Stateful Inspection firewall with passive FTPS( Explicit FTPS ?).
I looking for a solution with Fortigate(FortiOS) to dynamically open the required FTPS-data port on Firtigate(firewall) with passive FTPS mode.
Example,
1.When the client initiates a Control session(send Request:PASV), and get Response(with Data Port) from Server.
2.The firewall extracts the Data port number from the Response packet.
3.The firewall then records both the client and server's IP addresses and port numbers in an FTPS-data pending request list.
4.When the client later attempts to initiate a data connection, the firewall compares the connection request's parameters (ports and IP addresses) to the information in the FTPS-data pending request list, to determine whether the connection attempt is legitimate.
5.Since the FTPS-data pending request list is dynamic, the firewall can ensure that only the required FTP ports open.
6.When the session is closed, the firewall immediately closes the ports, guaranteeing the FTPS server's continued security.
My image is "explicit proxy for FTPS" about such as above feature.
Is it possible with FortiOS?
Best Regards,
Kim
