This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Transparent FTP proxy issue

Since one of the last updates our FTP proxy isn't functioning no more. Whenever trying to upload files to our FTP server it will ask if it's okay to overwrite the destination (even when the file didn't exist before) and when confirming the overwrite the resulting file will always be 0 bytes in size. Same happens with pre-existing files; they will just get 0 bytes.

When adding the host to the skip transparent FTP everything works as expected (and as it did until a while ago).

Our supplier confirmed this on their own system and filed it to Sophos support.

Edit: now using 9.205-12


This thread was automatically locked due to age.
  • I'm a little confused.  What mode is your FTP Proxy in - Transparent?  Are you uploading from a browser or from an FTP client like FileZilla?  Is your FTP server internal or external?  Have you tried rebooting the UTM again after the Up2Date?

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Hi Bob,
    I'm using transparent FTP proxy with FileZilla client. I'm using it on an external FTP server.
    Other than the automated reboot after Up2Date there haven't been any reboots. I can try a new reboot tonight and see what happens after that. For now I have added the FTP server to the Skip transparent host section.

    My UTM-partner however was able to reproduce this same behaviour on their own UTM and have therefore created a case with support.

    Managing several Sophos UTMs and Sophos XGs both at work and at some home locations, dedicated to continuously improve IT-security and feeling well helping others with their IT-security challenges.

    Sometimes I post some useful tips on my blog, see blog.pijnappels.eu/category/sophos/ for Sophos related posts.

  • When Web Filtering is in Transparent mode, you need to have the FTP Proxy in Transparent mode for the browser to be able to use it.  When you also want to use an FTP client like FileZilla, you should select mode "Both" and configure FileZilla to use the proxy on port 2121.  

    Cheers - Bob  
    PS I think this is in the documentation.

    Sorry for any short responses.  Posted from my iPhone.
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Hi Bob,

    Just tested this and selected "Both" logging in works using port 2121 but the same thing happens; uploading a non-existing file creates the file with 0 bytes size and asks permission to overwrite it, whatever is chosen the file stays 0 bytes. Also when really overwriting an existing file, the result will be a 0 byte file.

    Managing several Sophos UTMs and Sophos XGs both at work and at some home locations, dedicated to continuously improve IT-security and feeling well helping others with their IT-security challenges.

    Sometimes I post some useful tips on my blog, see blog.pijnappels.eu/category/sophos/ for Sophos related posts.

  • I can't reproduce this here.  It works flawlessly for me just as it did prior to upgrading fom V8. FileZilla V.3.5.3.  Win7-SP1.  UTM V9.205-12.  ftp.ourdomain.com at Bluehost.

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • We only use this one FTP-server (it's a Microsoft IIS FTP server). Up to a while ago this worked as expected. Will keep you informed when I hear more.

    Managing several Sophos UTMs and Sophos XGs both at work and at some home locations, dedicated to continuously improve IT-security and feeling well helping others with their IT-security challenges.

    Sometimes I post some useful tips on my blog, see blog.pijnappels.eu/category/sophos/ for Sophos related posts.

  • Please continue to follow up with Support on this.  I know that there have been issues with 9.2 and the FTP Proxy.  Make sure you are running the latest 9.2.

    Off the top of my head, I know there are differences between active and passive mode (PASSV), maybe take a look at that.  But if it was working and is not, then its a bug and support should be able to help get it to the developers.
  • Should be fixed now in 9.207 (I haven't installed it yet, so not yet tested)
    32321 Upload fails for passive FTP connections in transparent mode

    Managing several Sophos UTMs and Sophos XGs both at work and at some home locations, dedicated to continuously improve IT-security and feeling well helping others with their IT-security challenges.

    Sometimes I post some useful tips on my blog, see blog.pijnappels.eu/category/sophos/ for Sophos related posts.