Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations IamaSherpa on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

FTP on PIX

Status
Not open for further replies.

gmandg

IS-IT--Management
Sep 1, 2006
3
US
I have a customer that's suggesting we are not allowing encrypted traffic on port 21 for FTP traffic. Is there a way to check and/or confirgure this?

This if for a PIX 515 Firewall Version 6.0(1)4:1344.

Thanks!
 
The PIX has a problem with ftp over ssl. The pix does a fixup on the IP and port to allow the traffic through NAT/PAT. With ftp over ssl, the data channel is encrypted (including the TCP/IP headers) so the PIX can't read what's inside and can't do the fixup. The connection is basically trying to get to the internal IP address/negotioated port of the FTP server, not the public IP/translated port that the PIX will change as it passes through.


Brent
Systems Engineer / Consultant
CCNP, CCSP
 
And in the first note:

Ipswitch also published this

You can disable the ftp fixup, but then either passive or active ftp will fail (I forget which off the top of my head.). I suppose you could make some NAT exemption, but I haven't seen anything work yet.


Brent
Systems Engineer / Consultant
CCNP, CCSP
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top