I looking for a solution with Fortigate(FortiOS) to dynamically open the required FTPS-data port on Firtigate(firewall) with passive FTPS mode.
Example,
1.When the client initiates a Control session(send Request:PASV), and get Response(with Data Port) from Server.
2.The firewall extracts the Data port number from the Response packet.
3.The firewall then records both the client and server's IP addresses and port numbers in an FTPS-data pending request list.
4.When the client later attempts to initiate a data connection, the firewall compares the connection request's parameters (ports and IP addresses) to the information in the FTPS-data pending request list, to determine whether the connection attempt is legitimate.
5.Since the FTPS-data pending request list is dynamic, the firewall can ensure that only the required FTP ports open.
6.When the session is closed, the firewall immediately closes the ports, guaranteeing the FTPS server's continued security.
My image is "explicit proxy for FTPS" about such as above feature.
Is it possible with FortiOS?
Best Regards,
Kim
If we configure following workaround solution....
http://kb.fortinet.com/kb....do?externalId=FD32835
After then,Is there no way to control(Block) unsuspected FTPS-data request packet?
For Example using 'tcp_flags' in Session keywords(Custom signature)?
Best Regards,
Kim
Never mind
User | Count |
---|---|
2063 | |
1176 | |
770 | |
448 | |
344 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.