# Syncthing behind corporate firewall with cntlm

**URL:** https://forum.syncthing.net/t/syncthing-behind-corporate-firewall-with-cntlm/11489
**Category:** Support
**Created:** [April 18, 2018, 11:37am UTC](https://forum.syncthing.net/t/syncthing-behind-corporate-firewall-with-cntlm/11489 "2018-04-18T11:37:21Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![Kovacs\_Janos](https://forum.syncthing.net/letter_avatar_proxy/v4/letter/k/d2c977/32.png) [@Kovacs\_Janos](https://forum.syncthing.net/u/Kovacs_Janos)
#### Post date: [April 18, 2018, 11:37am UTC](https://forum.syncthing.net/t/syncthing-behind-corporate-firewall-with-cntlm/11489/1 "2018-04-18T11:37:21Z")

</div>

I use Syncthing via cntlm as socks proxy. Our firewall is very restrictive here, it only allows http and https outbound connections. Syncthing works perfectly. The only thing I’m worried about is the following messages in cntlm’s log:

```
Apr 18 13:31:51 arch-rf cntlm[545]: Request for CONNECT to 188.36.52.199:28607 denied!
Apr 18 13:33:01 arch-rf cntlm[545]: Request for CONNECT to 188.36.52.199:22000 denied!
Apr 18 13:33:11 arch-rf cntlm[545]: Request for CONNECT to 188.36.52.199:28607 denied!
Apr 18 13:33:25 arch-rf cntlm[545]: 127.0.0.1 SOCKS 195.201.94.137:443
Apr 18 13:34:21 arch-rf cntlm[545]: 127.0.0.1 SOCKS discovery.syncthing.net:443
Apr 18 13:34:21 arch-rf cntlm[545]: Request for CONNECT to 188.36.52.199:22000 denied!

```

How do I configure Syncthing so that those connections that are denied by the firewall will not even be initiated? I’m using the default configuration right now.

---

<div class="post-metadata">

### Author: ![AudriusButkevicius](https://forum.syncthing.net/user_avatar/forum.syncthing.net/audriusbutkevicius/32/277_2.png) [@AudriusButkevicius](https://forum.syncthing.net/u/AudriusButkevicius)
#### Post date: [April 18, 2018, 11:54am UTC](https://forum.syncthing.net/t/syncthing-behind-corporate-firewall-with-cntlm/11489/2 "2018-04-18T11:54:55Z")

</div>

You can’t as syncthing willtry all addresses advertised regardless of what your firewall allows.

---

<div class="post-metadata">

### Author: ![Kovacs\_Janos](https://forum.syncthing.net/letter_avatar_proxy/v4/letter/k/d2c977/32.png) [@Kovacs\_Janos](https://forum.syncthing.net/u/Kovacs_Janos)
#### Post date: [April 18, 2018, 12:28pm UTC](https://forum.syncthing.net/t/syncthing-behind-corporate-firewall-with-cntlm/11489/3 "2018-04-18T12:28:50Z")

</div>

That is a pity. Those addresses are advertised by whom? Maybe I can try something on cntlm.

---

<div class="post-metadata">

### Author: ![Tor](https://forum.syncthing.net/letter_avatar_proxy/v4/letter/t/ecccb3/32.png) [@Tor](https://forum.syncthing.net/u/Tor)
#### Post date: [April 18, 2018, 12:33pm UTC](https://forum.syncthing.net/t/syncthing-behind-corporate-firewall-with-cntlm/11489/4 "2018-04-18T12:33:06Z")

</div>

I suppose you could just block that (outgoing) port number in a local firewall on your syncthing host, if you just want to avoid creating noise in the corporate firewall logs.

---

<div class="post-metadata">

### Author: ![Kovacs\_Janos](https://forum.syncthing.net/letter_avatar_proxy/v4/letter/k/d2c977/32.png) [@Kovacs\_Janos](https://forum.syncthing.net/u/Kovacs_Janos)
#### Post date: [April 18, 2018, 12:34pm UTC](https://forum.syncthing.net/t/syncthing-behind-corporate-firewall-with-cntlm/11489/5 "2018-04-18T12:34:23Z")

</div>

Yes, that is the direction I will go then.

---

<div class="post-metadata">

### Author: ![system](https://forum-uploads.syncthingcdn.net/original/2X/0/0b50e0a202b22ae6a67190759e8c868805b8ed9f.png) [@system](https://forum.syncthing.net/u/system)
#### Post date: [May 18, 2018, 12:34pm UTC](https://forum.syncthing.net/t/syncthing-behind-corporate-firewall-with-cntlm/11489/6 "2018-05-18T12:34:46Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
