Re: secure ftp port 21 990 application layer firewall

2005-07-12 Thread Jay Maynard
On Tue, Jul 12, 2005 at 08:15:05AM -0500, Joel Ivey wrote: > Peter, thanks for the response. Our firewall is by Symantec. According to > the firewall folks, they cannot set up a separate set of rules to allow ftps > traffic through 21/20 from certain ip addresses.It's either all or > nothing

Re: secure ftp port 21 990 application layer firewall

2005-07-12 Thread Joel Ivey
Peter, thanks for the response. Our firewall is by Symantec. According to the firewall folks, they cannot set up a separate set of rules to allow ftps traffic through 21/20 from certain ip addresses.It's either all or nothing. If they allow ftps traffic through, they won't be able to do de

Re: secure ftp port 21 990 application layer firewall

2005-07-11 Thread Peter Vander Woude
Joel, I would suspect that the issue you're running into is that your firewall is doing "stateful inspection". The problem is not that the firewall doesn't recognize AUTH TLS, but that it's having a problem during the TLS negotiation. It is something that we ran into when first starting wit

secure ftp port 21 990 application layer firewall

2005-07-08 Thread Joel Ivey
Our network uses an application layer firewall for deep packet inspection. When we attempt to connect to an external ftps server on port 21, the firewall blocks it because it does not recognize the traffic to be ftp traffic. The AUTH TLS command is evidently not yet an accepted extension for the