<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FTP on non-standard port (sk43597) in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FTP-on-non-standard-port-sk43597/m-p/80583#M80784</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I am looking at how to support FTP on a non-standard port. I found a related SK,but it does not mention and version in the R80 version.&lt;/P&gt;&lt;P&gt;Does anyone have experience with FTP on non-standard ports in R80. Do we still need to apply all the steps in this SK? I would like to avoid having to open up high ports for the FTP data connection.&amp;nbsp; This SK specific mentions having to manually update files on each Security Gateway to configure&amp;nbsp;&lt;SPAN&gt;the Security Gateway to listen to FTP connections on the desired port&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="FTP.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/5318i94BD24064618903C/image-size/large?v=v2&amp;amp;px=999" role="button" title="FTP.png" alt="FTP.png" /&gt;&lt;/span&gt;Many thanks,&lt;/P&gt;&lt;P&gt;Michael&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 02 Apr 2020 09:48:10 GMT</pubDate>
    <dc:creator>Michael_Horne</dc:creator>
    <dc:date>2020-04-02T09:48:10Z</dc:date>
    <item>
      <title>FTP on non-standard port (sk43597)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FTP-on-non-standard-port-sk43597/m-p/80583#M80784</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I am looking at how to support FTP on a non-standard port. I found a related SK,but it does not mention and version in the R80 version.&lt;/P&gt;&lt;P&gt;Does anyone have experience with FTP on non-standard ports in R80. Do we still need to apply all the steps in this SK? I would like to avoid having to open up high ports for the FTP data connection.&amp;nbsp; This SK specific mentions having to manually update files on each Security Gateway to configure&amp;nbsp;&lt;SPAN&gt;the Security Gateway to listen to FTP connections on the desired port&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="FTP.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/5318i94BD24064618903C/image-size/large?v=v2&amp;amp;px=999" role="button" title="FTP.png" alt="FTP.png" /&gt;&lt;/span&gt;Many thanks,&lt;/P&gt;&lt;P&gt;Michael&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Apr 2020 09:48:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FTP-on-non-standard-port-sk43597/m-p/80583#M80784</guid>
      <dc:creator>Michael_Horne</dc:creator>
      <dc:date>2020-04-02T09:48:10Z</dc:date>
    </item>
    <item>
      <title>Re: FTP on non-standard port (sk43597)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FTP-on-non-standard-port-sk43597/m-p/80604#M80785</link>
      <description>&lt;P&gt;&amp;nbsp;This sk only shows how to handle this situation using an added Service in Dashboard and a new line in&amp;nbsp;&lt;CODE&gt;$FWDIR/conf/fwauthd.conf&lt;/CODE&gt;&lt;SPAN&gt; file. Not so hard&amp;nbsp;&lt;/SPAN&gt;to try and may work in R80.xx, too.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Apr 2020 12:40:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FTP-on-non-standard-port-sk43597/m-p/80604#M80785</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-04-02T12:40:53Z</dc:date>
    </item>
    <item>
      <title>Re: FTP on non-standard port (sk43597)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FTP-on-non-standard-port-sk43597/m-p/80613#M80786</link>
      <description>&lt;P&gt;I would start with creating a new TCP service, select FTP protocol and specify a custom port.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2020-04-02_15-38-46.png" style="width: 520px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/5325i224382032D3F166C/image-size/large?v=v2&amp;amp;px=999" role="button" title="2020-04-02_15-38-46.png" alt="2020-04-02_15-38-46.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Apr 2020 13:44:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FTP-on-non-standard-port-sk43597/m-p/80613#M80786</guid>
      <dc:creator>RickHoppe</dc:creator>
      <dc:date>2020-04-02T13:44:27Z</dc:date>
    </item>
    <item>
      <title>Re: FTP on non-standard port (sk43597)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FTP-on-non-standard-port-sk43597/m-p/80616#M80787</link>
      <description>&lt;P&gt;I'm pretty sure you don't need to update fwauthd.conf unless you are doing some kind of legacy User/Session/Client authentication for FTP.&amp;nbsp; However an FTP service on a non-standard port needs to be set up correctly so the firewall can properly sniff PORT commands and pinhole open the necessary data ports.&amp;nbsp; This is why FTP control connections (port 21) always go F2F (but the data connections can be accelerated by SecureXL). What you should be able to do is clone the existing FTP service, then edit the name and port number like this:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ftp_999.jpg" style="width: 544px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/5326i38BDC94B481D8F10/image-size/large?v=v2&amp;amp;px=999" role="button" title="ftp_999.jpg" alt="ftp_999.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Use this new service explicitly in your Network rules and you should be good to go.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Apr 2020 12:54:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FTP-on-non-standard-port-sk43597/m-p/80616#M80787</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-04-03T12:54:53Z</dc:date>
    </item>
    <item>
      <title>Re: FTP on non-standard port (sk43597)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FTP-on-non-standard-port-sk43597/m-p/80690#M80788</link>
      <description>These instructions involve the FTP Security Server which, unless you still have rules with Action: User Auth in your rulebase, is completely irrelevant.&lt;BR /&gt;Create a service as Rick Hoppe suggests.</description>
      <pubDate>Fri, 03 Apr 2020 00:28:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FTP-on-non-standard-port-sk43597/m-p/80690#M80788</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-04-03T00:28:32Z</dc:date>
    </item>
    <item>
      <title>Re: FTP on non-standard port (sk43597)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FTP-on-non-standard-port-sk43597/m-p/80902#M80789</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It would appear that you would only need to create the custom FTP service. I added a feedback comment to the SK and Checkpoint have come back to say that this SK is not relevant to R80.x. I take this to meant that nothing extra needs to be done beyond the customer service.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Apr 2020 07:13:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FTP-on-non-standard-port-sk43597/m-p/80902#M80789</guid>
      <dc:creator>Michael_Horne</dc:creator>
      <dc:date>2020-04-06T07:13:13Z</dc:date>
    </item>
  </channel>
</rss>

