<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why is Passive Ftp not working in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Why-is-Passive-Ftp-not-working/m-p/209343#M39665</link>
    <description>&lt;P&gt;Can you do zdebug to see if it gives specific reason for the drop?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Thu, 21 Mar 2024 00:48:19 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2024-03-21T00:48:19Z</dc:date>
    <item>
      <title>Why is Passive Ftp not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Why-is-Passive-Ftp-not-working/m-p/209303#M39649</link>
      <description>&lt;P&gt;Ive been having trouble stablishing a passive FTP connection with a host that resides in a public IP.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The connection itself works, but when i try to transfer or list a file i keep receiving reject from the firewall indicating error&amp;nbsp;(227)&lt;/P&gt;&lt;P&gt;Ive followed the instructions on the sk on this error (227) which is&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk171375" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk171375&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Remove all FTP services from the rule and use only ftp service. If you want only to use Passive mode FTP, use only ftp-pasv service in the rule. (In addition, this applies if you do not use multiple services with the same port in the same rule.)&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Despite the rule is matched, it still gets rejected, as soon as an ls command is issued on the session. High tcp ports are also allowed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Keep receiving the&amp;nbsp; the same message (227)&lt;/P&gt;&lt;P&gt;I understand that it get's rejected because the client is sending a port command when working in passive mode, but my linux is configured to work on passive mode and it works ok with other hosts... Also the connection from a network outside of the scope of the firewall also work.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I dont quite understand why does the host try to send a port command, even when the firewall detects it is a passive ftp connection, as it get matched with rule 6..&lt;/P&gt;&lt;P&gt;Wyh does this happen?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2024 16:22:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Why-is-Passive-Ftp-not-working/m-p/209303#M39649</guid>
      <dc:creator>Jveas</dc:creator>
      <dc:date>2024-03-20T16:22:44Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Passive Ftp not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Why-is-Passive-Ftp-not-working/m-p/209343#M39665</link>
      <description>&lt;P&gt;Can you do zdebug to see if it gives specific reason for the drop?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 21 Mar 2024 00:48:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Why-is-Passive-Ftp-not-working/m-p/209343#M39665</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-03-21T00:48:19Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Passive Ftp not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Why-is-Passive-Ftp-not-working/m-p/209344#M39666</link>
      <description>&lt;P&gt;The reject message specifies the exact reason: because a PORT command is received when PASV mode is expected based on the fact you’re only allowing Passive mode via the Access Policy.&lt;BR /&gt;The service matched ftp-pasv because that’s what you have in your policy.&lt;BR /&gt;It uses the same port as regular FTP, just with different enforcement logic, namely PORT commands are not allowed with PASV.&lt;/P&gt;
&lt;P&gt;This is expected behavior.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Mar 2024 01:07:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Why-is-Passive-Ftp-not-working/m-p/209344#M39666</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-03-21T01:07:39Z</dc:date>
    </item>
  </channel>
</rss>

