05-30-2003 05:09 AM - edited 02-20-2020 10:46 PM
We are trying to do Secure FTP to a server on port 21 through our PIX Firewall running 6.2(2). I have the "fixup protocol ftp 21" statement in the PIX. I can see the connection begin on port 21 but then I see the traffic getting blocked in my syslog. The traffic that is getting denied is between the workstation and the server both talking on high ports. I am wondering if the fixup cannot detect which high ports the conversation is moving to because the traffic is encrypted? Has anyone else worked with this or been able to get Secure FTP to work through the PIX?
Thanks,
Deanna
05-30-2003 06:14 AM
Deanna,
You are correct in your thinking, the fixup cannot track the high port allocated by the PORT statement over the encrypted data channel.
I was reading yesterday the ftp fixup details for 6.3, there was no mention of support for any form of secure FTP. Even more confusing I see there are 2 types of secure FTP, one based on SSL, the other on SSH2.
Andy
05-30-2003 07:20 AM
Is there a passive option you can use with the Secure FTP?
05-30-2003 07:58 AM
I use SFTP via SSH / OpenSSH through the PIX (501 / 6.2(2) and 6.31) with no problems.
Also, if you allow it, other protocols can be tunneled as well.
Check out the info at OpenSSH.org, VanDyke.com (SecureCRT and other SSH applications), or F-Secure (fsecure.com, I think).
BTW: SSH will run everything through port TCP/22.
Good Luck
Scott
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide