Elective Network and System Administration

Network and System AdministrationUnit 712 min read

FTP, File & Print Servers: Protocols, Configurations & Services

Unit 7 of Network and System Administration explores FTP (File Transfer Protocol), file servers (NFS/Samba), and print servers (CUPS/LPD), covering their architectures, configurations, security, and real-world deployments in Nepalese IT infrastructure like banks, universities, and e-commerce platforms.

TAKEAWAYS:

  • Understand FTP’s two modes (active/passive) and how they differ in firewall traversal and security.
  • Configure NFS and Samba for cross-platform file sharing, comparing their use cases (Linux vs. Windows).
  • Set up CUPS/LPD for centralized printing, troubleshooting common issues like queue jams or driver conflicts.
  • Secure servers using SFTP/FTPS, ACLs, and encryption (TLS/SSL) to prevent unauthorized access.
  • Analyze print server logs to diagnose errors like "printer offline" or "access denied."
  • Apply concepts to real-world scenarios like university file repositories, bank document sharing, or Daraz’s internal file transfers.

1. File Transfer Protocol (FTP)

FTP is a client-server protocol (port 20/21) for transferring files between systems. It uses two channels:

  • Command channel (port 21): Sends commands (e.g., USER, PASS, RETR).
  • Data channel (port 20): Transfers actual files.

1.1 FTP Modes: Active vs. Passive

FTP operates in two modes, differing in how the data connection is initiated:

Feature Active Mode Passive Mode
Initiator Client initiates data connection to server Server initiates data connection to client
Firewall Struggles with NAT/firewalls (server must open ports) Works behind NAT/firewalls (client opens ports)
Security Less secure (exposes server ports) More secure (client-controlled ports)
Use Case Legacy systems, internal networks Modern networks, cloud transfers

WORKED EXAMPLE: FTP in a University Lab Scenario: A student in TU’s Central Department of Computer Science needs to upload a 100 MB project file to a server in Pokhara University (across Nepal Telecom’s network).

  • Active Mode:
    • Client (student’s laptop) sends PORT command to server, specifying its IP (192.168.1.100) and a random port (e.g., 54321).
    • Server opens port 20 and connects back to the client’s port 54321 (firewall may block this if not configured).
    • Problem: If the student is behind NTC’s NAT, the server’s return connection fails.
  • Passive Mode:
    • Client sends PASV command.
    • Server opens a random high port (e.g., 60000) and tells the client to connect to it.
    • Client connects to server_ip:60000, bypassing NAT issues.
    • Solution: Works seamlessly for remote transfers (e.g., submitting assignments to a cloud server).

1.2 FTP Commands & Workflow

Key FTP commands:

USER username       # Login
PASS password       # Authentication
RETR filename       # Download file
STOR filename       # Upload file
LIST                # List directory contents
QUIT                # End session

Mermaid Sequence Diagram: FTP Login & File Transfer

sequenceDiagram
    Client->>Server: USER student (port 21)
    Server-->>Client: 331 Password required
    Client->>Server: PASS ******
    Server-->>Client: 230 Login successful
    Client->>Server: RETR project.zip
    Server->>Client: Opens data channel (port 20/21) and sends file
    Client-->>Server: 226 Transfer complete

1.3 Secure FTP (SFTP/FTPS)

Protocol Description Ports Security
SFTP SSH File Transfer (encrypted tunnel) 22 (SSH) Strong (SSH keys)
FTPS FTP over SSL/TLS 990 (explicit) Medium (certificates)
FTP Plaintext (unencrypted) 20/21 Weak (passwords in cleartext)

REAL-WORLD: SFTP in Nepal’s Banking Sector

  • Nepal Rastra Bank (NRB) uses SFTP to securely transfer daily transaction reports between branches and the central server.
  • Why SFTP?
    • Encrypts data in transit (prevents MITM attacks).
    • Uses SSH keys (no password brute-force risks).
    • Compatible with legacy banking systems.

