Network and System AdministrationUnit 712 min read
FTP, File & Print Servers: Protocols, Configurations & Services
Unit 7 of Network and System Administration explores FTP (File Transfer Protocol), file servers (NFS/Samba), and print servers (CUPS/LPD), covering their architectures, configurations, security, and real-world deployments in Nepalese IT infrastructure like banks, universities, and e-commerce platforms.
TAKEAWAYS:
- Understand FTP’s two modes (active/passive) and how they differ in firewall traversal and security.
- Configure NFS and Samba for cross-platform file sharing, comparing their use cases (Linux vs. Windows).
- Set up CUPS/LPD for centralized printing, troubleshooting common issues like queue jams or driver conflicts.
- Secure servers using SFTP/FTPS, ACLs, and encryption (TLS/SSL) to prevent unauthorized access.
- Analyze print server logs to diagnose errors like "printer offline" or "access denied."
- Apply concepts to real-world scenarios like university file repositories, bank document sharing, or Daraz’s internal file transfers.
1. File Transfer Protocol (FTP)
FTP is a client-server protocol (port 20/21) for transferring files between systems. It uses two channels:
- Command channel (port 21): Sends commands (e.g.,
USER,PASS,RETR). - Data channel (port 20): Transfers actual files.
1.1 FTP Modes: Active vs. Passive
FTP operates in two modes, differing in how the data connection is initiated:
| Feature | Active Mode | Passive Mode |
|---|---|---|
| Initiator | Client initiates data connection to server | Server initiates data connection to client |
| Firewall | Struggles with NAT/firewalls (server must open ports) | Works behind NAT/firewalls (client opens ports) |
| Security | Less secure (exposes server ports) | More secure (client-controlled ports) |
| Use Case | Legacy systems, internal networks | Modern networks, cloud transfers |
WORKED EXAMPLE: FTP in a University Lab Scenario: A student in TU’s Central Department of Computer Science needs to upload a 100 MB project file to a server in Pokhara University (across Nepal Telecom’s network).
- Active Mode:
- Client (student’s laptop) sends
PORTcommand to server, specifying its IP (192.168.1.100) and a random port (e.g.,54321). - Server opens port 20 and connects back to the client’s port 54321 (firewall may block this if not configured).
- Problem: If the student is behind NTC’s NAT, the server’s return connection fails.
- Client (student’s laptop) sends
- Passive Mode:
- Client sends
PASVcommand. - Server opens a random high port (e.g.,
60000) and tells the client to connect to it. - Client connects to
server_ip:60000, bypassing NAT issues. - Solution: Works seamlessly for remote transfers (e.g., submitting assignments to a cloud server).
- Client sends
1.2 FTP Commands & Workflow
Key FTP commands:
USER username # Login
PASS password # Authentication
RETR filename # Download file
STOR filename # Upload file
LIST # List directory contents
QUIT # End session
Mermaid Sequence Diagram: FTP Login & File Transfer
sequenceDiagram
Client->>Server: USER student (port 21)
Server-->>Client: 331 Password required
Client->>Server: PASS ******
Server-->>Client: 230 Login successful
Client->>Server: RETR project.zip
Server->>Client: Opens data channel (port 20/21) and sends file
Client-->>Server: 226 Transfer complete1.3 Secure FTP (SFTP/FTPS)
| Protocol | Description | Ports | Security |
|---|---|---|---|
| SFTP | SSH File Transfer (encrypted tunnel) | 22 (SSH) | Strong (SSH keys) |
| FTPS | FTP over SSL/TLS | 990 (explicit) | Medium (certificates) |
| FTP | Plaintext (unencrypted) | 20/21 | Weak (passwords in cleartext) |
REAL-WORLD: SFTP in Nepal’s Banking Sector
- Nepal Rastra Bank (NRB) uses SFTP to securely transfer daily transaction reports between branches and the central server.
- Why SFTP?
- Encrypts data in transit (prevents MITM attacks).
- Uses SSH keys (no password brute-force risks).
