SRX Services Gateway
Highlighted
SRX Services Gateway

SRX FTPS destination NAT

‎12-08-2011 12:50 AM

Hello,

 

I'd like to make my FTPS server available for Internet users. I was glad when I found the set security alg ftp ftps-extension but somehow the NAT is not working. The connection goes up but when data is passing through the SRX does not replace the internal address of the FTPS server.

When I try to connect from my client the error is: server reports local IP.

 

I've found this article: http://kb.juniper.net/InfoCenter/index?page=content&id=KB19444

According to this kb article the ftps-extension works only with source NAT and routed connection. Is it true?

 

What is the workaround for this?

 

Thanks,

BB

 

4 REPLIES 4
Highlighted
SRX Services Gateway

Re: SRX FTPS destination NAT

‎12-08-2011 01:48 AM

Because I don't have your valid and invalid IP addresses replace them with my sample IP address.

 

If your valid IP address(preNAT) is 1.1.1.1 and your invalid IP address is 10.10.10.10(Post-NAT), and the computer in the internet is 2.2.2.1, enable traceoption on your flow as following:

 

edit security flow traceoptions

set file FTPS-Flow

set flag basic-datapath

set packet-filter MachtFTPS-Traffic source-prefix 2.2.2.1/32

set packet-filter MachtFTPS-Traffic source-prefix 1.1.1.1/32

set packet-filter MachtFTPS-Traffic-Reverse source-prefix 10.10.10.10/32

set packet-filter MachtFTPS-Traffic-Reverse source-prefix 2.2.2.1/32

 

commit the config.

 

The output is a little messing, it needs a little patience.

 

Then check the log file "FTPS-Flow" and see if NAT happening, if not happening, look it somewhere in your nat configuration, you probably have static nat or some mistakes in your nat config, if NAT is happening check to see if routing happening good, then check if source zone and destination zone in detecting, next is your policies, you have to have good policy, and after policy is ALG and some other stuff.

 

Hope this is helpful

 

Good luck on your troubleshooting

 

Highlighted
SRX Services Gateway

Re: SRX FTPS destination NAT

‎12-09-2011 09:46 PM
can you post the detailed config ....

regards
Hafiz Muhammad Farooq
JNCIE-SEC, JNCIP-SEC, JNCIS-SEC, JNCIS-FWV
JNCIS-SP, JNCIS-SA, JNCIA-JUNOS
IBM Qradar Deployment Professional

[Please mark it as Accepted Solution if it works, Kudos if you like]

Highlighted
SRX Services Gateway

Re: SRX FTPS destination NAT

‎12-10-2011 10:02 AM

@rasmus wrote:
can you post the detailed config ....

regards

Agree with rasmus, it helps to give you more accurate instruciton, or config or...

Highlighted
SRX Services Gateway

Re: SRX FTPS destination NAT

[ Edited ]
‎03-02-2012 02:18 PM

Hi,

 

this version work fine : 11.2R2.4

 

FTPS in explicit and passif mode.

 

With DESTINATION NAT options.

 

 

Feedback