<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ftp server in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ftp-server/m-p/7791#M5745</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can't make active ftp working.&lt;/P&gt;&lt;P&gt;My ftp server is internal server (IP is public).&lt;/P&gt;&lt;P&gt;My policy accept ftp application on default ftp application in inboud (Internert -&amp;gt; ftp server).&lt;/P&gt;&lt;P&gt;How to make active session works ? Passive works fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;Franck.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 12 Apr 2012 09:32:57 GMT</pubDate>
    <dc:creator>franck.lichnowski</dc:creator>
    <dc:date>2012-04-12T09:32:57Z</dc:date>
    <item>
      <title>ftp server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ftp-server/m-p/7791#M5745</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can't make active ftp working.&lt;/P&gt;&lt;P&gt;My ftp server is internal server (IP is public).&lt;/P&gt;&lt;P&gt;My policy accept ftp application on default ftp application in inboud (Internert -&amp;gt; ftp server).&lt;/P&gt;&lt;P&gt;How to make active session works ? Passive works fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;Franck.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Apr 2012 09:32:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ftp-server/m-p/7791#M5745</guid>
      <dc:creator>franck.lichnowski</dc:creator>
      <dc:date>2012-04-12T09:32:57Z</dc:date>
    </item>
    <item>
      <title>Re: ftp server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ftp-server/m-p/7792#M5746</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Franck,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please open a case with Support so that we can review your config and troubleshoot further.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Sri&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Apr 2012 23:06:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ftp-server/m-p/7792#M5746</guid>
      <dc:creator>zarina</dc:creator>
      <dc:date>2012-04-16T23:06:12Z</dc:date>
    </item>
    <item>
      <title>Re: ftp server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ftp-server/m-p/7793#M5747</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you have a corresponding NAT rule for that incoming traffic ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Apr 2012 10:54:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ftp-server/m-p/7793#M5747</guid>
      <dc:creator>dieter_b</dc:creator>
      <dc:date>2012-04-18T10:54:38Z</dc:date>
    </item>
    <item>
      <title>Re: ftp server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ftp-server/m-p/7794#M5748</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Frank,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;As said before, please confirm if there is appropriate NAT rule configured for FTP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Similar to the following should be the security rule:- &lt;/P&gt;&lt;P&gt;Security Rule :-FTP-rule-Inbound&lt;/P&gt;&lt;P&gt;Source Zone:-&amp;nbsp; untrust (Outside zone)&lt;/P&gt;&lt;P&gt;Destination Zone:- trust&amp;nbsp; (inside zone)&lt;/P&gt;&lt;P&gt;Source Address:- any&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;Destination Address:-64,123,23,20&amp;nbsp; (Public Ip of FTP Sever)&lt;/P&gt;&lt;P&gt;Application: FTP&lt;/P&gt;&lt;P&gt;Action:- Allow&lt;/P&gt;&lt;P&gt;ATTACHMENT:- FTP-rule.PNG&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For incoming connection, what we call Destination NAT should be applied:-&lt;BR /&gt;It should look something like the following:-&lt;/P&gt;&lt;P&gt;NAT Rule:- FTP-inbound&lt;/P&gt;&lt;P&gt;Source Zone : Untrust&amp;nbsp; (Outside zone)&lt;/P&gt;&lt;P&gt;Desination Zone:- Untrust (Outside zone)&lt;/P&gt;&lt;P&gt;Source Address: Any&lt;/P&gt;&lt;P&gt;Destination Address:64,123,23,20&amp;nbsp; (Public Ip of FTP Sever)&lt;/P&gt;&lt;P&gt;Source Translation: None&lt;/P&gt;&lt;P&gt;Destination Translation:- 192.168.10.10 (Internal Ip of FTP Server)&lt;BR /&gt;ATTACHMENT:- NAT-inbound.PNG&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Parth&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 22 Apr 2012 00:59:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ftp-server/m-p/7794#M5748</guid>
      <dc:creator>ppatel</dc:creator>
      <dc:date>2012-04-22T00:59:04Z</dc:date>
    </item>
    <item>
      <title>Re: ftp server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ftp-server/m-p/7795#M5749</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Parth,&lt;BR /&gt; &lt;BR /&gt; thanks for the reply.&lt;BR /&gt; NAT is not active. All my IP are publics, no internal private IP.&lt;BR /&gt; &lt;BR /&gt; My rules is like this :&lt;BR /&gt; &lt;BR /&gt; &lt;SPAN style="color: #3333ff;"&gt;Security Rule : ftp-in&lt;BR /&gt; Source Zone:-&amp;nbsp; untrust (Outside zone)&lt;BR /&gt; Source Address:- any&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt; Destination Zone:- DR-LAN&amp;nbsp; (inside zone)&lt;BR /&gt; Destination Address:&amp;nbsp; 194.57.xxx.xxx (Public Ip of FTP Sever)&lt;BR /&gt; Application: FTP (application default)&lt;BR /&gt; Action:- Allow&lt;/SPAN&gt;&lt;BR /&gt; &lt;BR /&gt; With this only passive connexion works. Active not. I don't know why.&lt;BR /&gt; I 'am on PANoS 4.0.10&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I log all connexions, I never see any connexion in active : my server from port 20 to client (1024 - 65535).&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;With my old networks infrastructure (extreme networks) active works fine, so my server's configuration is fine.&lt;/P&gt;&lt;P&gt;May be it's because I let application ftp (service) with default ports (21) ?? May be I must set service on "any" ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Apr 2012 08:05:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ftp-server/m-p/7795#M5749</guid>
      <dc:creator>franck.lichnowski</dc:creator>
      <dc:date>2012-04-23T08:05:31Z</dc:date>
    </item>
    <item>
      <title>Re: ftp server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ftp-server/m-p/7796#M5750</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You should still see the blocked flows in your traffic log.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make sure that you in the end of your security rules manually setup one such as:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;srczone: any&lt;/P&gt;&lt;P&gt;dstzone: any&lt;/P&gt;&lt;P&gt;srcip: any&lt;/P&gt;&lt;P&gt;dstip: any&lt;/P&gt;&lt;P&gt;user: any&lt;/P&gt;&lt;P&gt;application: any&lt;/P&gt;&lt;P&gt;action: deny&lt;/P&gt;&lt;P&gt;options: log on session start, log on session end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should now see how your PA identifies the outgoing traffic from your FTP server (regarding active connection) in case this isnt matched to the ongoing incoming session.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For default deny in the bottom log on session start is the natural option for me (since the traffic is denied), however use also on session end for debugging since this will also include trafficvolume and identified application.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Apr 2012 08:12:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ftp-server/m-p/7796#M5750</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-04-23T08:12:20Z</dc:date>
    </item>
    <item>
      <title>Re: ftp server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ftp-server/m-p/7797#M5751</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;omg,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the problem came from another network switch (Extreme Networks X650) in head of PA 4020.&lt;/P&gt;&lt;P&gt;The problem is come form this rule :&lt;/P&gt;&lt;P&gt;enable ip-security anomaly-protection tcp flags&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for all replies.&lt;/P&gt;&lt;P&gt;Active now works with :&lt;/P&gt;&lt;P&gt;application : ftp&lt;/P&gt;&lt;P&gt;service : application default&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Franck.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Apr 2012 08:33:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ftp-server/m-p/7797#M5751</guid>
      <dc:creator>franck.lichnowski</dc:creator>
      <dc:date>2012-04-23T08:33:03Z</dc:date>
    </item>
  </channel>
</rss>

