SRX Services Gateway
Reply
Contributor
JamesNT
Posts: 26
Registered: ‎11-23-2011
0

Passive FTP

I have a user sitting behind a Juniper SRX 210 gateway.  They are trying to reach a secure passive FTP server over the Internet.  The server is using Explicit TLS which is port 21 for the command port but ports 10000 - 12000 for the range to transmit data.  I have determined that the SRX is blocking the data port(s).

 

Is there any way to open up that port range in NAT and in policies without having to enter each port one at a time?

 

Or is there a more best practices way?

 

James

Recognized Expert
JunOS_Fan
Posts: 241
Registered: ‎02-13-2012
0

Re: Passive FTP

Hi,

 

Just in case , you haven't tried this -  KB19444 (How to let FTPS pass though a SRX device) .

 

Best regards
Pradeep (JNCIP-SEC,ENT,SP)
www.networker.co.in
Copyright© 1999-2013 Juniper Networks, Inc. All rights reserved.