Forum Discussion

brahim94_11525's avatar
brahim94_11525
Icon for Nimbostratus rankNimbostratus
Jul 07, 2014

AFM and FTP

Hi,

 

I need to autorize FTP (via AFM) on the global context, but how to handle the dynamic port negociation between client and server ?

 

Best regards,

 

2 Replies

  • Hi, I am also wondering and it looks the only way is to create standard VIP with FTP profile binded and attache there AFM policy .. ? I have 2 forwarding VIPs per subnet (in/out) and I would appreciate if there is any way how to open FTP just by adding new rule into AFM policy and not to create new VIP for each FTP server.

     

    If you have any tips how to handle FTP in AFM, please share.

     

    Thanks Zdenek

     

  • I need to autorize FTP (via AFM) on the global context, but how to handle the dynamic port negociation between client and server ?

     

    as long as ftp control channel is allowed, global or route domain context won't drop/reject ftp data channel.

     

    there is a bug about global or route domain context action in 11.5.0 which is fixed in 11.5.1 hf4 and 11.6.0.

     

    ID456107 [Network Firewall] If AFM rule action (at global or rtdom contexts) is Drop/reject, LTM overrides this action for EPHEMERAL connections (such as FTP data channel) without any visibility