<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Enable FTP and FTPS for Active/Passive? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/enable-ftp-and-ftps-for-active-passive/m-p/347803#M86665</link>
    <description>&lt;P&gt;Creating the application override for the FTPS works for me.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!!!&lt;/P&gt;</description>
    <pubDate>Wed, 09 Sep 2020 06:11:42 GMT</pubDate>
    <dc:creator>AnthonyChanTBPH</dc:creator>
    <dc:date>2020-09-09T06:11:42Z</dc:date>
    <item>
      <title>Enable FTP and FTPS for Active/Passive?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/enable-ftp-and-ftps-for-active-passive/m-p/219002#M63272</link>
      <description>&lt;P&gt;Hello Folks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a CrushFTP server installed on a server behind our PA 3020 PANOS: 7.1.14, SSL decrypt not enabled.&lt;/P&gt;&lt;P&gt;Security Rule:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="FTP_rule.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/15594i7008FC77FDA68739/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="FTP_rule.jpg" alt="FTP_rule.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;NAT Rule:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="FTP_NAT_rule.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/15595iE04873AF910C04C8/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="FTP_NAT_rule.jpg" alt="FTP_NAT_rule.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Trying to figure out why Active and Passive with FTP over TLS (SSL) will not retrieve the directory listing and will not complete connection.&amp;nbsp; Works fine with just FTP (insecure).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do I need to add SSL to the security rule?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Filezilla client set to Active - FTP Only (Insecure) - Why do I not see the data transfer port 20 when I upload a file?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Active_FTP.jpg" style="width: 797px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/15600i8AC9C654255CB511/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Active_FTP.jpg" alt="Active_FTP.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Filezilla Client set to Active - FTP over TLS&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Active_FTPS.jpg" style="width: 797px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/15601i6289E88DB9BE8625/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Active_FTPS.jpg" alt="Active_FTPS.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Filezilla client set to Passive - FTP Only (Insecure)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Passive_FTP.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/15602i50C12C27F47D6E25/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Passive_FTP.jpg" alt="Passive_FTP.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Filezilla client set to Passive - FTP over TLS (SSL) - Does this mean that FTPS is detected as SSL and discarded because not added to the security rule?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Passive_FTPS.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/15603i5D988D33341153D8/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Passive_FTPS.jpg" alt="Passive_FTPS.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For reference:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Allow-FTPS-FTPES-Traffic-Through-the-Firewall/ta-p/55425" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Allow-FTPS-FTPES-Traffic-Through-the-Firewall/ta-p/55425&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Create-an-Application-Override-for-FTP/ta-p/58420" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Create-an-Application-Override-for-FTP/ta-p/58420&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jun 2018 15:37:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/enable-ftp-and-ftps-for-active-passive/m-p/219002#M63272</guid>
      <dc:creator>OMatlock</dc:creator>
      <dc:date>2018-06-25T15:37:27Z</dc:date>
    </item>
    <item>
      <title>Re: Enable FTP and FTPS for Active/Passive?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/enable-ftp-and-ftps-for-active-passive/m-p/219430#M63371</link>
      <description>&lt;P&gt;No response so far.&amp;nbsp; I will close this thread by the end of the week.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jun 2018 11:42:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/enable-ftp-and-ftps-for-active-passive/m-p/219430#M63371</guid>
      <dc:creator>OMatlock</dc:creator>
      <dc:date>2018-06-27T11:42:10Z</dc:date>
    </item>
    <item>
      <title>Re: Enable FTP and FTPS for Active/Passive?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/enable-ftp-and-ftps-for-active-passive/m-p/219508#M63385</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/56398"&gt;@OMatlock&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;You need SSL included in the policy if you are using FTPS and you aren't going to be decrypting the traffic. I suspect that the reason that you really haven't gotten any response is nobody here is using CrushFTP and therefore can't tell you which applications will actually be identified.&amp;nbsp;&lt;/P&gt;&lt;P&gt;It really sounds like what you need to do is actually see what the firewall is identifying the traffic and allow what it can see. Most of the traffic will likely actually identify as 'ssl' and be spread across whatever ports your FTPS server is actually using. You can see this easily if you temporarily build out an 'allow all' policy with one specific allowed testing IP and actually perfrom an upload and a download while logging the transactions.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just as an FYI the current Security Policy that you have specified really isn't that great since it has to allow a small amount of data to determine the application across all ports. I would verify which applications are actually coming across and then specify that application [ x y z ] can use services [ service-https&amp;nbsp;&lt;EM&gt;whateverelse &lt;/EM&gt;] as you now have a much smaller threat vector.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jun 2018 15:39:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/enable-ftp-and-ftps-for-active-passive/m-p/219508#M63385</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-06-27T15:39:42Z</dc:date>
    </item>
    <item>
      <title>Re: Enable FTP and FTPS for Active/Passive?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/enable-ftp-and-ftps-for-active-passive/m-p/219513#M63388</link>
      <description>&lt;P&gt;We changed over to SFTP rather than FTPS and are much happier. The issue we had with FTPS is the random ports that are used were causing us issues.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jun 2018 15:42:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/enable-ftp-and-ftps-for-active-passive/m-p/219513#M63388</guid>
      <dc:creator>dstjames</dc:creator>
      <dc:date>2018-06-27T15:42:57Z</dc:date>
    </item>
    <item>
      <title>Re: Enable FTP and FTPS for Active/Passive?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/enable-ftp-and-ftps-for-active-passive/m-p/219556#M63398</link>
      <description>&lt;P&gt;Thank you for the feedback!&lt;/P&gt;&lt;P&gt;Good advice about allow all and see the applications used in the traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After that could narrow the rule to ftp and ssl (and or if other).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Will update.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jun 2018 21:58:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/enable-ftp-and-ftps-for-active-passive/m-p/219556#M63398</guid>
      <dc:creator>OMatlock</dc:creator>
      <dc:date>2018-06-27T21:58:23Z</dc:date>
    </item>
    <item>
      <title>Re: Enable FTP and FTPS for Active/Passive?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/enable-ftp-and-ftps-for-active-passive/m-p/347803#M86665</link>
      <description>&lt;P&gt;Creating the application override for the FTPS works for me.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!!!&lt;/P&gt;</description>
      <pubDate>Wed, 09 Sep 2020 06:11:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/enable-ftp-and-ftps-for-active-passive/m-p/347803#M86665</guid>
      <dc:creator>AnthonyChanTBPH</dc:creator>
      <dc:date>2020-09-09T06:11:42Z</dc:date>
    </item>
  </channel>
</rss>