- Compatible with legacy banking systems.
2. File Servers: NFS vs. Samba
File servers allow shared access to files across a network. Two dominant protocols:
2.1 Network File System (NFS)
- Developed by: Sun Microsystems (1980s).
- OS Support: Primarily Linux/Unix.
- Port: 2049 (UDP/TCP).
- How it Works:
- Client mounts a remote directory (e.g.,
/mnt/server_share). - All file operations (read/write) are handled by the NFS server.
- Uses Remote Procedure Calls (RPC) for communication.
- Client mounts a remote directory (e.g.,
Mermaid Class Diagram: NFS Architecture
classDiagram
class Client {
+mount(server:ip, path)
+read/write(file)
}
class NFS_Server {
+export(path, permissions)
+handle_requests()
}
class RPC {
+call(procedure, args)
}
Client --> RPC : Uses RPC
RPC --> NFS_Server : Calls proceduresWORKED EXAMPLE: NFS in Tribhuvan University
- Scenario: TU’s Central Library hosts a 1 TB digital repository of research papers.
- Setup:
- Server: Linux machine with
/data/libraryexported via NFS. - Client: Faculty laptops mount
/data/libraryas/mnt/tu_library.
- Server: Linux machine with
- Commands:
# Server: Export directory echo "/data/library *(rw,sync,no_subtree_check)" >> /etc/exports exportfs -a # Client: Mount mount -t nfs server_ip:/data/library /mnt/tu_library - Advantages:
- High performance (low latency for Unix-like systems).
- No per-user authentication (relies on OS-level permissions).
2.2 Samba (SMB/CIFS)
- Developed by: Microsoft (SMB) / Samba Team (CIFS).
- OS Support: Windows, Linux (via Samba daemon).
- Port: 445 (SMB).
- How it Works:
- Uses Server Message Block (SMB) protocol.
- Supports user-level authentication (Windows AD integration).
- Works over NetBIOS (137-139) or TCP/IP (445).
Comparison Table: NFS vs. Samba
| Feature | NFS | Samba (SMB) |
|---|---|---|
| Primary OS | Linux/Unix | Windows/Linux (Samba) |
| Authentication | OS-level (UID/GID) | User/password (Windows AD) |
| Performance | Faster for Unix clients | Better for Windows clients |
| Security | RPC-based (vulnerable to attacks) | SMB signing, encryption |
| Use Case | Linux clusters, HPC | Mixed Windows/Linux networks |
REAL-WORLD: Samba in Nepal’s E-Commerce
- Daraz Nepal uses Samba to share product catalogs between:
- Web servers (hosting
daraz.com.np). - Inventory databases (stored in Windows SQL Server).
- Web servers (hosting
- Why Samba?
- Seamless integration with Windows-based ERP systems.
- Supports ACLs (Access Control Lists) for fine-grained permissions.
3. Print Servers: CUPS & LPD
Print servers manage printer queues, allowing multiple users to send jobs to shared printers.
3.1 Common Unix Printing System (CUPS)
- Port: 631 (IPP protocol).
- Architecture:
flowchart TD A["Client (Browser/Application)"] -->|"IPP Job"| B["CUPS Scheduler"] B --> C["CUPS Filter"] C --> D["Printer Driver"] D --> E["Physical Printer"]
- Key Commands:
lpstat -a # Check printer status cancel 123 # Cancel job ID 123 lpadmin -p printer_name -v /dev/usb/lp0 # Add printer
WORKED EXAMPLE: CUPS in Kathmandu University
- Scenario: A departmental printer in KU’s Computer Science building is shared by 50 students.
- Setup:
- Admin configures CUPS on a Linux server:
lpadmin -p ku_printer -E -v parallel:/dev/usb/lp0 -m foo.ppd - Students submit jobs via:
lp -d ku_printer assignment.pdf
- Admin configures CUPS on a Linux server:
- Common Issues & Fixes:
Issue Cause Solution Printer offline Paper jam or disconnected cable Check physical connections "Access denied" Wrong permissions lpadmin -p printer -u allow:allSlow printing High queue load Prioritize jobs with lp -o priority=50
3.2 Line Printer Daemon (LPD)
- Legacy protocol (still used in some Unix systems).
