FTPS and Service - problem

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

FTPS and Service - problem

L4 Transporter

Hello

I have FTP server on Debian 7 (ProFTPD 1.3.1) and security rule:

2014-07-02_202605.png

and now FTPS connection works.

With "application-default" as a service FTPS sessions hangs on listing directory and sfter some time FTP client was disconected.

I'm on 6.0.2 PAN with latest updates.

Is this a normal behaviour? According to best practice we should use "application-default" as a service - but in this case we couldn't.

Please share Your opinion about that.

With regards

SLawek

20 REPLIES 20

L4 Transporter

Hi Marco

How to do flow debug? You mean pcap from PA device?

Regards

Slawek

FTP app will not work with FTPS. From SLVs description, they encrypt data and control channels. Encrypted control traffic doesn't allow PA to learn ports used for data connection. To make it work either decrypt SSL on the firewall or open all ports that are used for data channel

L7 Applicator

Just a shot in the dark here, but it could be that it works for you with 'any' and not with application-default on the service tab, because it interprets the application initially as ftp, and then changes to ssl on port 21, and selecting 'any' covers for that odd port for ssl.

Try adding a rule allowing application = ssl and ftp, then service tab=(create a service for TCP 21), check if this works.

Mariano.

L4 Transporter

I got response from Support,

"This issue has been addressed with latest content and threat release version, I was not able to reproduce the same issue with the new version(while I was able reproduce with threat-version: 443-2274)."

Regards

Slawek

Thanks for sharing the issue and solution.

Steve Puluka BSEET - IP Architect - DQE Communications (Metro Ethernet/ISP)
ACE PanOS 6; ACE PanOS 7; ASE 3.0; PSE 7.0 Foundations & Associate in Platform; Cyber Security; Data Center

Similar issues here - Secure Passive FTP (FTPS) on remapped ports not working without app override

I've had this problem for ~5 months, going back several code releases and TP versions.  It is solved with an app override, but SSL decryption just won't jive.

  • 9805 Views
  • 20 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!