CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Services
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2005-08-13
BarryStiefel BarryStiefel is offline
Administrator
 
Join Date: 2005-08-11
Location: San Francisco, CA
Posts: 534
Rep Power: 10
BarryStiefel has disabled reputation
Default FTP to some sites fails

FTP to some sites fails



There are several different types of sites or proxy configurations that might make FTP fail when passing through FireWall-1. Some of the sites do not send newlines in the same packet as the PORT command. Refer to FTPAndNewlines for more information.

Another possibility is the FTP Data connection is not originating from port 20. FireWall-1 does not, by default, accept FTP Data connections that come from ports other than 20 unless it is a PASV connection. You can modify FireWall-1. Refer to FTP on non-standard ports for details.

Some "suspicious" FTP packets may get dropped in NG AI and above due to enhanced checks on FTP. To prevent FireWall-1 from dropping these packets (and instead rendering them harmless), modify the following line in $FWDIR/lib/base.def on the management station (This will not affect FireWall-1 NG FP3 and earlier versions.):

// #define FTP_CHECK_PACKET

This should be changed to the following and then the policy must be reinstalled on the gateways:

#define FTP_CHECK_PACKET

If a reset packet is seen from the FTP server to FTP client, you may need to increase the Maximum Segment Size (MSS) on your firewall. This is usually only a problem on IPSO. Increase the Maximum Segment Size (MSS) on IPSO by issuing the following command;

# ipsctl -w net:ip:tcp:default_mss 1460

Nokia customers should also refer to KB 3306 in Nokia's Knowledge Base for additional information.

-- PhoneBoy - 16 Jan 2004

FAQForm FAQs.Class: ServicesFAQs FAQs.OS: OsNokiaIPSO FAQs.Version:
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 01:29.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0