cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Who Me Too'd this topic

Enable FTP and FTPS for Active/Passive?

L4 Transporter

Hello Folks,

 

We have a CrushFTP server installed on a server behind our PA 3020 PANOS: 7.1.14, SSL decrypt not enabled.

Security Rule:

FTP_rule.jpg

 

NAT Rule:

FTP_NAT_rule.jpg

 

Trying to figure out why Active and Passive with FTP over TLS (SSL) will not retrieve the directory listing and will not complete connection.  Works fine with just FTP (insecure).

 

Do I need to add SSL to the security rule?

 

Filezilla client set to Active - FTP Only (Insecure) - Why do I not see the data transfer port 20 when I upload a file?

 

Active_FTP.jpg

 

Filezilla Client set to Active - FTP over TLS

 

Active_FTPS.jpg

 

Filezilla client set to Passive - FTP Only (Insecure)

 

Passive_FTP.jpg

 

Filezilla client set to Passive - FTP over TLS (SSL) - Does this mean that FTPS is detected as SSL and discarded because not added to the security rule?

 

Passive_FTPS.jpg

 

For reference:

https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Allow-FTPS-FTPES-Traffic-Through-...

 

https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Create-an-Application-Override-fo...

 

Who Me Too'd this topic