<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security policy rule - allowing a specific host access to ftp.sophos.com in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-allowing-a-specific-host-access-to-ftp/m-p/243489#M69615</link>
    <description>&lt;P&gt;Very important this is NOT sftp (which is a file transfer protocol using the same port and encryption as ssh). We are talking about ftp over ssl.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;this is explicit ftp over ssl. Meaning the client wil use ftp to connect to ftp.sophos.com and than do TLS encryption and than with an encrypted connection it will do authentication and negotation which ports to use for the data connection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;fom&amp;nbsp;&lt;A href="https://community.sophos.com/kb/en-us/113454" target="_blank"&gt;https://community.sophos.com/kb/en-us/113454&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you will need to allow the application: ftp to connect to tcp port 990 for ftp.sophos.com.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;after that you will need to allow the application ssl with ports 50000-51000&lt;/P&gt;</description>
    <pubDate>Mon, 17 Dec 2018 13:32:34 GMT</pubDate>
    <dc:creator>Rikkert_Kooy</dc:creator>
    <dc:date>2018-12-17T13:32:34Z</dc:date>
    <item>
      <title>Security policy rule - allowing a specific host access to ftp.sophos.com</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-allowing-a-specific-host-access-to-ftp/m-p/242012#M69276</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A colleague needs to access ftp.sophos.com (195.171.192.29) using Filezilla as their SFTP client, via TCP port 990. I set up the security policy rule as follows:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Source.PNG" style="width: 626px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17784i1BC8AC93598B5BBE/image-dimensions/626x182/is-moderation-mode/true?v=v2" width="626" height="182" role="button" title="Source.PNG" alt="Source.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Destination.PNG" style="width: 626px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17785i7C687555118C6652/image-dimensions/626x214/is-moderation-mode/true?v=v2" width="626" height="214" role="button" title="Destination.PNG" alt="Destination.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Service.PNG" style="width: 624px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17786i39D5C4ECB733C627/image-dimensions/624x228/is-moderation-mode/true?v=v2" width="624" height="228" role="button" title="Service.PNG" alt="Service.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Actions.PNG" style="width: 627px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17787i7FBA9C7A30ADBE09/image-dimensions/627x266/is-moderation-mode/true?v=v2" width="627" height="266" role="button" title="Actions.PNG" alt="Actions.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;They could not log onto the ftp.sophos.com site. The password credentials they used are correct. Is the rule set up correctly? On a Cisco ASA I would have used the following ACL:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;access-list aclinside extended permit tcp any host 195.171.192.29 eq 990&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any advice is much appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Roberto&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Dec 2018 11:12:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-allowing-a-specific-host-access-to-ftp/m-p/242012#M69276</guid>
      <dc:creator>rchung54</dc:creator>
      <dc:date>2018-12-04T11:12:52Z</dc:date>
    </item>
    <item>
      <title>Re: Security policy rule - allowing a specific host access to ftp.sophos.com</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-allowing-a-specific-host-access-to-ftp/m-p/242031#M69278</link>
      <description>Hi, as i can see at the last image you're using Profile Groups (in your case SPG_Outband). Have you also checked, that the "File Blocking Profile" for this group is set allowed / in alert mode? It may be that everything is blocked here.</description>
      <pubDate>Tue, 04 Dec 2018 13:27:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-allowing-a-specific-host-access-to-ftp/m-p/242031#M69278</guid>
      <dc:creator>Hodor</dc:creator>
      <dc:date>2018-12-04T13:27:15Z</dc:date>
    </item>
    <item>
      <title>Re: Security policy rule - allowing a specific host access to ftp.sophos.com</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-allowing-a-specific-host-access-to-ftp/m-p/242033#M69279</link>
      <description>&lt;P&gt;I've had to add the SSH application to many SFTP rules, as the firewall usually sees that. Look in your Unified Logs and it should show you why it was denied.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Dec 2018 13:39:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-allowing-a-specific-host-access-to-ftp/m-p/242033#M69279</guid>
      <dc:creator>DPoppleton</dc:creator>
      <dc:date>2018-12-04T13:39:50Z</dc:date>
    </item>
    <item>
      <title>Re: Security policy rule - allowing a specific host access to ftp.sophos.com</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-allowing-a-specific-host-access-to-ftp/m-p/242036#M69280</link>