2. File Servers: NFS vs. Samba

File servers allow shared access to files across a network. Two dominant protocols:

2.1 Network File System (NFS)

  • Developed by: Sun Microsystems (1980s).
  • OS Support: Primarily Linux/Unix.
  • Port: 2049 (UDP/TCP).
  • How it Works:
    1. Client mounts a remote directory (e.g., /mnt/server_share).
    2. All file operations (read/write) are handled by the NFS server.
    3. Uses Remote Procedure Calls (RPC) for communication.

Mermaid Class Diagram: NFS Architecture

classDiagram
    class Client {
        +mount(server:ip, path)
        +read/write(file)
    }
    class NFS_Server {
        +export(path, permissions)
        +handle_requests()
    }
    class RPC {
        +call(procedure, args)
    }
    Client --> RPC : Uses RPC
    RPC --> NFS_Server : Calls procedures

WORKED EXAMPLE: NFS in Tribhuvan University

  • Scenario: TU’s Central Library hosts a 1 TB digital repository of research papers.
  • Setup:
    • Server: Linux machine with /data/library exported via NFS.
    • Client: Faculty laptops mount /data/library as /mnt/tu_library.
  • Commands:
    # Server: Export directory
    echo "/data/library *(rw,sync,no_subtree_check)" >> /etc/exports
    exportfs -a
    # Client: Mount
    mount -t nfs server_ip:/data/library /mnt/tu_library
    
  • Advantages:
    • High performance (low latency for Unix-like systems).
    • No per-user authentication (relies on OS-level permissions).

2.2 Samba (SMB/CIFS)

  • Developed by: Microsoft (SMB) / Samba Team (CIFS).
  • OS Support: Windows, Linux (via Samba daemon).
  • Port: 445 (SMB).
  • How it Works:
    • Uses Server Message Block (SMB) protocol.
    • Supports user-level authentication (Windows AD integration).
    • Works over NetBIOS (137-139) or TCP/IP (445).

Comparison Table: NFS vs. Samba

Feature NFS Samba (SMB)
Primary OS Linux/Unix Windows/Linux (Samba)
Authentication OS-level (UID/GID) User/password (Windows AD)
Performance Faster for Unix clients Better for Windows clients
Security RPC-based (vulnerable to attacks) SMB signing, encryption
Use Case Linux clusters, HPC Mixed Windows/Linux networks

REAL-WORLD: Samba in Nepal’s E-Commerce

  • Daraz Nepal uses Samba to share product catalogs between:
    • Web servers (hosting daraz.com.np).
    • Inventory databases (stored in Windows SQL Server).
  • Why Samba?
    • Seamless integration with Windows-based ERP systems.
    • Supports ACLs (Access Control Lists) for fine-grained permissions.

3. Print Servers: CUPS & LPD

Print servers manage printer queues, allowing multiple users to send jobs to shared printers.

3.1 Common Unix Printing System (CUPS)

  • Port: 631 (IPP protocol).
  • Architecture:
    flowchart TD
      A["Client (Browser/Application)"] -->|"IPP Job"| B["CUPS Scheduler"]
      B --> C["CUPS Filter"]
      C --> D["Printer Driver"]
      D --> E["Physical Printer"]
  • Key Commands:
    lpstat -a          # Check printer status
    cancel 123        # Cancel job ID 123
    lpadmin -p printer_name -v /dev/usb/lp0 # Add printer
    

WORKED EXAMPLE: CUPS in Kathmandu University

  • Scenario: A departmental printer in KU’s Computer Science building is shared by 50 students.
  • Setup:
    1. Admin configures CUPS on a Linux server:
      lpadmin -p ku_printer -E -v parallel:/dev/usb/lp0 -m foo.ppd
      
    2. Students submit jobs via:
      lp -d ku_printer assignment.pdf
      
  • Common Issues & Fixes:
    Issue Cause Solution
    Printer offline Paper jam or disconnected cable Check physical connections
    "Access denied" Wrong permissions lpadmin -p printer -u allow:all
    Slow printing High queue load Prioritize jobs with lp -o priority=50

