<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Thanks for taking the time to in Cloud Security</title>
    <link>https://community.cisco.com/t5/cloud-security/ftp-through-cws/m-p/2861012#M281</link>
    <description>&lt;P&gt;Thanks for taking the time to reply!&lt;/P&gt;
&lt;P&gt;IF using HTTP connect does CWS just relay the traffic tot he FTP site and back to the source through CWS. Or does it scan the file on the way back to the client? I really want to have the FTP files scanned before they enter our network.&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Davie&lt;/P&gt;</description>
    <pubDate>Thu, 21 Apr 2016 14:13:55 GMT</pubDate>
    <dc:creator>david.bryant1</dc:creator>
    <dc:date>2016-04-21T14:13:55Z</dc:date>
    <item>
      <title>FTP through CWS</title>
      <link>https://community.cisco.com/t5/cloud-security/ftp-through-cws/m-p/2861010#M279</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have a requirement for access to 3 FTP sites to download data from. The users currently have this automated through a an application called KAPOW which is an internet data scraping application. I would much prefer that raw FTP access through our firewall was removed and I found a solution to have the FTP go through 8080 and our cisco web security towers.&lt;/P&gt;
&lt;P&gt;Has anyone configured something similar before?&lt;/P&gt;
&lt;P&gt;I have spoken to Cisco and Cisco Web Security is unable to take the FTP and put it through 8080. I need to find some way of doing this.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Davie&lt;/P&gt;</description>
      <pubDate>Sat, 09 Mar 2019 01:39:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-security/ftp-through-cws/m-p/2861010#M279</guid>
      <dc:creator>david.bryant1</dc:creator>
      <dc:date>2019-03-09T01:39:20Z</dc:date>
    </item>
    <item>
      <title>Cisco Web Security does</title>
      <link>https://community.cisco.com/t5/cloud-security/ftp-through-cws/m-p/2861011#M280</link>
      <description>&lt;P&gt;Cisco Web Security does support that way as long as your FTP client application supports using HTTP CONNECT method.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;For example, in FileZilla you could configure WSA IP in Generic proxy and just need to ensure it is using HTTP/1.1 CONNECT method.&lt;IMG src="https://community.cisco.com/legacyfs/online/media/screen_shot_2016-04-20_at_2.18.42_pm.png" class="migrated-markup-image" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;As FTP is using two channels, the only thing you need to be aware of is to ensure all ports will be allowed in HTTP CONNECT Ports settings within the corresponding WSA access policy&amp;gt;Protocols and User Agents configurations. Otherwise you will see the following.&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;1461125975.700 0 x.x.x.x&amp;nbsp;TCP_DENIED/403 0 CONNECT tunnel://208.90.57.232:10556/ - NONE/- - BLOCK_ADMIN_CONNECT_12-test.AP-test.ID-NONE-NONE-NONE-NONE &amp;lt;C_Skyp,-,-,"-",-,-,-,-,"-",-,-,-,"-",-,-,"-","-",-,-,-,-,"-","-","-","-","-","-",0.00,0,-,"-","-",-,"-",-,-,"-","-"&amp;gt; - "FileZilla"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;Here is an example:&lt;/P&gt;
&lt;P class="p1"&gt;&lt;IMG typeof="foaf:Image" src="https://community.cisco.com/legacyfs/online/media/screen_shot_2016-04-20_at_2.30.03_pm.png" width="1818" height="932" alt="UserAgent" title="UserAgent" data-fid="1285631" data-media-element="1" class="media-element file-default" /&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;/P&gt;
&lt;P class="p1"&gt;Then you will be able to access any FTP site and here are the corresponding access logs.&lt;/P&gt;
&lt;P class="p1"&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;1461126151.522 177330 x.x.x.x&amp;nbsp;TCP_MISS/200 1049 CONNECT tunnel://ftp.ironport.com:21/ - DIRECT/ftp.ironport.com - ALLOW_WBRS_12-test.AP-test.ID-NONE-NONE-NONE-DefaultGroup &amp;lt;IW_csec,9.3,1,"-",-,-,-,1,"-",-,-,-,"-",1,-,"-","-",-,-,IW_csec,-,"-","-","Unknown","Unknown","-","-",0.05,0,-,"-","-",1,"-",-,-,"-","-"&amp;gt; - "FileZilla" - 208.90.57.232&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;1461126153.598 706 x.x.x.x&amp;nbsp;TCP_MISS/200 27875 CONNECT tunnel://208.90.57.232:9378/ - DIRECT/208.90.57.232 - ALLOW_CUSTOMCAT_12-test.AP-test.ID-NONE-NONE-NONE-DefaultGroup &amp;lt;&lt;SPAN&gt;IW_csec&lt;/SPAN&gt;,-,-,"-",-,-,-,-,"-",-,-,-,"-",-,-,"-","-",-,-,-,-,"-","-","-","-","-","-",315.86,0,-,"-","-",-,"-",-,-,"-","-"&amp;gt; - "FileZilla" - 208.90.57.232&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Apr 2016 04:33:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-security/ftp-through-cws/m-p/2861011#M280</guid>
      <dc:creator>Tao Yang</dc:creator>
      <dc:date>2016-04-20T04:33:39Z</dc:date>
    </item>
    <item>
      <title>Thanks for taking the time to</title>
      <link>https://community.cisco.com/t5/cloud-security/ftp-through-cws/m-p/2861012#M281</link>
      <description>&lt;P&gt;Thanks for taking the time to reply!&lt;/P&gt;
&lt;P&gt;IF using HTTP connect does CWS just relay the traffic tot he FTP site and back to the source through CWS. Or does it scan the file on the way back to the client? I really want to have the FTP files scanned before they enter our network.&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Davie&lt;/P&gt;</description>
      <pubDate>Thu, 21 Apr 2016 14:13:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-security/ftp-through-cws/m-p/2861012#M281</guid>
      <dc:creator>david.bryant1</dc:creator>
      <dc:date>2016-04-21T14:13:55Z</dc:date>
    </item>
    <item>
      <title>Hello Davie,</title>
      <link>https://community.cisco.com/t5/cloud-security/ftp-through-cws/m-p/2861013#M282</link>
      <description>&lt;P&gt;Hello Davie,&lt;/P&gt;
&lt;P&gt;Firstly this solution is for WSA the on premise solution Additionally, as it is using HTTP CONNECT method, there is no way for WSA to see the exact file inside as it is encapsulated in the tunnel.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Hope it helps.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2016 01:26:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-security/ftp-through-cws/m-p/2861013#M282</guid>
      <dc:creator>Tao Yang</dc:creator>
      <dc:date>2016-04-22T01:26:30Z</dc:date>
    </item>
  </channel>
</rss>

