CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartDefense
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-06-17
Junior Member
 
Join Date: 2008-04-21
Posts: 2
Rep Power: 0
Chetan has an average reputation (10+)
Default Port 227/command missing a newline character

I think it will work if youchange protocol type to FTP_BASIC

Last edited by Chetan; 2008-06-24 at 02:07.
Reply With Quote
  #2 (permalink)  
Old 2008-06-23
Junior Member
 
Join Date: 2008-05-24
Posts: 6
Rep Power: 0
rockysam39 has an average reputation (10+)
Default Re: Port 227/command missing a newline character

HI

I am having the exact same issue. In my organization people reported that download from HP & DELL websies are ending up in PCBD. I checked in the Firewall Logs where it shows that the Firewall Accepts the FTP Packet but the SmartDefense rejects the packets...

Log details shows

Product: SmartDefense
Attack: FTP Bounce
Attack Information: Port/227 command missing a newline character

I read the following information on another Forum :-

The $FWDIR/lib/ftp.def file contains the following instructions:

// If you do not want the FW-1 module to insist on a newline at the end of the
// PORT command, change the following '1' to '0' and re-install the policy

#define FTPPORT_NL 1

so please do (taken from CP-support web):

* Issue cpstop from the command line, stopping all services on Smart Center. * Edit the $FWDIR/lib/ftp.def file and change FTPPORT_NL 1 to FTPPORT_NL 0
* Issue cpstart from the command line, starting all services.
* Reinstall the Security Policy.




I will try this myself tonight ( non-business hours ) and post the results
Reply With Quote
  #3 (permalink)  
Old 2008-06-24
Junior Member
 
Join Date: 2008-04-21
Posts: 2
Rep Power: 0
Chetan has an average reputation (10+)
Default Re: Port 227/command missing a newline character

I think it will work if you change the protcol type to FTP_BASIC .
Reply With Quote
  #4 (permalink)  
Old 2008-06-24
Senior Member
 
Join Date: 2006-03-14
Posts: 100
Rep Power: 3
avilT has an average reputation (10+)
Default Re: Port 227/command missing a newline character

I have my NGX R65 on Nokia IP390. Under SmartDefense I made "FTP BOUNCE" as Monitor Only.
Still FTP connection from one of my client are getting rejected by smartdefense. It was done by SMARTDEFENSE/Attack is FTP Bounce, Attack information: Port/227 command missing a newline character.

How do I disable this signature?
Reply With Quote
  #5 (permalink)  
Old 2008-07-30
Junior Member
 
Join Date: 2006-04-11
Posts: 16
Rep Power: 0
jeetu_chaudhari has an average reputation (10+)
Default Re: Port 227/command missing a newline character

Hi ,

I think FTP bounce attack can not be disabled.
Even if u make it as monitor only still it will drop.
I was facing same issue.
Solution you can try is
1. change FTP servie to FTP-BASIC
2. modification in ftp.lib file if you want i will try to post it what modification you should do in this file
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 11:07.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0