<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FTP question in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ftp-question/m-p/6229#M4544</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have a new rule for this testing configured as follows:&lt;/P&gt;&lt;P&gt;Source Zone: Untrust&lt;BR /&gt;Source Address: Any&lt;BR /&gt;Source User: Any&lt;/P&gt;&lt;P&gt;Destination Zone: Trust&lt;BR /&gt;Destination Address: My FTP's Nat Address&lt;BR /&gt;&lt;BR /&gt;Application: Any&lt;BR /&gt;Service(s): &lt;BR /&gt;-Custom FTP(port 31)&lt;BR /&gt;-Custom FTPS(port 990)&lt;BR /&gt;-Custom SFTP(port 32)&lt;BR /&gt;Service-HTTP&lt;BR /&gt;Service-HTTPS&lt;/P&gt;&lt;P&gt;Profiles: Only blocking for Virus' and Spyware.&amp;nbsp; Everything else open.&lt;BR /&gt;Sessions sent at END only.&lt;/P&gt;&lt;P&gt;I have a production Microsoft FTP server on the same server as the WING.&amp;nbsp; The MS FTP is only listening on port 21, hence the custom ports of 31/32.&amp;nbsp; The MS FTP works fine from both outside and inside the LAN.&lt;/P&gt;&lt;P&gt;There is a test Outbound rule for this server but I have never seen it used yet.&lt;/P&gt;&lt;P&gt;[See attached screenshot.]&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 27 Sep 2011 17:05:12 GMT</pubDate>
    <dc:creator>migration</dc:creator>
    <dc:date>2011-09-27T17:05:12Z</dc:date>
    <item>
      <title>FTP question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ftp-question/m-p/6227#M4542</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Greetings,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trialing a WING FTP server here at the office.&amp;nbsp; FTP and HTTPS work fine to the server from a FileZilla client.&amp;nbsp; I have an SSL certificate loaded onto the server for FTPS/HTTPS.&amp;nbsp; When I try to connect to the server via FTPS (port 990), the client connects but gets stuch at listing the directory contents.&amp;nbsp; The FileZilla client hangs at the command : MLSD.&amp;nbsp; Eventually, it times out.&lt;/P&gt;&lt;P&gt;I confirmed that FTPS works on my LAN so I am focusing on the firewall.&amp;nbsp; I do not see any Threat attempts that may have been dropped except for a few previous attempts at an SSH&amp;nbsp; (SFTP) connection I tried.&lt;/P&gt;&lt;P&gt;Any thoughts?&lt;/P&gt;&lt;P&gt;P.S.&amp;gt; an SSH connection works to this server from the outside,as well.&amp;nbsp; So it looks like the only issue is with FTP over SSL.&lt;/P&gt;&lt;P&gt;Thanks, Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Sep 2011 19:36:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ftp-question/m-p/6227#M4542</guid>
      <dc:creator>migration</dc:creator>
      <dc:date>2011-09-26T19:36:20Z</dc:date>
    </item>
    <item>
      <title>Re: FTP question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ftp-question/m-p/6228#M4543</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;May I know how you apply your policy for SSH traffic to your server? Have you tried to allow SSH traffic to and from your SFTP server?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jones&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Sep 2011 16:22:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ftp-question/m-p/6228#M4543</guid>
      <dc:creator>jleung</dc:creator>
      <dc:date>2011-09-27T16:22:25Z</dc:date>
    </item>
    <item>
      <title>Re: FTP question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ftp-question/m-p/6229#M4544</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have a new rule for this testing configured as follows:&lt;/P&gt;&lt;P&gt;Source Zone: Untrust&lt;BR /&gt;Source Address: Any&lt;BR /&gt;Source User: Any&lt;/P&gt;&lt;P&gt;Destination Zone: Trust&lt;BR /&gt;Destination Address: My FTP's Nat Address&lt;BR /&gt;&lt;BR /&gt;Application: Any&lt;BR /&gt;Service(s): &lt;BR /&gt;-Custom FTP(port 31)&lt;BR /&gt;-Custom FTPS(port 990)&lt;BR /&gt;-Custom SFTP(port 32)&lt;BR /&gt;Service-HTTP&lt;BR /&gt;Service-HTTPS&lt;/P&gt;&lt;P&gt;Profiles: Only blocking for Virus' and Spyware.&amp;nbsp; Everything else open.&lt;BR /&gt;Sessions sent at END only.&lt;/P&gt;&lt;P&gt;I have a production Microsoft FTP server on the same server as the WING.&amp;nbsp; The MS FTP is only listening on port 21, hence the custom ports of 31/32.&amp;nbsp; The MS FTP works fine from both outside and inside the LAN.&lt;/P&gt;&lt;P&gt;There is a test Outbound rule for this server but I have never seen it used yet.&lt;/P&gt;&lt;P&gt;[See attached screenshot.]&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Sep 2011 17:05:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ftp-question/m-p/6229#M4544</guid>
      <dc:creator>migration</dc:creator>
      <dc:date>2011-09-27T17:05:12Z</dc:date>
    </item>
    <item>
      <title>Re: FTP question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ftp-question/m-p/6230#M4545</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;@mwaters31:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;are you seeing any drops in the traffic logs?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if not and since you are not seeing the traffic match your security rule I am going to assume that the implicit deny rule is dropping your traffic. This would mean that some of the parameters of the traffic do not conform with the security policy. I suggest performing a packet capture from the ftp client and server to determine where your security policy is not matching the actual traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Benjamin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Nov 2011 08:23:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ftp-question/m-p/6230#M4545</guid>
      <dc:creator>bpappas</dc:creator>
      <dc:date>2011-11-09T08:23:27Z</dc:date>
    </item>
    <item>
      <title>Re: FTP question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ftp-question/m-p/6231#M4546</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It actually ended up being a problem with the configuration of their server.&amp;nbsp; It works fine now.&amp;nbsp; Thanks for checking in.&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Nov 2011 15:54:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ftp-question/m-p/6231#M4546</guid>
      <dc:creator>migration</dc:creator>
      <dc:date>2011-11-09T15:54:55Z</dc:date>
    </item>
  </channel>
</rss>

