Skip to main content
wcruvinel
Staff
Staff
October 6, 2025

Troubleshooting Tip: FTPS file transfer is not working

  • October 6, 2025
  • 0 replies
  • 918 views
Description

This article describes a situation with FortiGate units running FortiOS 7.2.10 and later when operating in Flow mode with IPS or Deep Inspection enabled, and the FTPS file transfer is not working. 

 

When using explicit FTPS, after the TLS AUTH negotiation, the data channel (high-port session) is initiated.
Because the traffic is encrypted, the kernel session helper cannot extract the required session information and fails to create the expected session. As a result, the FortiGate denies the data connection.

Scope FortiGate units running FortiOS v7.2.10 and later.
Solution

Trigger condition:
Attempt to use explicit FTPS over a policy configured to allow only the FTP service.

 

Workaround:
Temporarily allow all outgoing ports to the destination FTPS server in the policy; this will enable the high-port session to be established.

 

Final Solution:
Will be released on FortiOS to v7.4.10 and v7.6.5.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.