      <description>&lt;P&gt;Hello Hodor,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your reply. The file blocking profile looks good.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="File block.PNG" style="width: 0px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17790i7ADFE94FBB38BB2D/image-size/small/is-moderation-mode/true?v=v2&amp;amp;px=200" width="0" height="0" role="button" title="File block.PNG" alt="File block.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="File block.PNG" style="width: 612px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17791i31B83CB54567137D/image-dimensions/612x213/is-moderation-mode/true?v=v2" width="612" height="213" role="button" title="File block.PNG" alt="File block.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Dec 2018 13:56:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-allowing-a-specific-host-access-to-ftp/m-p/242036#M69280</guid>
      <dc:creator>rchung54</dc:creator>
      <dc:date>2018-12-04T13:56:43Z</dc:date>
    </item>
    <item>
      <title>Re: Security policy rule - allowing a specific host access to ftp.sophos.com</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-allowing-a-specific-host-access-to-ftp/m-p/242039#M69282</link>
      <description>&lt;P&gt;Like&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/48237"&gt;@DPoppleton&lt;/a&gt;&amp;nbsp;mentioned what do the deny logs say is the reason for traffic being stopped?&amp;nbsp; What is the FW seeing?&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Dec 2018 14:21:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-allowing-a-specific-host-access-to-ftp/m-p/242039#M69282</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2018-12-04T14:21:32Z</dc:date>
    </item>
    <item>
      <title>Re: Security policy rule - allowing a specific host access to ftp.sophos.com</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-allowing-a-specific-host-access-to-ftp/m-p/242047#M69285</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/48237" target="_self"&gt;&lt;SPAN&gt;DPoppleton,&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I don't see any 'deny' in the Actions when the user is trying to access 195.171.192.29&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Unified log.PNG" style="width: 634px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17793i4CDD1B9943E186D6/image-dimensions/634x103/is-moderation-mode/true?v=v2" width="634" height="103" role="button" title="Unified log.PNG" alt="Unified log.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Dec 2018 14:49:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-allowing-a-specific-host-access-to-ftp/m-p/242047#M69285</guid>
      <dc:creator>rchung54</dc:creator>
      <dc:date>2018-12-04T14:49:52Z</dc:date>
    </item>
    <item>
      <title>Re: Security policy rule - allowing a specific host access to ftp.sophos.com</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-allowing-a-specific-host-access-to-ftp/m-p/242049#M69287</link>
      <description>&lt;P&gt;That screen shot shows the application as FTP, which means the FileZilla client isn't encrypting. The client may need to be set to use SFTP (and the firewall will see that as SSH, so you will need to add that application to your rule.)&lt;/P&gt;</description>
      <pubDate>Tue, 04 Dec 2018 14:57:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-allowing-a-specific-host-access-to-ftp/m-p/242049#M69287</guid>
      <dc:creator>DPoppleton</dc:creator>
      <dc:date>2018-12-04T14:57:30Z</dc:date>
    </item>
    <item>
      <title>Re: Security policy rule - allowing a specific host access to ftp.sophos.com</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-allowing-a-specific-host-access-to-ftp/m-p/242189#M69314</link>
      <description>&lt;P&gt;Hi DPoppleton,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your reply again. I have now added SSH under Application within my rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ssh.PNG" style="width: 764px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17804i1C892DE0289A377D/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="ssh.PNG" alt="ssh.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will have the user test.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Roberto&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Dec 2018 11:08:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-allowing-a-specific-host-access-to-ftp/m-p/242189#M69314</guid>
      <dc:creator>rchung54</dc:creator>
      <dc:date>2018-12-05T11:08:58Z</dc:date>
    </item>
    <item>
      <title>Re: Security policy rule - allowing a specific host access to ftp.sophos.com</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-allowing-a-specific-host-access-to-ftp/m-p/242190#M69315</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/48237"&gt;@DPoppleton&lt;/a&gt;, forgot to mention that the Filezilla client was configured for SFTP and was tested on a ADSL line and the user was able to connect fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Roberto&lt;/P&gt;</description>
      <pubDate>Wed, 05 Dec 2018 11:12:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-allowing-a-specific-host-access-to-ftp/m-p/242190#M69315</guid>
      <dc:creator>rchung54</dc:creator>
      <dc:date>2018-12-05T11:12:45Z</dc:date>
    </item>
    <item>
      <title>Re: Security policy rule - allowing a specific host access to ftp.sophos.com</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-allowing-a-specific-host-access-to-ftp/m-p/242508#M69366</link>
      <description>&lt;P&gt;Have you found a solution to this issue yet?&lt;/P&gt;</description>
      <pubDate>Fri, 07 Dec 2018 14:24:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-allowing-a-specific-host-access-to-ftp/m-p/242508#M69366</guid>