3.2 Line Printer Daemon (LPD)

  • Legacy protocol (still used in some Unix systems).
  • Port: 515 (LPD), 721 (LPRng).
  • Commands:
    lpr file.txt        # Send print job
    lpq                # Check queue
    lprm job_id         # Remove job
    

Comparison: CUPS vs. LPD

Feature CUPS LPD
Protocol IPP (modern) LPR (legacy)
Port 631 515
GUI Web interface (http://localhost:631) CLI-only
Security Built-in authentication Weak (relies on OS permissions)

REAL-WORLD: Print Servers in Nepal Telecom (NTC)

  • NTC’s billing department uses a CUPS-based print server to:
    • Generate monthly phone bills (PDFs) for 10,000 customers.
    • Route jobs to high-speed printers in bulk.
  • Why CUPS?
    • Centralized logging (/var/log/cups/).
    • IPP supports IPv6 (future-proof for NTC’s network upgrades).

4. Security Best Practices

4.1 FTP Security

  • Avoid plain FTP: Use SFTP (SSH) or FTPS (TLS).
  • Chroot jail: Restrict users to their home directories.
  • Disable anonymous login:
    anonymous_enable=NO  # In vsftpd.conf
    
  • Firewall rules:
    iptables -A INPUT -p tcp --dport 21 -j ACCEPT
    iptables -A INPUT -p tcp --dport 20 -j DROP   # Block active mode
    

4.2 File Server Security

  • NFS:
    • Use no_root_squash cautiously (root access risks).
    • Restrict exports to trusted subnets:
      echo "/data *(rw,root_squash,subnet=192.168.1.0/24)" >> /etc/exports
      
  • Samba:
    • Enable SMB signing:
      [global]
      smb encrypt = required
      
    • Use AD integration for centralized authentication.

4.3 Print Server Security

  • Disable unnecessary ports:
    cupsd -d (debug mode) → Check listening ports
    
  • Restrict access:
    lpadmin -p printer_name -o auth-info-required=yes
    
  • Audit logs:
    tail -f /var/log/cups/error_log
    

In the Real World

  1. eSewa & Khalti (Digital Payments)

    • FTP/SFTP: Used internally to transfer transaction logs between eSewa’s servers and Nepal Rastra Bank’s auditing systems.
    • Why? Secure, encrypted transfers of sensitive financial data.
  2. Daraz Nepal (E-Commerce)

    • Samba: Shares product images and inventory data between Windows-based ERP systems and Linux web servers.
    • Print Server: CUPS manages shipping labels printed in bulk for Kathmandu warehouses.
  3. Nepal Stock Exchange (NEPSE)

    • NFS: Hosts real-time stock data for brokers across Nepal, ensuring low-latency access.
    • Security: Data encrypted in transit (TLS) and access restricted via IP whitelisting.

Exam Tip

This unit is heavily practical in exams. Expect:

  1. Configuration questions:
    • Write vsftpd.conf for passive FTP with TLS.
    • Configure Samba shares with read-only permissions.
  2. Troubleshooting:
    • Debug a printer offline issue (check CUPS logs, cable, permissions).
    • Fix an NFS mount failure (verify rpcbind, /etc/exports).
  3. Scenario-based:
    • "A bank uses FTP to transfer reports. Why is passive mode preferred over active?"
    • "How would you secure a Samba share for a university’s student files?"
  4. Diagrams:
    • Draw FTP active/passive data flow.
    • Sketch a CUPS architecture with clients, scheduler, and printer.
  5. Short-answer:
    • Define chroot in FTP.
    • Compare NFS vs. Samba in one sentence.

Common Pitfalls:

  • Forgetting firewall rules for passive FTP (port 21 + dynamic ports).
  • Misconfiguring Samba permissions (e.g., guest ok = yes in production).
  • Ignoring TLS for FTP (exams may ask for FTPS/SFTP setup).

Based on the TU BSc CSIT syllabus for Network and System Administration, unit 7.

Discussion

Loading…