listens and which connects, and once the connection is established it is just a connection over which data passes. Passive is often used these days because firewalls and ISPs block (active) client listening ports, to stop you running servers, and for security ( preventing exploits ). In practice I agree with you - some setups and some servers work better on one, others on the other!
 
Ah, it is good to notice that there are also some people around that act "civilized" ;-)

Peter_J, you say in BOTH cases (both active and passive FTP) the port used for the second ( data ) connection is typically a high numbered port.
This is true for passive FTP, but not for active FTP as far as I know: active FTP uses port 20 for data on the server's site ( see e.g. http://slacksite.com/other/ftp.html ).
So that's why I think the problem is the high port traffic, not the direction of the connection. In both cases, the client connects to the server, only in pasv mode the server opens a high port for the client instead of port 20.

The reason that I prefer to use pasv FTP on my FTP server myself, is because of clients that are behind a firewall they can not control themselves.

If the problem is not Telkom, but the ISP (which is Telkom as well in my case), would it help to change ISP?
Does anyone experience unshaped traffic on high ports with other SA ISP's?
 
melse said:
Peter_J, you say in BOTH cases (both active and passive FTP) the port used for the second ( data ) connection is typically a high numbered port.
This is true for passive FTP, but not for active FTP as far as I know: active FTP uses port 20 for data on the server's site ( see e.g. http://slacksite.com/other/ftp.html ).

To my knowledge it depends on the client. I have never seen a client use port 20, but I do not go round looking at this! ;)

On my PC, connecting to funet using CuteFTP, CuteFTP issues ( x=my IP ) :
PORT xxx,xxx,xxx,x,7,22
which would be 7*256 plus 22 if I recall correctly. Another sample:
(See PORT 192,168,10,232,6,127.) The 6, 127 portion becomes a port number by multiplying the first digit by 256 and adding the second digit. So the client specified a port number that is (6 x 256) + 127, which equals 1663.
from http://www.troubleshootingnetworks.com/ftpinfo.html

So I suggest looking at your FTP client's logs to see what port it is using. Or run something like ActivePorts if you are on a PC. Also, typically a client ( and server too I suppose ) use a different or new port for each direcory list or file transfer ( e.g. each time you change server directory ).
 
Hi, I run a Windows pc, so I ran netstat to see actual port number at my side and took an exact log at the ftp client and server logs.

Running a client on my side:
Both active and passive mode: ports used on my side are between 1023-2000 (= settings of my client)
Port on server is 20 in active mode and varies if in pasv mode, usually > 10000 (depending on server settings).

Running a server on my side:
Passive mode:
Data ports on server are between 50000-50100 (=settings of my server), ports on client side between 1000-2000.
Active mode:
Data ports on server is 20, ports on client side between 1000-2000.

In all cases, at active mode I experience high speeds, in passive mode low speeds. So both data transfer to and from high range ports seems to be a problem.

Will this problem disappear if I change of provider (currently Telkom)??
 
Well that gives you the answer I think ( feeling a bit befuddled at the moment so excuse confusion! ). Low ports not heavily shaped, high ones heavily shaped. Just like using NNTP to my one overseas news server which takes connections on port 119 ( normal NNTP ) and 23 ( telnet ). Port 119 dog slow, port 23 nice and fast!

I do not know if changing your ISP will help - can you just not always use active? There have been posts on these forums about unshaped accounts not really being unshaped, hence my doubts. The damn stuff seems to get shaped at different points ( ie: a SAIX reseller might not shape, but SAIX does etc ).

I would suggest finding a friend or whatever who might let you try via a different ISP - maybe IS or Verizon. Am on IS myself at the moment.

Interesting results you got though. :)

PS Edit - You could maybe also buy a small account from one of the other ISPs who resell IS or Verizon to test with. Some are regulars around here so I am sure you could search the forum and find a good e.g. 1Gb test account for not much $$, or mail them and ask.
 
Last edited:
I will see, maybe I will just forget about pasv ftp untill policy changes...

BTW, I am having the same problem as you about that overseas nntp server; unfortunately that news server only accepts port 119 traffic :-(
 
Ha, I just found out both SHAPED and UNSHAPED accounts exist here. I had never heard from that... (you must excuse me, I am quite new to South Africa :-)
In The Netherlands, where I come from, no one has ever heard from shaped internet access, all subsriptions are uncapped, and finally, it is much much cheaper!
So getting un unshaped account should solve my issues I guess.

Anyone knows what is the cheapest unshaped subscription around?
 
Top
Sign up to the MyBroadband newsletter
X