- Port: 515 (LPD), 721 (LPRng).
- Commands:
lpr file.txt # Send print job lpq # Check queue lprm job_id # Remove job
Comparison: CUPS vs. LPD
| Feature | CUPS | LPD |
|---|---|---|
| Protocol | IPP (modern) | LPR (legacy) |
| Port | 631 | 515 |
| GUI | Web interface (http://localhost:631) |
CLI-only |
| Security | Built-in authentication | Weak (relies on OS permissions) |
REAL-WORLD: Print Servers in Nepal Telecom (NTC)
- NTC’s billing department uses a CUPS-based print server to:
- Generate monthly phone bills (PDFs) for 10,000 customers.
- Route jobs to high-speed printers in bulk.
- Why CUPS?
- Centralized logging (
/var/log/cups/). - IPP supports IPv6 (future-proof for NTC’s network upgrades).
- Centralized logging (
4. Security Best Practices
4.1 FTP Security
- Avoid plain FTP: Use SFTP (SSH) or FTPS (TLS).
- Chroot jail: Restrict users to their home directories.
- Disable anonymous login:
anonymous_enable=NO # In vsftpd.conf - Firewall rules:
iptables -A INPUT -p tcp --dport 21 -j ACCEPT iptables -A INPUT -p tcp --dport 20 -j DROP # Block active mode
4.2 File Server Security
- NFS:
- Use
no_root_squashcautiously (root access risks). - Restrict exports to trusted subnets:
echo "/data *(rw,root_squash,subnet=192.168.1.0/24)" >> /etc/exports
- Use
- Samba:
- Enable SMB signing:
[global] smb encrypt = required - Use AD integration for centralized authentication.
- Enable SMB signing:
4.3 Print Server Security
- Disable unnecessary ports:
cupsd -d (debug mode) → Check listening ports - Restrict access:
lpadmin -p printer_name -o auth-info-required=yes - Audit logs:
tail -f /var/log/cups/error_log
In the Real World
eSewa & Khalti (Digital Payments)
- FTP/SFTP: Used internally to transfer transaction logs between eSewa’s servers and Nepal Rastra Bank’s auditing systems.
- Why? Secure, encrypted transfers of sensitive financial data.
Daraz Nepal (E-Commerce)
- Samba: Shares product images and inventory data between Windows-based ERP systems and Linux web servers.
- Print Server: CUPS manages shipping labels printed in bulk for Kathmandu warehouses.
Nepal Stock Exchange (NEPSE)
- NFS: Hosts real-time stock data for brokers across Nepal, ensuring low-latency access.
- Security: Data encrypted in transit (TLS) and access restricted via IP whitelisting.
Exam Tip
This unit is heavily practical in exams. Expect:
- Configuration questions:
- Write
vsftpd.conffor passive FTP with TLS. - Configure Samba shares with read-only permissions.
- Write
- Troubleshooting:
- Debug a printer offline issue (check CUPS logs, cable, permissions).
- Fix an NFS mount failure (verify
rpcbind,/etc/exports).
- Scenario-based:
- "A bank uses FTP to transfer reports. Why is passive mode preferred over active?"
- "How would you secure a Samba share for a university’s student files?"
- Diagrams:
- Draw FTP active/passive data flow.
- Sketch a CUPS architecture with clients, scheduler, and printer.
- Short-answer:
- Define chroot in FTP.
- Compare NFS vs. Samba in one sentence.
Common Pitfalls:
- Forgetting firewall rules for passive FTP (port 21 + dynamic ports).
- Misconfiguring Samba permissions (e.g.,
guest ok = yesin production). - Ignoring TLS for FTP (exams may ask for FTPS/SFTP setup).
Based on the TU BSc CSIT syllabus for Network and System Administration, unit 7.
Discussion
Loading…