CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 52 attendees signed up from 14 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > NAT (Network Address Translation)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-04-26
ChrisA ChrisA is offline
Senior Member
 
Join Date: 2006-02-18
Posts: 101
Rep Power: 3
ChrisA has an average reputation (10+)
Default FTP Nat - Can't build data connection: Connection timed out

We're running CheckPoint NGX HFA02. We have a server that external folks connect to over non-standard FTP port 10021. All works fine. All sessions come through a VPN connection (SecureClient or site-to-site VPN).

One site cannot do 10021, for whatever reason, and asked that we perform nat so that they can do straight FTP and we xlate the service from FTP to 10021 at the firewall. It works, and the site can log in to the server, but any command (dir, ls, ..) gives "425 Can't build data connection: Connection timed out". The site tried passive mode but that didn't work either.

Any ideas?
Reply With Quote
  #2 (permalink)  
Old 2006-05-01
dguinn dguinn is offline
Junior Member
 
Join Date: 2006-04-19
Posts: 13
Rep Power: 0
dguinn has an average reputation (10+)
Default Re: FTP Nat - Can't build data connection: Connection timed out

When you created your protocol object for this port, did you go under advanced and change the protocol type to FTP? Be sure to do this, as FTP requires special INSPECT rules.

DG
Reply With Quote
  #3 (permalink)  
Old 2006-05-02
ChrisA ChrisA is offline
Senior Member
 
Join Date: 2006-02-18
Posts: 101
Rep Power: 3
ChrisA has an average reputation (10+)
Default Re: FTP Nat - Can't build data connection: Connection timed out

Yes, the protocol was set to FTP in the advanced settings of the 10021 service object. It's working fine for folks who connect over this port, but it isn't working when folks connect with FTP and then the firewall NATs FTP to 10021.
Reply With Quote
  #4 (permalink)  
Old 2006-05-03
dguinn dguinn is offline
Junior Member
 
Join Date: 2006-04-19
Posts: 13
Rep Power: 0
dguinn has an average reputation (10+)
Default Re: FTP Nat - Can't build data connection: Connection timed out

Ok, again, silly question here, any chance that you need a outbound NAT rule for his particular IP/Range, and be sure it's placed BEFORE the 10021 port rule, so that you can be sure that the outbound packet is excluded from the blanket ANY translation?

e.g.:

source,dest,port...source,dest,port
problem_ip,EXT_ftpsvr,ftp...orig,INT_ftpsvr,10021
INT_ftpsvr,problem_ip,10021 EXT_ftpsvr,orig,ftp
orig, EXT_ftpsvr,10021...orig,INT_ftpsvr,orig
INT_ftpsvr,orig, 10021...EXT_ftpsvr,ANY,orig

I know, this should be stateful, but it might warrant a look since it's a complex TCP type protocol.
Reply With Quote
  #5 (permalink)  
Old 2006-11-15
manfred.huels manfred.huels is offline
Junior Member
 
Join Date: 2006-11-07
Location: Germany, Münster
Posts: 4
Rep Power: 0
manfred.huels has an average reputation (10+)
Send a message via Yahoo to manfred.huels
Default Re: FTP Nat - Can't build data connection: Connection timed out

Could be, this is a "extended passive" problem. Some Clients first try to make an EPSV for dataconnections. Checkpoint does not support this, so the packet will be dropped. (By the way, does anybody know a solution for this?) If the client first toggels EPSV, all should goes well.
Reply With Quote
  #6 (permalink)  
Old 2006-11-29
Mathieu Mathieu is offline
Junior Member
 
Join Date: 2006-05-18
Location: France
Posts: 8
Rep Power: 0
Mathieu has an average reputation (10+)
Default Re: FTP Nat - Can't build data connection: Connection timed out

Yes, I think it is ! At least I have the problem with the EPSV command which is not recognised, so fw1 is unable to know on which port the data connection will occur (on NGX R60 HFA03).
Anybody knows if it is recognised in more recent version ?
Reply With Quote
  #7 (permalink)  
Old 2007-06-30
Mathieu Mathieu is offline
Junior Member
 
Join Date: 2006-05-18
Location: France
Posts: 8
Rep Power: 0
Mathieu has an average reputation (10+)
Default Re: FTP Nat - Can't build data connection: Connection timed out

So, according to a Check Point engineer, the solution would be to disable the EPSV command for the FTP protocol in CP. Not tried yet, but it makes senses :)
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 21:04.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0