<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Guide to FTPS? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/guide-to-ftps/m-p/217391#M62891</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71756"&gt;@RobinClayton&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Like what you have to enable on the firewall to get the traffic to be allowed through or what exactly are you looking for?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Jun 2018 18:20:00 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2018-06-11T18:20:00Z</dc:date>
    <item>
      <title>Guide to FTPS?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/guide-to-ftps/m-p/217357#M62881</link>
      <description>&lt;P&gt;One of our partners is switching it's service to FTPS,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone know of a decent guide on implementing FTPS? I saw a brife article by "&lt;SPAN class="lia-link-navigation lia-page-link lia-link-disabled lia-user-name-link"&gt;&lt;SPAN&gt;sdurga" but it's not very detailed.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="lia-link-navigation lia-page-link lia-link-disabled lia-user-name-link"&gt;&lt;SPAN&gt;We don't presently do any SSL decryption so unsure of what we need to do and what effect it may have on other parts of the system???&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="lia-link-navigation lia-page-link lia-link-disabled lia-user-name-link"&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="lia-link-navigation lia-page-link lia-link-disabled lia-user-name-link"&gt;&lt;SPAN&gt;Robin&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jun 2018 13:53:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/guide-to-ftps/m-p/217357#M62881</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2018-06-11T13:53:49Z</dc:date>
    </item>
    <item>
      <title>Re: Guide to FTPS?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/guide-to-ftps/m-p/217391#M62891</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71756"&gt;@RobinClayton&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Like what you have to enable on the firewall to get the traffic to be allowed through or what exactly are you looking for?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jun 2018 18:20:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/guide-to-ftps/m-p/217391#M62891</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-06-11T18:20:00Z</dc:date>
    </item>
    <item>
      <title>Re: Guide to FTPS?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/guide-to-ftps/m-p/217487#M62910</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is the only information I have found,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Allow-FTPS-FTPES-Traffic-Through-the-Firewall/ta-p/55425" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Allow-FTPS-FTPES-Traffic-Through-the-Firewall/ta-p/55425&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We don't presently have any SSL decryption so I am workign out how to get a trusted CERT workign first,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But would the rule need applciations FTP/SSL , it's unclear from the above post?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jun 2018 07:58:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/guide-to-ftps/m-p/217487#M62910</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2018-06-12T07:58:38Z</dc:date>
    </item>
    <item>
      <title>Re: Guide to FTPS?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/guide-to-ftps/m-p/217495#M62915</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FTPS is basically FTP over SSL layer (do not confuse with SFTP), which means that since you enable SSL decryption you should see application "FTP". When you don't enable SSL decryption you will see application "SSL".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just be carefull as often, FTPS service are running on exotic ports (I have many in my environment on port 90x or 120x it depends of the provider. In this case be sure to disable "default application" in the service tab (and use particular service or "any")&amp;nbsp; otherwise your FW wil drop the traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jun 2018 09:07:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/guide-to-ftps/m-p/217495#M62915</guid>
      <dc:creator>Laurent_Dormond</dc:creator>
      <dc:date>2018-06-12T09:07:02Z</dc:date>
    </item>
    <item>
      <title>Re: Guide to FTPS?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/guide-to-ftps/m-p/217507#M62921</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71756"&gt;@RobinClayton&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;As&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/46085"&gt;@Laurent_Dormond&lt;/a&gt;&amp;nbsp;pointed out this traffic really isn't any different than any other application that you would have to allow through the firewall.&amp;nbsp;You'll simply need to identify the ports that this server is going to use and allow the identified applications on that range of ports. More that likley the only app-id that the firewall will see is going to be 'ssl' unless you start decrypting the traffic moving forward.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jun 2018 12:44:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/guide-to-ftps/m-p/217507#M62921</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-06-12T12:44:58Z</dc:date>
    </item>
    <item>
      <title>Re: Guide to FTPS?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/guide-to-ftps/m-p/218335#M63118</link>
      <description>&lt;P&gt;So initialy then,&amp;nbsp; I will just enable SSL from the source to the destiantion on the expected port.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Perhaps in future once tested and working we would move to SSL Decryption and inspect the application inside the tunnel.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jun 2018 08:28:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/guide-to-ftps/m-p/218335#M63118</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2018-06-19T08:28:18Z</dc:date>
    </item>
    <item>
      <title>Re: Guide to FTPS?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/guide-to-ftps/m-p/218362#M63126</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71756"&gt;@RobinClayton&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Right. You would just have a policy similar to something like&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;set rulebase security rules "Allow FTPS" from untrust to dmz source any destination FTPS-Server application ssl service [ FTPS service-https ] action allow log-end yes&lt;/PRE&gt;&lt;P&gt;Note that in this example I have an address object 'FTPS-Server' that ties to the destination address of the FTPS server that you would be using, and I've created a service object 'FTPS' that maps to tcp-990. You likely wouldn't want to actually allow a source 'any' in this policy and you would likely want to assign some security profile or security group to this.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jun 2018 15:16:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/guide-to-ftps/m-p/218362#M63126</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-06-19T15:16:15Z</dc:date>
    </item>
  </channel>
</rss>

