- Posts: 1
- Thank you received: 0
Checkoint Firewall and FTPS /SFTP
- CaptainSOS
- Topic Author
- Offline
- New Member
Less
More
19 years 2 months ago #10174
by CaptainSOS
Checkoint Firewall and FTPS /SFTP was created by CaptainSOS
I am having an issue when configuring FTPS running on a Windows server that using Serv-U ftp server. The issue is when I place a port into the configuration, say in the case the port is TCP 115. I am unable to connect to the FTP session. Regular ftp works fine. I am using a Checkpoint firewall with AI. The rule base shows ftp is allowed as well as SFTP (TCP port 115). Any thoughts why I get an error that basically states that the inital configuration is being allowed and then dropped. I suspect that I needed to also supply the port ranges for data. Thanks.
CAPSOS
CAPSOS
19 years 2 months ago #10199
by TheBishop
You might be right. 'Normal' FTP uses two ports, one for control and another for the data. Try to find out the second port your application uses and open that too. Or two alternative methods would be
1) Stick in a temporary rule that does "pass all and log", run your FTP then examine the logs
2) Leave the firewall rules as they are but do a packet capture on your attempted FTP. Examine the trace to see what ports are used
1) Stick in a temporary rule that does "pass all and log", run your FTP then examine the logs
2) Leave the firewall rules as they are but do a packet capture on your attempted FTP. Examine the trace to see what ports are used
19 years 2 months ago #10201
by TheBishop
Replied by TheBishop on topic Duplicate Post
This is a duplicate post with two sets of answers running. Perhaps one of our illustrious moderators would merge them? Thanks guys
- jimmyhoward
- Offline
- New Member
Less
More
- Posts: 1
- Thank you received: 0
19 years 2 days ago #11591
by jimmyhoward
Replied by jimmyhoward on topic Any luck with this one?
I am experiencing the same thing.
Did you guys have any resolution here? Hopefully?
Cheers,
Jimmy
Did you guys have any resolution here? Hopefully?
Cheers,
Jimmy
19 years 1 day ago #11634
by nske
Replied by nske on topic Re: Checkoint Firewall and FTPS /SFTP
Sorry for the pause, in case TheBishop wonders why the duplicate threads were not merged as he had correctly pointed out, it's because that is not technically possible through the forum script. So everyone please avoid opening duplicate topics! thanks
Time to create page: 0.141 seconds