FTPS and Service - problem

cancel
Showing results for 
Search instead for 
Did you mean: 

FTPS and Service - problem

L4 Transporter

Hello

I have FTP server on Debian 7 (ProFTPD 1.3.1) and security rule:

2014-07-02_202605.png

and now FTPS connection works.

With "application-default" as a service FTPS sessions hangs on listing directory and sfter some time FTP client was disconected.

I'm on 6.0.2 PAN with latest updates.

Is this a normal behaviour? According to best practice we should use "application-default" as a service - but in this case we couldn't.

Please share Your opinion about that.

With regards

SLawek

20 REPLIES 20

Hello

Only one option related to ports is:

# Port 21 is the standard FTP port.

Port                            21

FTPS uses the same port as a FTP (look onto my screenshot) and above configurations. Applipedia dosn't have dedicated app because its a regular FTP tunneled in SSL (according to my knoweladge)

With regards

Slawek

In that case FTPS is SSL running on port 25, hence you must need any for it to work.

Hi ,

i think you are mixing up some thinks.

FTPS is FTP with TLS encryption and uses still standard Port 21

SFTP is secure copy over ssh Protocol which uses Port 22

I don't know why hshah is talking about Port 25

FTPS should work with app FTP and app-default (actually it does in my config)

You should start a flow debug to find out whats happening.

Regards

Marco

L4 Transporter

I have problem with FTPS I know what it is and differences between SFTP and FTPS http://en.wikipedia.org/wiki/FTPS

Regards

Slawek

Ok,

FTPS (with client Option explicit over TLS) should work with app FTP and App default.

You should start a flow debug to find out whats happening.

Regards

Marco

L4 Transporter

Hi Marco

How to do flow debug? You mean pcap from PA device?

Regards

Slawek

FTP app will not work with FTPS. From SLVs description, they encrypt data and control channels. Encrypted control traffic doesn't allow PA to learn ports used for data connection. To make it work either decrypt SSL on the firewall or open all ports that are used for data channel

L7 Applicator

Just a shot in the dark here, but it could be that it works for you with 'any' and not with application-default on the service tab, because it interprets the application initially as ftp, and then changes to ssl on port 21, and selecting 'any' covers for that odd port for ssl.

Try adding a rule allowing application = ssl and ftp, then service tab=(create a service for TCP 21), check if this works.

Mariano.

L4 Transporter

I got response from Support,

"This issue has been addressed with latest content and threat release version, I was not able to reproduce the same issue with the new version(while I was able reproduce with threat-version: 443-2274)."

Regards

Slawek

View solution in original post

Thanks for sharing the issue and solution.

Steve Puluka BSEET - IP Architect - DQE Communications (Metro Ethernet/ISP)
ACE PanOS 6; ACE PanOS 7; ASE 3.0; PSE 7.0 Foundations & Associate in Platform; Cyber Security; Data Center
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!