      <dc:creator>DPoppleton</dc:creator>
      <dc:date>2018-12-07T14:24:13Z</dc:date>
    </item>
    <item>
      <title>Re: Security policy rule - allowing a specific host access to ftp.sophos.com</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-allowing-a-specific-host-access-to-ftp/m-p/242826#M69439</link>
      <description>&lt;P&gt;Hi DPoppleton,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Still not working.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I get this from the log in the Filezila FTP client.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sophos error.PNG" style="width: 453px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17877i1B38E4E9B34CCF2F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="sophos error.PNG" alt="sophos error.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Filezila client configured as so for FTP over SSL/TLS&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Filezila config.PNG" style="width: 605px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17878i839443351FD8960F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Filezila config.PNG" alt="Filezila config.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Logs from Unified today.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Unified log.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17879i4FA239EEBDA2A9FF/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Unified log.PNG" alt="Unified log.PNG" /&gt;&lt;/span&gt;Any further advice will be appreciated.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Dec 2018 11:57:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-allowing-a-specific-host-access-to-ftp/m-p/242826#M69439</guid>
      <dc:creator>rchung54</dc:creator>
      <dc:date>2018-12-11T11:57:20Z</dc:date>
    </item>
    <item>
      <title>Re: Security policy rule - allowing a specific host access to ftp.sophos.com</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-allowing-a-specific-host-access-to-ftp/m-p/243229#M69560</link>
      <description>&lt;P&gt;This isn't caused by the firewall.... I seem to remember a problem with the MLSD command with certain clients or servers while running a passive FTP connection. Try it as an active connection and I think it would work.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Dec 2018 21:22:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-allowing-a-specific-host-access-to-ftp/m-p/243229#M69560</guid>
      <dc:creator>DPoppleton</dc:creator>
      <dc:date>2018-12-13T21:22:46Z</dc:date>
    </item>
    <item>
      <title>Re: Security policy rule - allowing a specific host access to ftp.sophos.com</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-allowing-a-specific-host-access-to-ftp/m-p/243430#M69605</link>
      <description>&lt;P&gt;Thanks for the info on&amp;nbsp;allowing a specific host access to ftp.sophos.com&amp;nbsp;&lt;A href="https://mindmajix.com/jira-training" target="_self"&gt;jira&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 16 Dec 2018 15:35:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-allowing-a-specific-host-access-to-ftp/m-p/243430#M69605</guid>
      <dc:creator>soujanyabargavi</dc:creator>
      <dc:date>2018-12-16T15:35:48Z</dc:date>
    </item>
    <item>
      <title>Re: Security policy rule - allowing a specific host access to ftp.sophos.com</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-allowing-a-specific-host-access-to-ftp/m-p/243489#M69615</link>
      <description>&lt;P&gt;Very important this is NOT sftp (which is a file transfer protocol using the same port and encryption as ssh). We are talking about ftp over ssl.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;this is explicit ftp over ssl. Meaning the client wil use ftp to connect to ftp.sophos.com and than do TLS encryption and than with an encrypted connection it will do authentication and negotation which ports to use for the data connection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;fom&amp;nbsp;&lt;A href="https://community.sophos.com/kb/en-us/113454" target="_blank"&gt;https://community.sophos.com/kb/en-us/113454&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you will need to allow the application: ftp to connect to tcp port 990 for ftp.sophos.com.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;after that you will need to allow the application ssl with ports 50000-51000&lt;/P&gt;</description>
      <pubDate>Mon, 17 Dec 2018 13:32:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-allowing-a-specific-host-access-to-ftp/m-p/243489#M69615</guid>
      <dc:creator>Rikkert_Kooy</dc:creator>
      <dc:date>2018-12-17T13:32:34Z</dc:date>
    </item>
    <item>
      <title>Re: Security policy rule - allowing a specific host access to ftp.sophos.com</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-allowing-a-specific-host-access-to-ftp/m-p/244010#M69683</link>
