Re: Is there a standard port for (ftp over) TLS ?

Re: Is there a standard port for (ftp over) TLS ?

Secure Home | Search | About
 Networking Firewalls    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Re: Is there a standard port for (ftp over) TLS ? Alexander Dalloz 01-15-2007
Posted by Alexander Dalloz on January 15, 2007, 4:46 am
If you were  Registered and logged in, you could reply and use other advanced thread options
On Sun, 14 Jan 2007 13:35:18 +0000 Marcus Mender wrote:

> I have to setup a ftp server and would like to enable TLS.
>
> I have to configure the firewall as well.
>
> Is there a different standard port for TLS (for ftp its 21)?

No

> Maybe its a pair of ports similarly to the standard ftp: 21 + 22

Ports are 20 and 21 if you are speaking about active FTP [1].

> One port for data and one port for protocol negotiations?

Yes

> Is there a difference if I use "implicit" or "explicit" TLS mode ?

Yes, see http://en.wikipedia.org/wiki/FTPS:

"Implicit FTPS is an older, but still widely implemented style in which
the client connects to a different port (usually 990), and an SSL
handshake is performed before any FTP commands are sent."

> Marcus

Basically the same decisions regarding firewalling (active or/and passive
FTP) applies to the situation when using TLS secured FTP. But in addition,
if your firewall is doing NAT as well there is a rather big chance that
FTP connections with TLS security will fail.

http://www.ford-hutchinson.com/~fh-1-pfh/ftps-ext.html

Alexander

[1] http://slacksite.com/other/ftp.html


--
Alexander Dalloz | Löhne, Germany | GPG http://pgp.mit.edu 0xB366A773
legal statement: http://www.uni-x.org/legal.html
Fedora Core 2 GNU/Linux on Athlon with kernel 2.6.11-1.35_FC2smp
Serendipity 10:36:33 up 1 day, 12:03, load average: 0.22, 0.24, 0.19


Similar ThreadsPosted
Re: Is there a standard port for (ftp over) TLS ? January 14, 2007, 12:06 pm
Re: Is there a standard port for (ftp over) TLS ? January 14, 2007, 2:15 pm
Malicious port scanning or standard Active Directory/Exchange Server behavior November 26, 2004, 3:24 pm
Product Standard April 2, 2006, 8:27 am
SonicWall PRO 2040 Standard VPN November 10, 2006, 9:44 am
Advanced Encryption Standard-Can any one explain?? February 10, 2005, 7:19 am
newbie: https on non standard ports September 5, 2007, 2:17 pm
Zone Alarm Standard v. eTrust EZ Armour???? March 15, 2007, 12:24 am
Why does Adobe Acrobat 7 Standard secretly phone home? October 29, 2007, 10:12 pm
netscreen: not allowed to port forward port outside port < 1024 toone inside >= 1024? December 15, 2004, 12:47 pm

The site map in XML format XML site map

Contact Us | Privacy Policy