- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
07-02-2014 11:31 AM
Hello
I have FTP server on Debian 7 (ProFTPD 1.3.1) and security rule:
and now FTPS connection works.
With "application-default" as a service FTPS sessions hangs on listing directory and sfter some time FTP client was disconected.
I'm on 6.0.2 PAN with latest updates.
Is this a normal behaviour? According to best practice we should use "application-default" as a service - but in this case we couldn't.
Please share Your opinion about that.
With regards
SLawek
07-03-2014 05:44 AM
Hi Marco
How to do flow debug? You mean pcap from PA device?
Regards
Slawek
07-03-2014 06:04 AM
FTP app will not work with FTPS. From SLVs description, they encrypt data and control channels. Encrypted control traffic doesn't allow PA to learn ports used for data connection. To make it work either decrypt SSL on the firewall or open all ports that are used for data channel
07-08-2014 04:53 PM
Just a shot in the dark here, but it could be that it works for you with 'any' and not with application-default on the service tab, because it interprets the application initially as ftp, and then changes to ssl on port 21, and selecting 'any' covers for that odd port for ssl.
Try adding a rule allowing application = ssl and ftp, then service tab=(create a service for TCP 21), check if this works.
Mariano.
07-08-2014 11:46 PM
I got response from Support,
"This issue has been addressed with latest content and threat release version, I was not able to reproduce the same issue with the new version(while I was able reproduce with threat-version: 443-2274)."
Regards
Slawek
07-09-2014 02:58 AM
Thanks for sharing the issue and solution.
09-12-2014 02:01 PM
Similar issues here - Secure Passive FTP (FTPS) on remapped ports not working without app override
I've had this problem for ~5 months, going back several code releases and TP versions. It is solved with an app override, but SSL decryption just won't jive.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!