      <description>&lt;P&gt;Hi&amp;nbsp;Rikkert_Kooy,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your reply. My mistake, it is explicit FTP over SSL, not SFTP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have added ftp to the Application and already had TCP port 990 under the Service. I also added SSL and the port range 50000-51000, but it is still not working. The Palo is not configured for SSL decrypt/encrypt. Could this be why it is still not working?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sophos rule.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/18006iDE6713C7883C8788/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="sophos rule.PNG" alt="sophos rule.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unified logs - it says incomplete in Application. What does this mean please?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sophos error on palo.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/18009i08B95A1C6F786C23/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="sophos error on palo.PNG" alt="sophos error on palo.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Error message on the Filezilla client&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ftp client error.PNG" style="width: 636px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/18008iBE85882BA599F8DF/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="ftp client error.PNG" alt="ftp client error.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Dec 2018 12:03:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-allowing-a-specific-host-access-to-ftp/m-p/244010#M69683</guid>
      <dc:creator>rchung54</dc:creator>
      <dc:date>2018-12-20T12:03:50Z</dc:date>
    </item>
    <item>
      <title>Re: Security policy rule - allowing a specific host access to ftp.sophos.com</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-allowing-a-specific-host-access-to-ftp/m-p/244011#M69684</link>
      <description>&lt;P&gt;Hi DPoppleton,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I set the Transfer Settings to Active in the FTP client (I guess this what you meant), but still not working. I did what&amp;nbsp;Rikkert_Kooy suggested too and still no joy. Is it because the Palo is not configured with SSL decrypt/encrypt?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Dec 2018 12:17:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-allowing-a-specific-host-access-to-ftp/m-p/244011#M69684</guid>
      <dc:creator>rchung54</dc:creator>
      <dc:date>2018-12-20T12:17:09Z</dc:date>
    </item>
    <item>
      <title>Re: Security policy rule - allowing a specific host access to ftp.sophos.com</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-allowing-a-specific-host-access-to-ftp/m-p/244033#M69688</link>
      <description>&lt;P&gt;Hi rchung54,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;decrypting ssl traffic is not strictly needed to make this connection possible.&amp;nbsp;I have configured passive ftp with explicit ssl in this way before.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I see that your rule is being hit for the passive connection on port 50661 (your filezilla screenshot shows that the client is trying to connect to 195.171.192.29:50661 (197*156+227)), but your ftp client either says the connection has timed out or that the server denied the connection (were the three error messages at the same time?).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What does your Palo alto say is the reason for the session end reason?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Dec 2018 14:27:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-allowing-a-specific-host-access-to-ftp/m-p/244033#M69688</guid>
      <dc:creator>Rikkert_Kooy</dc:creator>
      <dc:date>2018-12-20T14:27:42Z</dc:date>
    </item>
    <item>
      <title>Re: Security policy rule - allowing a specific host access to ftp.sophos.com</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-allowing-a-specific-host-access-to-ftp/m-p/244036#M69690</link>
      <description>&lt;P&gt;Hi Rikkert_Kooy,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, i saw the three error messages at the same time on the Filezilla client.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Session End Reason is 'tcp-rst-from-server'.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Palo session end reason.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/18010i39CC9B3E0D68F1CB/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Palo session end reason.PNG" alt="Palo session end reason.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What does it mean where it says 'incomplete' under Application please?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Dec 2018 14:40:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-allowing-a-specific-host-access-to-ftp/m-p/244036#M69690</guid>
      <dc:creator>rchung54</dc:creator>
      <dc:date>2018-12-20T14:40:20Z</dc:date>
    </item>
    <item>
      <title>Re: Security policy rule - allowing a specific host access to ftp.sophos.com</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-allowing-a-specific-host-access-to-ftp/m-p/244041#M69692</link>
      <description>&lt;P&gt;incomplete means not enough packets have gone through the Palo Alto for it to recognise the application. So it doesn't know yet whether it is SSL (which the rule allows) or something else.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I read the session end reason it seems like the ftp.sophos.com causes the disconnect, but likely because the client was trying to connect to it for 20 seconds.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why your FTP client wasn't able to actually connect to the server in passive mode I do not understand.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Dec 2018 15:40:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-rule-allowing-a-specific-host-access-to-ftp/m-p/244041#M69692</guid>
      <dc:creator>Rikkert_Kooy</dc:creator>
      <dc:date>2018-12-20T15:40:30Z</dc:date>
    </item>
  </channel>
</rss>

