Re: FTP Download Access

From: Andrew Mitchell (amitchell_at_removecasey.vic.gov.au)
Date: 10/14/04


Date: Wed, 13 Oct 2004 18:57:52 -0700


"=?Utf-8?B?bWpvaGVhZDI=?=" <mjohead2@discussions.microsoft.com> said

> Hello everyone, here is my quesition: Users on my network need to
> download files that are only available via FTP. I do not have any FTP
> servers on my network. I placed a rule on my firewall that only allows
> FTP 'GET' traffic to pass through. Is the network still secure?

Depending on how 'application aware' your firewall is, this may not work.
FTP uses many other commands to retrieve a file. Open, Close, LS, Mode etc.
If your firewall is blocking these commands the file download will more then
likely fail.

Just create a rule that allows your local network to access any host where
the destination is on port 21. If your firewall will not allow active FTP you
must set your clients to use passive FTP.

Allthough this will also allow uploads from clients to servers, it will not
allow unsolicited ftp download requests from the internet to come through and
is no less secure than what you have allowed by opening up HTTP traffic.

-- 
Andy.


Relevant Pages

  • Re: Problem about Window Xp SP2 firewall and the buildin FTP command
    ... Problem about Window Xp SP2 firewall and the buildin FTP ... I find a problem that if running multiple FTP command at the same ... Windows XP SP2 to limit Max Connections/sec ...
    (microsoft.public.windowsxp.general)
  • Problem about Window XP SP2 firewall and the buildin FTP command
    ... Problem about Window Xp SP2 firewall and the buildin FTP ... I find a problem that if running multiple FTP command at the same ... Windows XP SP2 to limit Max Connections/sec ...
    (microsoft.public.windowsxp.perform_maintain)
  • Re: Mitigate FTP
    ... You should consider implementing an Network Intrusion Prevention System dependent on your firewall technology and network topology this should not be to hard to implement. ... Sniffing will only be possible if the attacker is in the same network segment as your FTP service, on a vulnerable downstream or upstream router from yourselves or people who access the FTP. ...
    (Pen-Test)
  • Re: Cannot Access External http sites
    ... Pc can access network resources on the local lan and internet ... DNS queries work fine and so does FTP. ... This sounds very much like a firewall problem. ...
    (microsoft.public.windowsxp.network_web)
  • Re: Ftp connection - it worked
    ... I installed Comodo and it really allows me to connect to my ftp sites. ... strange behavior since the windows firewall allow my Limewire and MSN ... I would recommend that you install either ZoneAlarm ...
    (microsoft.public.windowsxp.general)