Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Setting up FTP and FTP-bounce attack

I'm trying to access an FTP server located in our Server Zone from our DMZ Zone (passive mode).

When the server initially responds from port 21 to the initial connection, the connection is being blocked by Sophos XG - "FTP-bounce attack" but I have set FtpBounce Prevention to 'data'.

I'm running SFOS 19.5 MR1

Any suggestions (apart from not use FTP, which I hate, but is the only option in this situation)?



This thread was automatically locked due to age.
Parents
  • Mit freundlichem Gruß, best regards from Germany,

    Philipp Rusch

    New Vision GmbH, Germany
    Sophos Silver-Partner

    If a post solves your question please use the 'Verify Answer' button.

  • Thanks for the suggestion but I have already tried the solution "set advanced-firewall ftpbounce-prevention data", as I sort of said in my original post.

    I presume the point of this change is to prevent blocking the initial FTP port negotiation (control) messages (the default is "advanced-firewall ftpbounce-prevention control") but it doesn't seem to be working as it blocks the very first (control) response from the FTP server with the error "FTP-bounce attack".

Reply
  • Thanks for the suggestion but I have already tried the solution "set advanced-firewall ftpbounce-prevention data", as I sort of said in my original post.

    I presume the point of this change is to prevent blocking the initial FTP port negotiation (control) messages (the default is "advanced-firewall ftpbounce-prevention control") but it doesn't seem to be working as it blocks the very first (control) response from the FTP server with the error "FTP-bounce attack".

Children