Checkpoint vs FTP/PASV

Checkpoint vs FTP/PASV

Secure Home | Search | About
 Networking Firewalls    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Checkpoint vs FTP/PASV Ascadix 06-02-2007
Posted by Ascadix on June 2, 2007, 12:16 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hello

I have a pb with a checkpoint FW

i have set up a FTP server on my DMZ, added a rule FTP in my FW,but clients
have pb in some cases

- connexion : ok
- login / password : ok

- data exchange in PORT mode : all is ok.

- if a client try to switch to PASV mode ..the FW cut the connexion when the
server reply to PASV

the log on the FW is from to the "SmartDefense" module :

* Attack name : FTP Bounce
* Attack Info : IP adress mismatch in PORT/227 command - header IP
* different from command IP
* service : ftp (21)
* source : X.X.X.X
* target : X.X.X.X

"source" is the IP of ftp client ( on internet )
"target" id the public IP adress of my FTP server

When i check log on my fTP client and server :

- last line on client before disconnect is: "PASV"
- last line on server is "227 Entering Passive Mode (x,x,x,x,215,36) " (
x.x.x.x is public IP of my FTP server, port is in the good range )

If i uncheck the "FTP Bounce protection" in the SMARTDEFENSE module, no more
pb, so i think that all rules are fine, good port are open ..just this
damned smartdefense pb.

anyone have i idea on this ? is it possible to correct something ? if
possible, i'd prefer to reactivate this protection.

Sorry for my english ..i don't use it very often.
Thanks in advance

--
@+
Ascadix
adresse @mail valide, mais ajoutez "sesame" dans l'objet pour que ça arrive.


Posted by CosmicV on June 6, 2007, 4:57 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
> Hello
>
> I have a pb with a checkpoint FW
>
> i have set up a FTP server on my DMZ, added a rule FTP in my FW,but clien=
ts
> have pb in some cases
>
> - connexion : ok
> - login / password : ok
>
> - data exchange in PORT mode : all is ok.
>
> - if a client try to switch to PASV mode ..the FW cut the connexion when =
the
> server reply to PASV
>
> the log on the FW is from to the "SmartDefense" module :
>
> * Attack name : FTP Bounce
> * Attack Info : IP adress mismatch in PORT/227 command - header IP
> * different from command IP
> * service : ftp (21)
> * source : X.X.X.X
> * target : X.X.X.X
>
> "source" is the IP of ftp client ( on internet )
> "target" id the public IP adress of my FTP server
>
> When i check log on my fTP client and server :
>
> - last line on client before disconnect is: "PASV"
> - last line on server is "227 Entering Passive Mode (x,x,x,x,215,36) " (
> x.x.x.x is public IP of my FTP server, port is in the good range )
>
> If i uncheck the "FTP Bounce protection" in the SMARTDEFENSE module, no m=
ore
> pb, so i think that all rules are fine, good port are open ..just this
> damned smartdefense pb.
>
> anyone have i idea on this ? is it possible to correct something ? if
> possible, i'd prefer to reactivate this protection.
>
> Sorry for my english ..i don't use it very often.
> Thanks in advance
>
> --
> @+
> Ascadix
> adresse @mail valide, mais ajoutez "sesame" dans l'objet pour que =E7a ar=
rive.

Is this connection to your FTP server being NATed per chance? I could
understand the problem if thats the case.


Posted by Ascadix on June 7, 2007, 6:52 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
SmartDefense doesn't like that my FTP put is public adresse in the PASV
answer while it is in my DMZ with a private IP, it need that the FT Panswer
with its private adresse and the CheckPoint swap private / public IP while
PASV answer go across the FW.

> Hello
>
> I have a pb with a checkpoint FW
>
> i have set up a FTP server on my DMZ, added a rule FTP in my FW,but
> clients have pb in some cases
>
> - connexion : ok
> - login / password : ok
>
> - data exchange in PORT mode : all is ok.
>
> - if a client try to switch to PASV mode ..the FW cut the connexion
> when the server reply to PASV
>
> the log on the FW is from to the "SmartDefense" module :
>
> * Attack name : FTP Bounce
> * Attack Info : IP adress mismatch in PORT/227 command - header IP
> * different from command IP
> * service : ftp (21)
> * source : X.X.X.X
> * target : X.X.X.X
>
> "source" is the IP of ftp client ( on internet )
> "target" id the public IP adress of my FTP server
>
> When i check log on my fTP client and server :
>
> - last line on client before disconnect is: "PASV"
> - last line on server is "227 Entering Passive Mode (x,x,x,x,215,36)
> " ( x.x.x.x is public IP of my FTP server, port is in the good range
> )
> If i uncheck the "FTP Bounce protection" in the SMARTDEFENSE module,
> no more pb, so i think that all rules are fine, good port are open
> ..just this damned smartdefense pb.
>
> anyone have i idea on this ? is it possible to correct something ? if
> possible, i'd prefer to reactivate this protection.
>
> Sorry for my english ..i don't use it very often.
> Thanks in advance


Posted by JJ on June 8, 2007, 10:28 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Thanks for the follow-up. I was wondering what it could be.

Take care,

Ray

> SmartDefense doesn't like that my FTP put is public adresse in the PASV
> answer while it is in my DMZ with a private IP, it need that the FT
> Panswer with its private adresse and the CheckPoint swap private / public
> IP while PASV answer go across the FW.
>
>> Hello
>>
>> I have a pb with a checkpoint FW
>>
>> i have set up a FTP server on my DMZ, added a rule FTP in my FW,but
>> clients have pb in some cases
>>
>> - connexion : ok
>> - login / password : ok
>>
>> - data exchange in PORT mode : all is ok.
>>
>> - if a client try to switch to PASV mode ..the FW cut the connexion
>> when the server reply to PASV
>>
>> the log on the FW is from to the "SmartDefense" module :
>>
>> * Attack name : FTP Bounce
>> * Attack Info : IP adress mismatch in PORT/227 command - header IP
>> * different from command IP
>> * service : ftp (21)
>> * source : X.X.X.X
>> * target : X.X.X.X
>>
>> "source" is the IP of ftp client ( on internet )
>> "target" id the public IP adress of my FTP server
>>
>> When i check log on my fTP client and server :
>>
>> - last line on client before disconnect is: "PASV"
>> - last line on server is "227 Entering Passive Mode (x,x,x,x,215,36)
>> " ( x.x.x.x is public IP of my FTP server, port is in the good range
>> )
>> If i uncheck the "FTP Bounce protection" in the SMARTDEFENSE module,
>> no more pb, so i think that all rules are fine, good port are open
>> ..just this damned smartdefense pb.
>>
>> anyone have i idea on this ? is it possible to correct something ? if
>> possible, i'd prefer to reactivate this protection.
>>
>> Sorry for my english ..i don't use it very often.
>> Thanks in advance
>



Similar ThreadsPosted
Checkpoint - Deny traceroute through checkpoint firewall August 10, 2004, 3:27 pm
Checkpoint - NAT Help February 7, 2005, 8:00 am
checkpoint March 17, 2005, 5:12 pm
checkpoint fp1 +ike October 25, 2005, 12:08 am
CheckPoint help on September 15, 2006, 2:37 pm
Checkpoint QoS October 24, 2006, 3:29 pm
PIX to checkpoint VPN August 14, 2007, 1:08 pm
checkpoint and static nat August 3, 2004, 5:19 pm
Checkpoint and Cisco 501 August 29, 2004, 10:47 am
Looking at PIX syslogs the CheckPoint way December 21, 2004, 11:41 am

The site map in XML format XML site map

Contact Us | Privacy Policy